In the GUI, you can configure the XML SQL Injection security check in the pane for the profile associated with your application.
To configure or modify the XML SQL Injection check by using the GUI
-
Navigate to Web App Firewall > Profiles, highlight the target profile, and click Edit.
-
In the Advanced Settings pane, click Security Checks.
The security check table displays the currently configured action settings for all the security checks. You have 2 options for configuration:
a. If you just want to enable or disable Block, Log, and Stats actions for XML SQL Injection, you can select or clear check boxes in the table, click OK, and then click Save and Close to close the Security Check pane.
b. If you want to configure additional options for this security check, double click XML SQL Injection, or select the row and click Action Settings, to display the following options:
Check for SQL Wildcard Characters—Consider SQL Wildcard characters in the payload to be attack patterns.
Check Request Containing—Type of SQL injection (SQLKeyword, SQLSplChar, SQLSplCharANDKeyword, or SQLSplCharORKeyword) to check.
SQL Comments Handling—Type of comments (Check All Comments, ANSI, Nested, or ANSI/Nested) to check.
After changing any of the above settings, click OK to save the changes and return to the Security Checks table. You can proceed to configure other security checks if needed. Click OK to save all the changes you have made in the Security Checks section, and then click Save and Close to close the Security Check pane.
To configure a XML SQL Injection relaxation rule by using the GUI
-
Navigate to Web App Firewall > Profiles, highlight the target profile, and click Edit.
-
In the Advanced Settings pane, click Relaxation Rules.
-
In the Relaxation Rules table, double-click the XML SQL Injection entry, or select it and click Edit.
-
In the XML SQL Injection Relaxation Rules dialogue box, perform Add, Edit, Delete, Enable, or Disable operations for relaxation rules.
To manage XML SQL Injection relaxation rules by using the visualizer
For a consolidated view of all the relaxation rules, you can highlight the XML SQL Injection row in the Relaxation Rules table, and click Visualizer. The visualizer for deployed relaxations offers you the option to Add a new rule or Edit an existing one. You can also Enable or Disable a group of rules by selecting a node and clicking the corresponding buttons in the relaxation visualizer.
To view or customize the SQL Injection patterns by using the GUI:
You can use the GUI to view or customize the SQL patterns.
The default SQL patterns are specified in Web App Firewall > Signatures > *Default Signatures. If you do not bind any signature object to your profile, the default SQL patterns specified in the Default Signatures object will be used by the profile for XML SQL Injection security check processing. The rules and patterns in the Default Signatures object are read-only. You cannot edit or modify them. If you want to modify or change these patterns, create a user-defined signature object by making a copy of the Default Signatures object and changing the SQL patterns. Use the user-defined signature object in the profile that processes the traffic for which you want to use these customized SQL patterns.
To view default SQL patterns:
a. Navigate to Web App Firewall > Signatures, select *Default Signatures, and click Edit. Then click Manage SQL/cross-site scripting Patterns.
The Manage SQL/cross-site scripting Paths table shows following four rows pertaining to SQL Injection:
Injection (not_alphanum, SQL)/ Keyword
Injection (not_alphanum, SQL)/ specialstring
Injection (not_alphanum, SQL)/ transformrules/transform
Injection (not_alphanum, SQL)/ wildchar
b. Select a row and click Manage Elements to display the corresponding SQL patterns (keywords, special strings, transformation rules or the wildcard characters) used by the Web App Firewall SQL injection check.
To customize SQL Patterns: You can edit a user-defined signature object to customize the SQL key words, special strings, and wildcard characters. You can add new entries or remove the existing ones. You can modify the transformation rules for the SQL special strings.
a. Navigate to Web App Firewall > Signatures, highlight the target user-defined signature, and click Edit. Click Manage SQL/cross-site scripting Patterns to display the Manage SQL/cross-site scripting paths table.
b. Select the target SQL row.
i. Click Manage Elements, to Add, Edit or Remove the corresponding SQL element.
ii. Click Remove to remove the selected row.
You must be very careful when removing or modifying any default SQL element, or deleting the SQL path to remove the entire row. The signature rules as well as the XML SQL Injection security check rely on these elements for detecting SQL Injection attacks to protect your applications. Customizing the SQL patterns can make your application vulnerable to XML SQL attacks if the required pattern is removed during editing.