Unusual Security Alert
-
A few months ago, the problem was a bug in app, that doesn't display the details. That should be fixed.
This particular alarm is more of Firewalla detects there is a possibility (likely, but not always guaranteed) that one of devices is sending out a query pattern in the URL that match (using regex) a pattern used to do SQL injection. (SQL commands in the URL, and hoping it gets executed). Since regex is used, false-positive is likely.
-
Tap on the alarm and send that information to help@firewalla.com, we can help you take a look.
Sql injection are matching special patterns in the URL ... so it is possible at times there are false positives.
-
I just experienced the same issue - security alert SQL injection with all 0s and no actionable information.
When I choose device details I get a failed to load device error.
Can you please explain how to send the information to Firewalla. When I tap on the alarm I have no option to send the details that I can find.
Please sign in to leave a comment.
Comments
7 comments