File upload protection
ExcludeFileUploadFormChecks option in the WAF profile.
How file upload works
-
Client request has a form submission with a file upload type, for example PDF.
-
As part of the security check, WAF inspects the request payload and validates the file type (based on magic signature numbers).
-
If the file type is not in a supported format, the corresponding action based on file type binding is applied.
-
To validate the file type the appliance inspects the payload and checks for the known magic numbers at known offsets. Each file type has a sequence of magic numbers that validates the file type.
Configure file type upload by using NetScaler CLI
-
Configure Web Application Firewall profile
set appfw profile <profile_name> [-fileUploadTypesAction <fileUploadTypesAction>]<fileUploadTypesAction> = ( none | block | log | stats )
Example
set appfw profile profile1 –fileUploadTypesAction block
-
Bind Web Application Firewall profile with file upload parameters. The command binds the specified exemption (relaxation) or rule to the specified application firewall profile.
bind appfw profile <profile_name> - fileUploadType <form_field > <form_action_url> [-isNameRegex ( REGEX | NOTREGEX )] -fileType <fileType> ( pdf | msdoc | text | image | any)
NOTREGEX.
Example
> bind appfw profile test -fileuploadType thefile "http://10.10.10.10/fileupload_sample/upload.php" -isNameRegex NOTREGEX -filetype image
Configure file upload security protection by using NetScaler GUI
-
In the navigation pane, navigate to Security > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Security Checks under Advanced Settings.
-
In the Security Checks section, select File Upload Types and click Action Settings.
-
In the File Upload Types Settings page, set the file upload action.
-
Click OK.
-
In the NetScaler Web App Firewall Profile page, click OK and Done.
Configure file upload relaxation rule by using NetScaler GUI
-
In the navigation pane, navigate to Security > NetScaler Web App Firewall > Profiles.
-
In the Profiles page, click Add.
-
In the NetScaler Web App Firewall Profile page, click Relaxation Rules under Advanced Settings.
-
In the Relaxation Rules section, select File Upload Types and click Edit.

-
In the File Upload Types Rexalation Rules page, click Add.
-
In the File Upload Types Relaxation Rule page, set the following parameters:
-
Enabled - Select to enable the relaxation rule.
-
Is Form Field Name Regex - Select to update a regex pattern for the form field name.
-
Form Field Name - Enter the file name that does not require a security check.
-
Action URL - The form submission URL that must be exempted from security checks.
-
File Type - Supported file format that can be uploaded.
-
Comments - A brief description about the file upload.
-
-
Click Create.

-
In the NetScaler Web App Firewall Profile page, click OK and Done.