JSON SQL Injection protection check
Configure JSON SQL Injection protection
-
Add application firewall profile as JSON.
-
Set application firewall profile for JSON SQL Injection settings
-
Configure JSON SQL action by binding the application firewall profile.
Add application firewall profile of type JSON
add appfw profile <name> -type (HTML | XML | JSON)
Example
add appfw profile profile1 –type JSON
Configure JSON SQL Injection action
set appfw profile <name> - JSONSQLInjectionAction [block] [log] [stats] [none]
Configure JSON SQL Injection type
set appfw profile <name> - JSONSQLInjectionType <JSONSQLInjectionType>
Example
set appfw profile profile1 -JSONSQLInjectionType SQLKeyword
Example
set appfw profile profile1 -JSONSQLInjectionAction block log stat
Payload:
=======
{
"test": "data",
"username": "waf",
"password": "select * from t1;",
"details": {
"surname": "test",
"age": "23"
}
}
Log Message:
===========
08/19/2019:08:49:46 GMT pegasus121 Informational 0-PPE-0 : default APPFW APPFW_JSON_SQL 6656 0 : 10.217.32.165 18402-PPE0 - profjson http://10.217.32.147/test.html SQL Keyword check failed for object value(with violation="select(;)") starting at offset(52) <blocked>
Counters:
========
1 441083 1 as_viol_json_sql
3 0 1 as_log_json_sql
5 0 1 as_viol_json_sql_profile appfw__(profjson)
7 0 1 as_log_json_sql_profile appfw__(profjson)
Configure JSON SQL Injection protection by using GUI
-
On the navigation pane, navigate to Security > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Security Checks under Advanced Settings.
-
In the Security Checks section, go to JSON SQL Injection settings.
-
Click the executable icon near the check box.
-
Click Action Settings to access the JSON SQL Injection Settings page.
-
Select the JSON SQL Injection actions.
-
Click OK.
-
In the NetScaler Web App Firewall Profile page, click Relaxation Rules under Advanced Settings.
-
In Relaxation Rules section, select JSON SQL Injection settings and click Edit.
-
In the JSON SQL Injection Relaxation Rule page, enter the URL to which the request has to be sent. All requests sent to this URL will not be blocked.
-
Click Create.JSON SQL Injection Security Check
Configure fine grain relaxation for JSON SQL injection protection
-
Key names
-
Key values
Points to Consider
-
Value expression is an optional argument. A field name might not have any value expression.
-
A key name can be bound to multiple value expressions.
-
Value expressions must be assigned a value type. The value type can be: 1) Keyword, 2) SpecialString.
-
You can have multiple relaxation rules per key name or URL combination.
Configure JSON fine grain relaxation for command injection attacks using command interface
bind appfw profile <profile name> -jsoncmdURL <URL> -key <key name> -isregex <REGEX/NOTREGEX> -valueType <keyword/SpecialString> <value Expression> -isvalueRegex <REGEX/NOTREGEX>
bind appfw profile appprofile1 -jsonsqlurl www.example.com -key stn_name -isRegex NOTREGEX -valueType Keyword “union” -isvalueRegex NOTREGEX
-
Navigate to Application Firewall > Profiles, select a profile, and click Edit.
-
In the Advanced Settings pane, click Relaxation Rules.
-
In the Relaxation Rules section, select a JSON SQL Injection record and click Edit.
-
In the JSON SQL Injection Relaxation Rule slider, click Add.
-
In the JSON SQL Injection Relaxation Rule page, set the following parameters.
-
Enabled
-
Is Name Regex
-
Key Name
-
URL
-
Value Type
-
Comments
-
Resource ID
-
-
Click Create.