Skip to main content
Version: v6

KB: 1058

How to prevent sites from XML bomb attack?

Problem Statement

Client wants to protect their sites from XML bomb attack which are protected by Haltdos solutions.

SOLUTION

The client can achieve the above requirement by configuring XML policies.

  1. First, log into the haltdos management console.

kb-1058

2.Go to Stacks > WAF > Listener > Profile > Profile default setting > Policy > **XML Policy ** > Configure the XML Policy > Save Changes.

kb-1058

  1. Now send bulk XML to the respective listener.

  2. Below WAF incident is showing dropped request when bulk XML payload hit the listener.

kb-1058

kb-1058