18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Creating Web or Secure Web Application Defenses<br />

Note: The fields in this tab will be disabled unless you select the URL Control check box<br />

on the Enforcements tab.<br />

1. In the Allow Selected HTTP Commands area, select the commands<br />

(operations) that you want to allow users to issue by clicking in the<br />

corresponding check box(es).<br />

To select all <strong>of</strong> the commands, click Select All. To deselect all <strong>of</strong> the<br />

commands, click Deselect All. A description <strong>of</strong> each command is<br />

provided within the window.<br />

2. To disallow special characters in a query, select the Enforce Strict URLs<br />

check box. If you select this option, URLs with certain special characters<br />

will be disallowed under certain circumstances (such as RFC violation).<br />

For example: quote (“), single quote (‘), back quote (`),<br />

brackets ( [ ], { }, < >), pipe (|), back slash (\), karat (^), and tilde (~).<br />

3. To allow international multi-byte characters in a query, select the Allow<br />

Unicode check box.<br />

4. [Server or Combined only] In the Maximum URL Length field, specify the<br />

maximum length allowed for a URL. The default value is 1024<br />

characters. Valid values are 1–10000.<br />

5. To require that the HTTP version be included in all requests, select the<br />

Require HTTP Version in Request check box.<br />

6. [Conditional] If you selected Require HTTP Version in Request in the<br />

previous step, specify the HTTP versions that you want to allow in the<br />

Allow Selected HTTP Versions area. Valid versions are 1.0 and 1.1.<br />

7. In the Deny Specified URL Matches table, you can specify which URLs to<br />

explicitly deny. The table lists any URLs that are currently denied.<br />

To add a URL to the list, click New. To modify a URL in the list, highlight<br />

the click Modify. The Edit URL Parsing Values window appears. See<br />

“Configuring the Edit URL Parsing Values window” on page 6-9 for<br />

information on adding a URL.<br />

Configuring the Edit URL Parsing Values window<br />

This window allows you to create a URL value to add to the Deny<br />

Specified URL Matches table. Follow the steps below.<br />

1. In the String field, type the URL string that you want to deny. For<br />

example: www.do-not-go-here.com<br />

Configuring Application Defenses 6-9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!