Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Confused About Cookiie Injection

    Posted 07-06-2020 07:37
    Dear
          I was confused about this  attack of cookie injection,as follow:
    Violation item and value are same as observed value,why it is identify a cookie injection attack?
    Other screen:
    Thanks!

    #Attack Analytics


  • 2.  RE: Confused About Cookiie Injection

    Posted 07-06-2020 17:15
    @jeff Gao what are you confused about? Can you give me some more detail? I can then take it back to one of the experts to get you some help on the issue.  ​

    ------------------------------
    Christopher Detzel
    Community Manager
    Imperva
    ------------------------------



  • 3.  RE: Confused About Cookiie Injection

    Posted 07-06-2020 21:38
    Why the traffic be identify as cooike injection attack?
    It's identified as cookie injection attack when client add new cookie value into request,but we can see the screen,Violation item and value are same as observed value,so,why it is identify a cookie injection attack.

    ------------------------------
    yonghao gao
    Shanghai SHNetworks Technology Co.,Ltd.
    shanghai
    ------------------------------



  • 4.  RE: Confused About Cookiie Injection

    Posted 07-07-2020 11:59
    @jeff Gao, I spoke to one of our sales engineers @Pal Balint and he said: 

    The Profile Policy fired an alert on the type or length deviation of the observed vs the profiled value of that cookie. 
     ​​This is a medium severity alert by default. Depending on the traffic and volume profile of that protected website, Learning Preferences may require to be tuned to better adapt and learn of low / medium / high traffic sites so that all legit variation of cookies and values are seen & learned by the Profiler

    ------------------------------
    Christopher Detzel
    Community Manager
    Imperva
    ------------------------------



  • 5.  RE: Confused About Cookiie Injection

    Posted 07-11-2020 09:21
    @Christopher Detzel ​So,I'm not clear about how to adjustment parameter and how to clear this alert.

    ------------------------------
    yonghao gao
    Shanghai SHNetworks Technology Co.,Ltd.
    shanghai
    ------------------------------