The XML Message Validation check examines requests that contain XML messages to ensure that they are valid. If a request contains an invalid XML message, the Web App Firewall blocks the request. The purpose of the XML Validation check is to prevent an attacker from using specially constructed invalid XML messages to breach the security of your application.
If you use the wizard or the GUI, in the Modify XML Message Validation Check dialog box, on the General tab you can enable or disable the Block, Log, and Statistics actions.
If you use the command-line interface, you can enter the following command to configure the XML Message Validation Check:
You must use the GUI to configure the other XML Validation check settings. In the Modify XML Message Validation Check dialog box, on the Checks tab, you can configure the following settings:
-
XML Message Validation. Use one of the following options to validate the XML message:
-
Response Validation. By default, the Web App Firewall does not attempt to validate responses. If you want to validate responses from your protected application or Web 2.0 site, select the Validate Response check box. When you do, the Reuse the XML Schema specified in request validation check box and the XML Schema Object drop-down list are activated.
-
Check the Reuse XML Schema check box to use the schema you specified for request validation to do response validation as well. Note: If you check this check box, the XML Schema Object drop-down list is grayed out.
-
If you want to use a different XML schema for response validation, use the XML Schema Object drop-down list to select or upload that XML schema.