[jboss-user] [JBossWS] - SOAP calls done with native stack blocked by SmartDefense fi

maffeis do-not-reply at jboss.com
Tue Sep 30 00:40:10 EDT 2008


I would like to inform you of an issue I encountered while deploying JBoss and JBossWS (native) at a bank. The bank uses the SmartDefense intrusion detection system, and SmartDefense blocks SOAP calls done via the JBossWS native stack because of a "non-compliant HTTP header". The only details we could get from the intrusion detection system is that a header contains non-ascii data (our URLs, headers, payload does not contain any funny characters). Sorry but I have no further details nor dumps.

Of course that could also be a bug in the intrusion detection system, but it was not possible to overcome the issue. So I replaced the native stack by metro and the issue went away.

Not sure whether my input is valuable to the JBossWS team but I felt I should let you know of this issue, as other deployments might be affected as well.


View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4179469#4179469

Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4179469

More information about the jboss-user mailing list