JSON command injection protection check
How command injection protection works
-
For an incoming JSON request, WAF examines the traffic for keywords or special characters. If the JSON request has no patterns that match any of the denied keywords or special characters, the request is allowed. Otherwise, the request is blocked, dropped, or redirected based on the configured action.
-
If you prefer to exempt a keyword or a special character from the list, you can create a relaxation rule to bypass the security check under specific conditions.
-
You can enable logging to generate log messages. You can monitor the logs to determine whether responses to legitimate requests are getting blocked. A large increase in the number of log messages can indicate attempts to launch an attack.
-
You can also enable the statistics feature to gather statistical data about violations and logs. An unexpected surge in the stats counter might indicate that your application is under attack. If legitimate requests are getting blocked, you might have to revisit the configuration to see if you must configure the new relaxation rule or modify the existing one.
Keywords and special characters denied for command injection check
<commandinjection>
<keyword type="LITERAL" builtin="ON">7z</keyword>
<keyword type="LITERAL" builtin="ON">7za</keyword>
<keyword type="LITERAL" builtin="ON">7zr</keyword>
…
</commandinjection>
| ; & $ > < ' \ ! >> #
Configuring JSON command injection check by using the CLI
appfw profile command or add an appfw profile command to configure the JSON command injection settings. You can enable the block, log, and stats actions. You must also set the command injection type such as key words and string characters that you want to detect in the payloads.
set appfw profile <profile-name> –cmdInjectionAction <action-name> -CMDInjectionType <CMDInjectionType>]
CmdSplCharANDKeyWord. After an upgrade, the existing Web app Firewall profiles have the action set as None.
set appfw profile profile1 -JSONCMDInjectionAction block -JSONCMDInjectionType CmdSplChar
Cmd SplChar - Checks special characters CmdKeyWord - Checks command injection Keywords CmdSplCharANDKeyWord - This is the default action. The action checks special characters and command injection. Keywords and blocks only if both are present. CmdSplCharORKeyWord - Checks special characters and command injection Keywords and blocks if either of them is found.
Configuring relaxation rules for JSON command injection protection check
bind appfw profile <profile name> –JSONCMDURL <expression> -comment <string> -isAutoDeployed ( AUTODEPLOYED | NOTAUTODEPLOYED ) -state ( ENABLED | DISABLED )
Example for relaxation rule for Regex in header
bind appfw profile abc_json -jsoncmDURL http://1.1.1.1/hello.html
bind appfw profile abc_json -jsoncmDURL http://1.1.1.1/*”
unbind appfw profile abc_json -jsoncmDURL “ http://1.1.1.1/*”
Configure JSON command injection check by using the GUI
-
Navigate to Security > NetScaler Web App Firewall and Profiles.
-
On the Profiles page, select a profile and click Edit.
-
On the NetScaler Web App Firewall Profile page, go to Advanced Settings section and click Security Checks.
-
In Security Checks section, select JSON Command Injection and click Action settings.
-
In the JSON Command Injection Settings page, set the following parameters
-
Actions. Select one or more actions to perform for JSON command injection security check.
-
Check Request Containing. Select a command injection pattern to check if the incoming request has the pattern.
-
-
Click OK.
