SQL grammar-based protection for HTML and JSON payload
HTTP and JSON payloads. The approach uses a set of pre-defined key-words and (or) special characters to detect an attack and flag it as a violation. Although this approach is effective, it can result in many false positives resulting in adding one or more relaxation rules. Especially when commonly used words such as "Select" and “From” are used in an HTTP or JSON request. We can reduce false positives by implementing the SQL grammar protection check for HTML and JSON payload.
SQL grammar-based protection usage scenario
JSON payloads. For adding a relaxation rule, you can reuse the existing relaxation rules. Fine grained relaxation rules are also applicable for SQL grammar, for rules with "valueType" "keyword". In JSON SQL grammar, the existing URL-based method can be reused.
Configure SQL grammar-based protection for HTML using the CLI
add appfw profile <profile-name> –SQLInjectionAction <action-name> -SQLInjectionGrammar ON/OFF
add appfw profile profile1 –SQLInjectionAction Block –SQLInjectionGrammar ON
Configure SQL pattern-match protection and grammar-based protection for HTML using the CLI
add appfw profile <profile-name> –SQLInjectionAction <action-name> -SQLInjectionGrammar ON –SQLInjectionType <Any action other than ‘None’: SQLSplCharANDKeyword/ SQLSplCharORKeyword/ SQLSplChar/ SQLKeyword>
add appfw profile p1 –SQLInjectionAction block – SQLInjectionGrammar ON –SQLInjectionType SQLSplChar
Configure SQL Injection check only with grammar-based protection for HTML using the CLI
add appfw profile <profile-name> –SQLInjectionAction <action-name> -SQLInjectionGrammar ON –SQLInjectionType None
add appfw profile p1 –SQLInjectionAction block – SQLInjectionGrammar ON –SQLInjectionType None
Bind relaxation rules for SQL grammar-based protection for HTML using the CLI
SQL injection check for a specific "ELEMENT" or "ATTRIBUTE" in the payload, you must configure a relaxation rule.
SQL grammar.
SQL command Injection inspection relaxation rules have the following syntax. At the command prompt, type:
bind appfw profile <name> -SQLInjection <String> [isRegex(REGEX| NOTREGE)] <formActionURL> [-location <location>] [-valueType (Keywor|SpecialString|Wildchar) [<valueExpression>][-isValueRegex (REGEX | NOTREGEX) ]]
bind appfw profile p1 -sqlinjection abc http://10.10.10.10/ bind appfw profile p1 –sqlinjection 'abc[0-9]+' http://10.10.10.10/ -isregex regEX bind appfw profile p1 –sqlinjection 'name' http://10.10.10.10/ -valueType Keyword 'selec[a-z]+' -isvalueRegex regEX
Configure SQL grammar based protection for HTML using the GUI
-
On the navigation pane, navigate to Security > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Security Checks under Advanced Settings.
-
In the Security Checks section, go to HTML SQL Injection settings.
-
Click the executable icon near the check box.
-
Click Action Settings to access the HMTL SQL Injection Settings page.
-
Select the Check using SQL Grammar check box.
-
Click OK.
Configure SQL grammar-based protection for JSON payload using the CLI
add appfw profile <profile-name> -type JSON –JSONSQLInjectionAction <action-name> -JSONSQLInjectionGrammar ON/OFF
add appfw profile profile1 –type JSON –JSONSQLInjectionAction Block –JSONSQLInjectionGrammar ON
Configure SQL pattern match protection and grammar-based protection for JSON payload using the CLI
add appfw profile <profile-name> -type JSON –JSONSQLInjectionAction <action-name> -JSONSQLInjectionGrammar ON –JSONSQLInjectionType <Any action other than ‘None’: SQLSplCharANDKeyword/ SQLSplCharORKeyword/ SQLSplChar/ SQLKeyword>
add appfw profile p1 –type JSON –JSONSQLInjectionAction block – JSONSQLInjectionGrammar ON –JSONSQLInjectionType SQLSplChar
Configure SQL Injection check only grammar-based protection for JSON payload using the CLI
add appfw profile <profile-name> -type JSON –JSONSQLInjectionAction <action-name> -JSONSQLInjectionGrammar ON –JSONSQLInjectionType None`\
add appfw profile p1 –type JSON –JSONSQLInjectionAction block – JSONSQLInjectionGrammar ON –JSONSQLInjectionType None
Bind url-based relaxation rules for JSON SQL grammar-based protection for JSON payload using the CLI
JSON command injection inspection for a specific "ELEMENT" or "ATTRIBUTE" in the payload, you can configure a relaxation rule. The JSON command Injection inspection relaxation rules have the following syntax. At the command prompt, type:
bind appfw profile <profile name> –JSONCMDURL <expression> -comment <string> -isAutoDeployed ( AUTODEPLOYED | NOTAUTODEPLOYED ) -state ( ENABLED | DISABLED )
bind appfw profile p1 -sqlinjection abc http://10.10.10.10/ bind appfw profile p1 –sqlinjection 'abc[0-9]+' http:// 10.10.10.10/ -isregex regEX bind appfw profile p1 –sqlinjection 'name' http://10.10.10.10/ -valueType Keyword 'selec[a-z]+' -isvalueRegex regEX
Configure SQL grammar based protection for JSON payload using the GUI
-
On the navigation pane, navigate to Security > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Security Checks under Advanced Settings.
-
In the Security Checks section, go to JSON SQL Injection settings.
-
Click the executable icon near the check box.
-
Click Action Settings to access the JSON SQL Injection Settings page.
-
Select the Check using SQL Grammar check box.
-
Click OK.