This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webserver protection - URL hardening wildcard

We have an application published on the Sophos and only allow specific paths by using a firewall profile with static URL hardening + exceptions. Do wildcards work when used in the middle of a path?

Example:

Firewall profile - Static URL hardening, entry URL = /folder/subfolder/welcome.html
Exception - Skip URL hardening for requests mathing this path = /otherfolder/othersubfolder/*

That seems to work, but can we use an exception like this:

Exception - Skip URL hardening for requests mathing this path = /otherfolder*/othersubfolder/*

The application sometimes uses a dynamically generated path so we don't know what the exact path will be. Could be "otherfolderABC" but next time "otherfolderXYZ", etc.



This thread was automatically locked due to age.
Parents Reply Children
No Data