IPS detects HTML SQL Injection attempt (35827) only after WebServer returns 302 on original request

Reply
Highlighted

IPS detects HTML SQL Injection attempt (35827) only after WebServer returns 302 on original request

During an event investigation, noticed the following behavior:

 

  1. Attacker sends SQL injection request to WebServer (that sits behind a Palo-Alto).
  2. WebServer answers with HTTP 302 to redirect to error page (the error page is basically "/error.aspx/[original request from attacker]")
  3. Attacker follows the 302
  4. IPS blocks request at this point.

I'm wondering why the IPS is not blocking the SQL injection attempt when the original request from the attacker is sent and only blocks it once the attacker tries to follow the 302?

 

Anyone else noticed the same behavior? 

Highlighted
Cyber Elite

@Benoit_Malenfant,

Is the traffic running over HTTPS and if so are you performing decryption on the traffic? 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!