Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Look Up a Parameter's Value in Lookup Data Set

    Posted 01-22-2020 08:02
    Hi,

    I want to search the value of a request parameter in a lookup data set feeding by external list. For example, I want to know whether value of username parameter (like admin, administrator, etc.) is in list or not.

    Is it possible?
    #On-PremisesWAF(formerlySecuresphere)

    ------------------------------
    cezmi çal
    technical expert
    Barikat Cyber Security
    ------------------------------


  • 2.  RE: Look Up a Parameter's Value in Lookup Data Set

    Posted 01-22-2020 10:03
    Need to make sure I understand 

    HTTP requests can either be GETs or POSTs 
    I assume you are trying to interrogate a POST as it may have a user name in it 
    A GET would be for retrieving 'names' - for example 

    Is that right?


  • 3.  RE: Look Up a Parameter's Value in Lookup Data Set

    Posted 01-22-2020 10:12
    Hi Phil,

    Yes you are right.

    Is it important for Imperva? As I know, it can detect the parameters for both methods?

    ------------------------------
    cezmi çal
    technical expert
    Barikat Cyber Security
    ------------------------------



  • 4.  RE: Look Up a Parameter's Value in Lookup Data Set

    Posted 01-23-2020 09:57
    You will need to inspect using two match criteria 
    HTTP request parameter - will match on parameter name 
    - it will not match on the value associated with that  parameter 
    - but you need to use this criteria so we can look in the right field 

    The add HTTP request 
    This is where you specify the value/name you want to alert on 

    HTTP request method
    Recommend using this one to make the policy more efficient


  • 5.  RE: Look Up a Parameter's Value in Lookup Data Set

    Posted 01-24-2020 01:14
    Hi Phil,

    Thanks for the response.

    However, HTTP request does not provide lookup data option as "Match Operation" that you can see below:



    ------------------------------
    cezmi çal
    technical expert
    Barikat Cyber Security
    ------------------------------



  • 6.  RE: Look Up a Parameter's Value in Lookup Data Set

    Posted 02-16-2022 16:21
    Hi cezmi!
    Coud you solve this issue?
    Want to do practically the same thig:

    Create a policy where it will execute some action whern the request parameter value (not key) match a value in the lookup data configured.
    Ii this possible?

    Thx!

    ------------------------------
    Ricardo Gilberto
    Analista Seguridad
    Ciudad de Buenos Aires
    ------------------------------



  • 7.  RE: Look Up a Parameter's Value in Lookup Data Set

    Posted 02-17-2022 08:14
    Hi Ricardo,

    Sorry we could not solve the issue in v13.6 version. But I could not try to create such a policy in v14 platform and I do not know weather there is a solution in v14 or not

    ------------------------------
    Cezmi Cal
    technical support engineer
    Barikat Cyber Security
    Ankara
    ------------------------------