Viewing command injection traffic and violation statistics
stat appfw profile profile1
| Appfw profile Traffic Statistics | Rate (/s) | Total |
|---|---|---|
| Requests | 0 | 0 |
| Request Bytes | 0 | 0 |
| Responses | 0 | 0 |
| Response Bytes | 0 | 0 |
| Aborts | 0 | 0 |
| Redirects | 0 | 0 |
| Long Term Ave Response Time (ms) | -- | 0 |
| Recent Ave Response Time (ms) | -- | 0 |
| HTML/XML/JSON Violation Statistics | Rate (/s) | Total |
|---|---|---|
| Start URL | 0 | 0 |
| Deny URL | 0 | 0 |
| Referer header | 0 | 0 |
| Buffer overflow | 0 | 0 |
| Cookie consistency | 0 | 0 |
| Cookie hijacking | 0 | 0 |
| CSRF form tag | 0 | 0 |
| HTML Cross-site scripting | 0 | 0 |
| HTML SQL injection | 0 | 0 |
| Field format | 0 | 0 |
| Field consistency | 0 | 0 |
| Credit card | 0 | 0 |
| Safe object | 0 | 0 |
| Signature Violations | 0 | 0 |
| Content Type | 0 | 0 |
| JSON Denial of Service | 0 | 0 |
| JSON SQL injection | 0 | 0 |
| JSON Cross-Site Scripting | 0 | 0 |
| File Upload Types | 0 | 0 |
| Infer Content Type XML Payload | 0 | 0 |
| HTML CMD Injection | 0 | 0 |
| XML Format | 0 | 0 |
| XML Denial of Service (XDoS) | 0 | 0 |
| XML Message Validation | 0 | 0 |
| Web Services Interoperability | 0 | 0 |
| XML SQL Injection | 0 | 0 |
| XML Cross-Site Scripting | 0 | 0 |
| XML Attachment | 0 | 0 |
| SOAP Fault Violations | 0 | 0 |
| XML Generic Violations | 0 | 0 |
| Total Violations | 0 | 0 |
| HTML/XML/JSON Log Statistics | Rate (/s) | Total |
|---|---|---|
| Start URL logs | 0 | 0 |
| Deny URL logs | 0 | 0 |
| Referer header logs | 0 | 0 |
| Buffer overflow logs | 0 | 0 |
| Cookie consistency logs | 0 | 0 |
| Cookie hijacking logs | 0 | 0 |
| CSRF from tag logs | 0 | 0 |
| HTML cross-site scripting logs | 0 | 0 |
| HTML cross-site scripting transform logs | 0 | 0 |
| HTML SQL Injection logs | 0 | 0 |
| HTML SQL transform logs | 0 | 0 |
| Field format logs | 0 | 0 |
| Field consistency logs | 0 | 0 |
| Credit cards | 0 | 0 |
| Credit card transform logs | 0 | 0 |
| Safe object logs | 0 | 0 |
| Signature logs | 0 | 0 |
| Content Type logs | 0 | 0 |
| JSON Denial of Service logs | 0 | 0 |
| JSON SQL injection logs | 0 | 0 |
| JSON Cross-Site Scripting logs | 0 | 0 |
| File upload types logs | 0 | 0 |
| Infer Content Type XML Payload L | 0 | 0 |
| JSON CMD Injection | 0 | 0 |
| HTML Command Injection logs | 0 | 0 |
| XML Format logs | 0 | 0 |
| XML Denial of Service(XDoS) logs | 0 | 0 |
| XML Message Validation logs | 0 | 0 |
| WSI logs | 0 | 0 |
| XML SQL Injection logs | 0 | 0 |
| XML cross-site scripting logs | 0 | 0 |
| XML Attachment logs | 0 | 0 |
| SOAP Fault logs | 0 | 0 |
| XML Generic logs | 0 | 0 |
| Total log messages | 0 | 0 |
| HTML/XML/JSON Log Statistics | Rate (/s) | Total |
|---|---|---|
| JSON Command Injection logs | 0 | 0 |
| XML format logs | 0 | 0 |
Viewing JSON command injection statistics by using the NetScaler GUI
-
Navigate to Security > NetScaler Web App Firewall > Profiles.
-
In the details pane, select a Web App Firewall profile and click Statistics.
-
The NetScaler Web App Firewall Statistics page displays the JSON command injection traffic and violation details.
-
You can select Tabular View or switch to Graphical View to display the data in a tabular or graphical format.
Configure fine grain relaxation for JSON command injection
-
Key names
-
Key values
Points to Consider
-
Value expression is an optional argument. A field name might not have any value expression.
-
A key name can be bound to multiple value expressions.
-
Value expressions must be assigned a value type. The value type can be: 1) Keyword, 2) SpecialString.
-
You can have multiple relaxation rules per key name/URL combination.
Configure JSON fine grain relaxation for command injection attacks using command interface
bind appfw profile <profile name> -jsoncmdURL <URL> -key <key name> -valueType <keyword/SpecialString> <value Expression>
bind appfw profile appprofile1 -jsoncmdurl www.example.com -key blg_cnt -isRegex NOTREGEX -valueType Keyword “cat” -isvalueRegex NOTREGEX
-
Navigate to Application Firewall > Profiles, select a profile, and click Edit.
-
In the Advanced Settings pane, click Relaxation Rules.
-
In the Relaxation Rules section, select a JSON Command Injection record and click Edit.
-
In the JSON Command Injection Relaxation Rule slider, click Add.
-
In the JSON Command Injection Relaxation Rule page, set the following parameters.
-
Enabled
-
Is Name Regex
-
Key Name
-
URL
-
Value Type
-
Comments
-
Resource ID
-
-
Click Create.