HTTP OPTIONS Method

Reply
Highlighted
L4 Transporter

HTTP OPTIONS Method

Hi,

I am getting contionous 'HTTP OPTIONS Method' - alert
What is the reason for this

If I have multiple vulnerabilty profile ,I want to exclude this from one of the profile or one of the ip
(I want to ignore this vulnerabilty checking in a profile or against an IP)
How can i do that ?

Thanks

Highlighted
L5 Sessionator

The reason is that some traffic matches the signature for this alert. Would need to check details of the signature and traffic to analyze why exactly it matches and if it's a false positive.

 

If you want to ignore this alert just from (or to) few IP addresses make an exception in that IPS profile.

 

If you want to ignore this alert for all traffic make a rule in IPS profile which sets this signature to allow

Highlighted
L4 Transporter

Hi,

The reason is that some traffic matches the signature for this alert. Would need to check details of the signature and traffic to analyze why exactly it matches and if it's a false positive.

 

How to begin the analyziz

 

2)I believe there are two ways we can do the exception
One from under monitor-threats

 

vulnerabilty exception.JPG

 

 

 

second from profiles

vulnerabilty exception-2.JPG

 

 

Please correct me if i wrong ?

 

 

If you want to ignore this alert for all traffic make a rule in IPS profile which sets this signature to allow?

can you expalin this 

 

Thanks

 

 

 

Highlighted
L5 Sessionator

For analysis: read the signature description, capture the traffic, see if the destination server is vulnerable etc. 

 

Both ways to exempt IP address are equivalent. From threat monitor is just a shortct to exemptions in IPS profile. 

 

You can make a rule which includes just this signature and set it to allow (like there are rules for other signatures, usualy defined by sevirity). It's same as make an exception just for this signature.

 

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!