Introduction to NetScaler Web App Firewall
Web application security
Known web attacks
-
Buffer overflow attacks. Sending a long URL, long cookie, or long information to a web server causes the system to hang, crash, or provide unauthorized access to the underlying operating system. A buffer overflow attack can be used to gain access to unauthorized information, to compromise a web server, or both.
-
Cookie security attacks. Sending a modified cookie to a web server, usually in hopes of obtaining access to unauthorized content by using falsified credentials.
-
Forceful browsing. Accessing URLs on a website directly, without navigating to the URLs with hyperlinks on the home page or other common start URLs on the website. Individual instances of forceful browsing might indicate a user who bookmarked a page on your website, but repeated attempts to access nonexistent content, or content that users must never access directly, often represent an attack on website security. Forceful browsing is normally used to gain access to unauthorized information, but can also be combined with a buffer overflow attack in an attempt to compromise your server.
-
Web form security attacks. Sending inappropriate content to your website in a web form. Inappropriate content can include modified hidden fields, HTML, or code in a field intended for alphanumeric data only, an overly long string in a field that accepts only a short string, an alphanumeric string in a field that accepts only an integer, and a wide variety of other data that your website does not expect to receive in that web form. A web form security attack can be used either to obtain unauthorized information from your website or to compromise the website outright, usually when combined with a buffer overflow attack.
-
SQL injection attacks. Sending an active SQL command or commands in a web form or as part of a URL, with the goal of causing an SQL database to run the command or commands. SQL injection attacks are normally used to obtain unauthorized information.
-
Cross-site scripting attacks. Using a URL or a script on a webpage to violate the same-origin policy, which forbids any script from obtaining properties from or modifying any content on a different website. Since scripts can obtain information and modify files on your website, allowing a script access to content on a different website can provide an attacker the means to obtain unauthorized information, to compromise a web server, or both.
-
Malicious code or objects. XML requests that contain code or objects that can either directly obtain sensitive information or can give an attacker control of the web service or underlying server.
-
Badly-formed XML requests. XML requests that do not conform to the W3C XML specification, and that can therefore breach security on an insecure web service
-
Denial of service (DoS) attacks. XML requests that are sent repeatedly and in high volume, with the intent of overwhelming the targeted web service and denying legitimate users access to the web service.
-
SQL injection attacks. Sending an active SQL command or commands in an XML-based request, with the goal of causing an SQL database to run that command or commands. As with HTML SQL injection attacks, XML SQL injection attacks are normally used to obtain unauthorized information.
-
Cross-site scripting attacks. Using a script included in an XML based application to violate the same-origin policy, which does not allow any script to obtain properties from or modify any content on a different application. Since scripts can obtain information and modify files by using your XML application, allowing a script access to content belonging to a different application can give an attacker the means to obtain unauthorized information, to compromise the application, or both
Unknown web attacks
How NetScaler Web App Firewall works
NetScaler Web App Firewall features
How NetScaler Web App Firewall modifies application traffic
-
Cookies
-
HTTP Headers
-
Forms/Data
NetScaler Web App Firewall session cookie
citrix_ns_id.
citrix_ns_id generated by the appliance is not enforced. For more information on configuring cookies, see Engine settings.
NetScaler Web App Firewall cookies
-
Persistent Cookies - These cookies are stored locally on the computer and used again the next time you visit the site. This type of cookie usually contains information about the user, such as, logon, password, or preferences.
-
Session or Transient Cookies - These cookies are used only during the session and are destroyed after the session is terminated. This type of cookie contains application state information, such as, shopping cart items or session credentials.
-
Persistent Cookies:
citrix_ns_id_wlf. Note: wlf stands for will live forever. -
Session or Transient Cookies:
citrix_ns_id_wat. Note: wat stands for will act transiently. To track the application cookies, the Application Firewall groups the persistent or session application cookies together and then hash and sign all the cookies together. Thus, the Application Firewall generates onewlfcookie to track all persistent application cookies and onewatcookie to track all application session cookies.
| Before NetScaler Web App Firewall | To |
|---|---|
| One persistent cookie | Persistent cookie: citix_ns_id_wlf |
| One transient cookie | Transient cookie: citix_ns_id_wat |
| Multiple persistent cookies, Multiple transient cookies | One Persistent cookie: citrix_ns_id_wlf, One Transient cookie: citix_ns_id_wat |
How the application firewall affects HTTP headers
Host: www.citrix.com
Request headers dropped by NetScaler Web App Firewall
-
Range – Used to recover from a failed or partial file transfers.
-
If-Range – Allows a client to retrieve a partial object when it contains a part of that object in its cache already (conditional GET).
-
If-Modified-Since – If the requested object is not modified since the time specified in this field, an entity is not returned from the server. You get an HTTP 304 not modified error.
