JSON Cross-Site Scripting protection check
Configure JSON Cross-Site Scripting protection
-
Add application firewall profile as JSON.
-
Configure JSON cross-site scripting action to block cross-site scripting malicious payload
Add application firewall profile of type JSON
add appfw profile <name> -type (HTML | XML | JSON)
Example
add appfw profile profile1 –type JSON
JSONcross-site scriptingAction: block log stats
Payload: {"username":"<a href=\"jAvAsCrIpT:alert(1)\">X</a>","password":"xyz"}
Log message: Aug 19 06:57:33 <local0.info> 10.106.102.21 08/19/2019:06:57:33 GMT 0-PPE-0 : default APPFW APPFW_JSON_cross-site scripting 58 0 : 10.102.1.98 12-PPE0 - profjson http://10.106.102.24/ Cross-site script check failed for object value(with violation="Bad URL: jAvAsCrIpT:alert(1)") starting at offset(12). <blocked>
Counters
1 357000 1 as_viol_json_xss
3 0 1 as_log_json_xss
5 0 1 as_viol_json_xss_profile appfw__(profjson)
7 0 1 as_log_json_xss_profile appfw__(profjson)
Configure JSON Cross-Site Scripting action
set appfw profile <name> - JSONcross-site scriptingAction [block] [log] [stats] [none]
Example
set appfw profile profile1 –JSONcross-site scriptingAction block
Example
set appfw profile profile1 -JSONSQLInjectionAction block log stat
Configure JSON Cross Site Scripting (cross-site scripting) protection by using GUI
-
On the navigation pane, navigate to Security > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Security Checks under Advanced Settings.
-
In the Security Checks section, go to JSON Cross-Site Scripting (cross-site scripting) settings.
-
Click the executable icon near the checkbox.
-
Click Action Settings to access the JSON Cross-Site Scripting Settings page.
-
Select the JSON cross-site scripting actions.
-
Click OK.
-
In the NetScaler Web App Firewall Profile page, click Relaxation Rules under Advanced Settings.
-
In Relaxation Rules section, select JSON Cross-Site Scripting settings and click Edit.
-
In the JSON Cross-Site Scripting Relaxation Rule page, click Add to add a JSON Cross-Site Scripting relaxation rule.
-
Enter the URL to which the request has to be sent. All requests sent to this URL will not be blocked.
-
Click Create.
Configure fine grained relaxation for JSON-based cross-site scripting
-
Key names
-
Key values
Points to Consider
-
Value expression is an optional argument. A field name might not have any value expression.
-
A key name can be bound to multiple value expressions.
-
Value expressions must be assigned a value type. The value types are tag, attribute, and pattern.
-
You can have multiple relaxation rules per key name/URL combination.
Configure JSON fine grain relaxation for cross-site scripting (XSS) injection attacks using command interface
bind appfw profile <profile name> -jsonxssURL <URL> -key <key name> -isregex <REGEX/NOTREGEX> -valueType <keyword/SpecialString> <value Expression> -isvalueRegex <REGEX/NOTREGEX>
bind appfw profile appprofile1 -jsonxssurl www.example.com -key name -isRegex NOTREGEX -valueType Tag “sname” -isvalueRegex NOTREGEX
-
Navigate to Application Firewall > Profiles, select a profile, and click Edit.
-
In the Advanced Settings pane, click Relaxation Rules.
-
In the Relaxation Rules section, select a JSON SQL Injection record and click Edit.
-
In the JSON Cross-Site Scripting Relaxation Rules slider, click Add.
-
In the JSON Cross-Site Scripting Relaxation Rule page, set the following parameters.
-
Enabled
-
Is Name Regex
-
Key Name
-
URL
-
Value Type
-
Comments
-
Resource ID
-
-
Click Create.