<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Specific keyword(s) not allowed in POST operations with published web app? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Specific-keyword-s-not-allowed-in-POST-operations-with-published/m-p/13691#M12992</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if anyone has had any issues with certain open source apps, etc. when publishing as a web app in MAB. For example, I have an XWiki site that is working well most of the time, but when&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;creating or editing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a post containing the word "find" and then previewing it, an error page is shown:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error:&amp;nbsp; Access denied. The format or content of your request has been detected as invalid or unsafe. (400)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I change it to finding/finder, etc. then I can save and preview. When I looked in the logs, there&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;some&amp;nbsp;IPS 'prevent' log entries referring to command injection. However I can't create an exception from the log and whitelisting the destination server in the IPS or inspection policy hasn't helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also used the option to not inspect content, etc. for the destination in the CVPN config file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone suggest where else I could look?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Nov 2018 09:33:38 GMT</pubDate>
    <dc:creator>Timothy_Morty</dc:creator>
    <dc:date>2018-11-06T09:33:38Z</dc:date>
    <item>
      <title>Specific keyword(s) not allowed in POST operations with published web app?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Specific-keyword-s-not-allowed-in-POST-operations-with-published/m-p/13691#M12992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if anyone has had any issues with certain open source apps, etc. when publishing as a web app in MAB. For example, I have an XWiki site that is working well most of the time, but when&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;creating or editing&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;a post containing the word "find" and then previewing it, an error page is shown:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error:&amp;nbsp; Access denied. The format or content of your request has been detected as invalid or unsafe. (400)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I change it to finding/finder, etc. then I can save and preview. When I looked in the logs, there&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;some&amp;nbsp;IPS 'prevent' log entries referring to command injection. However I can't create an exception from the log and whitelisting the destination server in the IPS or inspection policy hasn't helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also used the option to not inspect content, etc. for the destination in the CVPN config file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone suggest where else I could look?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 09:33:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Specific-keyword-s-not-allowed-in-POST-operations-with-published/m-p/13691#M12992</guid>
      <dc:creator>Timothy_Morty</dc:creator>
      <dc:date>2018-11-06T09:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Specific keyword(s) not allowed in POST operations with published web app?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Specific-keyword-s-not-allowed-in-POST-operations-with-published/m-p/13692#M12993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like a particular signature is generating a false positive.&lt;/P&gt;&lt;P&gt;I would work with the TAC on this so the signature can be adjusted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 19:59:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Specific-keyword-s-not-allowed-in-POST-operations-with-published/m-p/13692#M12993</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-06T19:59:29Z</dc:date>
    </item>
  </channel>
</rss>

