Command injection grammar-based protection for HTML payload
Command injection grammar-based protection usage scenario
Configure command injection grammar-based protection parameter using the CLI
add appfw profile <profile-name> –CMDInjectionAction <action-name> -CMDInjectionGrammar ON/OFF
add appfw profile profile1 –CMDInjectionAction Block –CMDInjectionGrammar ON
Configure command injection pattern-match protection and grammar-based protection using the CLI
add appfw profile <profile-name> –CMDInjectionAction <action-name> -CMDInjectionGrammar ON –CMDInjectionType <Any action other than ‘None’: CMDSplCharANDKeyword/ CMDSplCharORKeyword/ CMDSplChar/ CMDKeyword>
add appfw profile p1 –CMDInjectionAction block – CMDInjectionGrammar ON –CMDInjectionType CMDSplChar
Configure command injection check only with grammar-based protection using the CLI
add appfw profile <profile-name> –CMDInjectionAction <action-name> -CMDInjectionGrammar ON –CMDInjectionType None
add appfw profile p1 –CMDInjectionAction block – CMDInjectionGrammar ON –CMDInjectionType None
Bind relaxation rules for command injection grammar-based protection using the CLI
bind appfw profile <name> -CMDInjection <String> [isRegex(REGEX| NOTREGE)] <formActionURL> [-location <location>] [-valueType (Keywor|SpecialString|Wildchar) [<valueExpression>][-isValueRegex (REGEX | NOTREGEX) ]]
bind appfw profile p1 -cmdinjection abc http://10.10.10.10/
bind appfw profile p1 –cmdinjection 'abc[0-9]+' http://10.10.10.10/ -isregex regEX
bind appfw profile p1 –cmdinjection 'name' http://10.10.10.10/ -valueType Keyword 'exi[a-z]+' -isvalueRegex regEX
Configure command injection grammar-based protection using the GUI
-
Navigate to Security > NetScaler Web App Firewall Profile > Profiles.
-
Select a profile and click Edit.
-
Go to the Advanced Settings section and click Security Checks.
-
Select the HTML Command Injection check box and click Action Settings.
-
Select the Check using CMD Grammar check box.
-
Select None from Check Request Containing.
-
Click OK.