In the GUI, you can configure the XML Cross-Site scripting check in the pane for the profile associated with your application.
To configure or modify the XML Cross-Site Scripting check by using the GUI
-
Navigate to Web App Firewall > Profiles, highlight the target profile, and click Edit.
-
In the Advanced Settings pane, click Security Checks.
The security check table displays the currently configured action settings for all the security checks. You have 2 options for configuration:
a) If you just want to enable or disable Block, Log, and Stats actions for the XML Cross-Site Scripting check, you can select or clear check boxes in the table, click OK, and then click Save and Close to close the Security Check pane.
b) You can double click XML Cross-Site Scripting, or select the row and click Action Settings, to display the action options. After changing any of the action settings, click OK to save the changes and return to the Security Checks table.
You can proceed to configure other security checks if needed. Click OK to save all the changes you have made in the Security Checks section, and then click Save and Close to close the Security Check pane.
To configure a XML Cross-Site Scripting relaxation rule by using the GUI
-
Navigate to Web App Firewall > Profiles, highlight the target profile, and click Edit.
-
In the Advanced Settings pane, click Relaxation Rules.
-
In the Relaxation Rules table, double-click the XML Cross-Site Scripting entry, or select it and click Edit.
-
In the XML Cross-Site Scripting Relaxation Rules dialogue box, perform Add, Edit, Delete, Enable, or Disable operations for relaxation rules.
To manage XML Cross-Site Scripting relaxation rules by using the visualizer
For a consolidated view of all the relaxation rules, you can highlight the XML Cross-Site Scripting row in the Relaxation Rules table, and click Visualizer. The visualizer for deployed relaxations offers you the option to Add a new rule or Edit an existing one. You can also Enable or Disable a group of rules by selecting a node and clicking the corresponding buttons in the relaxation visualizer.
To view or customize the Cross-Site Scripting patterns by using the GUI
You can use the GUI to view or customize the default list of cross-site scripting allowed attributes or allowed tags. You can also view or customize the default list of cross-site scripting denied Patterns.
The default lists are specified in Web App Firewall > Signatures > Default Signatures. If you do not bind any signature object to your profile, the default cross-site scripting Allowed and Denied list specified in the Default Signatures object will be used by the profile for the Cross-Site Scripting security check processing. The Tags, Attributes, and Patterns, specified in the default signatures object, are read-only. You cannot edit or modify them. If you want to modify or change these, make a copy of the Default Signatures object to create a User-Defined signature object. Make changes in the Allowed or Denied lists in the new user-defined signature object and use this signature object in the profile that is processing the traffic for which you want to use these customized allowed and denied lists.
For more information about signatures, see <http://support.citrix.com/proddocs/topic/ns-security-10-map/appfw-signatures-con.html>.
To view default cross-site scripting patterns:
-
Navigate to Web App Firewall > Signatures, select *Default Signatures, and click Edit. Then click Manage SQL/cross-site scripting Patterns.
The Manage SQL/cross-site scripting Paths table shows following three rows pertaining to cross-site scripting :
xss/allowed/attribute
xss/allowed/tag
xss/denied/pattern
Select a row and click Manage Elements to display the corresponding cross-site scripting Elements (Tag, Attribute, Pattern) used by the Web App Firewall Cross-Site Scripting check.
To customize cross-site scripting Elements: You can edit the user-defined signature object to customize the allowed Tag, allowed Attributes and denied Patterns. You can add new entries or remove the existing ones.
-
Navigate to Web App Firewall > Signatures, highlight the target user-defined signature, and click Edit. Click Manage SQL/cross-site scripting Patterns to display the Manage SQL/cross-site scripting paths table.
-
Select the target cross-site scripting row.
a) Click Manage Elements, to Add, Edit or Remove the corresponding cross-site scripting element.
b) Click Remove to remove the selected row.
Be very careful when you remove or modify any default cross-site scripting element, or delete the cross-site scripting path to remove the entire row. The signatures, HTML Cross-Site Scripting security check, and XML Cross-Site Scripting security check rely on these Elements for detecting attacks to protect your applications. Customizing the cross-site scripting Elements can make your application vulnerable to Cross-Site Scripting attacks if the required pattern is removed during editing.