Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

Generic SQL Injection in HTTP Request

  So our project allows Facebook interaction.  Mars sends out this  Incident Event type every time someone attaches to Facebook.  Is this something I can just False Positive out or should I be concerned about it?  What is Facebook sending back to our network so we get this message on Mars?

2 REPLIES
Cisco Employee

Re: Generic SQL Injection in HTTP Request

Which device is sending this alert to MARS?  If it's an IPS sensor, check the description of the signature to see what kind of behavior will trigger the alert.  To see what Facebook is sending back to your network, you can do a sniffer trace and analyze the packets.

Community Member

Re: Generic SQL Injection in HTTP Request

I get numerous alerts from our IDSMs and have mitigated this by

1: not allowing the IDSMs to block our outgoing traffic at all. Not worth the risk causing major outage.

2: created av drop in MARS that drops all SQL Injections destined for the Facebook subnets. (69.63.176.1-69.63.183.254,  66.220.144.1-66.220.159.255)

Regards

Fredrik

1167
Views
0
Helpful
2
Replies
CreatePlease to create content