-
If-None-Match – Allows efficient updates of cached information with a minimum amount of overhead.
-
Accept-Encoding – What encoding methods are allowed for a particular object, such as gzip.
Request header modified by NetScaler Web App Firewall
Request headers added by NetScaler Web App Firewall
Response header dropped by NetScaler Web App Firewall
Response Headers Modified by NetScaler Web App Firewall
-
If Server sends Pragma: no-cache, then the Application Firewall does not do any modification.
-
If Client Request is HTTP 1.0, then Application Firewall inserts Pragma: no-cache.
-
If Client Request is HTTP 1.1 and has Cache-control: no-store, then Application Firewall does not make any modification.
-
If Client Request is HTTP 1.1 and Server Response has Cache-Control header with no store or no cache directive, then Application Firewall does not make any modification.
-
If Client Request is HTTP 1.1 and Server Response has either No Cache-control Header or Cache-Control header does not have no store or no-cache directive, the Application Firewall completes the following tasks:
-
Inserts Cache-control: max-age=3, must-revalidate,private.
-
Inserts X-Cache-Control-orig = Original value of Cache-Control Header.
-
Deletes Last-Modified header.
-
Replaces Etag.
-
Inserts X-Expires-Orig=Original value of the Expire Header sent by the server.
-
Modifies the Expires Header and sets the expiration date of the webpage to the past, so it is always picked up again.
-
Modifies Accept-Ranges and sets it to none.
-
Deletes Last-Modified from server before forwarding to client.
-
Replaces Etag with a value determined by Application Firewall.
Response headers added by NetScaler Web App Firewall
-
Transfer-Encoding: Chunked. This header streams information back to a client without having to know the total length of the response before sending the response. This header is required because the content-length header is removed. -
Set-Cookie: The cookies added by the Application Firewall. -
Xet-Cookie: If the session is valid and if the response is not expired in cache, you can serve from cache and do not have to send a new cookie because the session is still valid. In such a scenario, the Set-Cookie is changed to Xet-Cookie. For the web browser.
How form data is affected
<input type="hidden" name="as_fid" value="VRgWq0I196Jmg/+LOY7C" />
Sessionless form check
<input type="hidden" name="as_ffc_field" value="CwAAAAVIGLD/luRRi1Wu1rbYrFYargEDcO5xVAxsEnMP1megXuQfiDTGbwk0fpgndMHqfMbzfAFdjwR+TOm1oT
+u+Svo9+NuloPhtnbkxGtNe7gB/o8GlxEcK9ZkIIVv3oIL/nIPSRWJljgpWgafzVx7wtugNwnn8/GdnhneLCJTaYU7ScnC6LexJDLisI1xsEeONWt8Zm
+vJTa3mTebDY6LVyhDpDQfBgI1XLgfLTexAUzSNWHYyloqPruGYfnRPw+DIGf6gGwn1BYLEsRHKNbjJBrKpOJo9JzhEqdtZ1g3bMzEF9PocPvM1Hpvi5T6VB
/YFunUFM4f+bD7EAVcugdhovzb71CsSQX5+qcC1B8WjQ==" />
HTML comment stripping
Credit card protection
Safe object protection
Cross-site scripting transforms action
"<" into "%26lt;" and ">" into "%26gt;" in the requests. If the checkRequestHeaders setting in the Web App Firewall is enabled, then the Web App Firewall inspects the Request Headers and transforms these characters in Header and cookies also. The transform action does not block or transform values that were originally sent by the server. There is a set of default attributes and tags for cross-site scripting which the Web App Firewall allows. A default list of denied cross-site scripting patterns is also provided. These can be customized by selecting the signatures object and clicking the Manage SQL/cross-site scripting Patterns dialogue in the GUI.
Transforming SQL special characters
| From | To | Transformation |
|---|---|---|
| ' (single quote that is, %27) | " | Another single quote |
| \ (backslash that is %5C) | Another backslash added | |
| ; (semicolon that is %3B) | Dropped |
NetScaler Web App Firewall behavior wherein it corrupts the EXPECT header
-
Whenever NetScaler receives an HTTP request with the EXPECT header in it, NetScaler sends the EXPECT: 100 -continue response to client on behalf of the back end server.
-
This behavior is because Application Firewall protections must be run on the entire request before forwarding the request to the server, NetScaler must get the entire request from the client.
-
On receiving a
100 continueresponse, the client sends the remaining portion of request that completes the request. -
NetScaler then runs all the protections and then forwards the request to the server.
-
Now as NetScaler is forwarding the complete request the EXPECT header that came in the initial request becomes obsolete as a result NetScaler corrupts this header and sends it to the server.
-
Server on receiving the request ignores any header which is corrupted.