Manual Chapter :
Configuring
phishing detection on a URL
Applies To:
Show VersionsBIG-IP FPS
- 17.1.2, 17.1.1, 17.1.0, 17.0.0, 16.1.5, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.0
Configuring
phishing detection on a URL
Configure phishing detection on a URL if you want
the system to check for phishing attacks on the web page of the URL, and send an alert
to the FPS Dashboard if an attack is detected.
- On the Main tab, click.The Anti-Fraud Profiles screen opens.
- From the list of profiles, select the profile on which you want to configure phishing detection.The Anti-Fraud Profile Properties screen opens.
- In the Anti-Fraud Configuration area, clickURL List.The URL List opens.
- Click the URL on which you want to configure phishing detection (or clickAddif you want to define a new URL with phishing detection).The URL Properties screen opens.
- In the URL Configuration area, selectPhishing Detection.
- Select theEnabledcheck box forPhishing Detection.The Phishing Detection configuration options appear.
- Select theEnabledcheck box for theLog credentials theft by a phishing sitesetting if you want the system to log the user names and text fields (not passwords) of users attacked by a phishing attempt on this URL.This setting does not appear ifWeb page copy detection(in the Advanced settings) is disabled.
- ClickAdvanced.
- Select theEnabledcheck box for theWeb page copy detectionsetting if you want the system to detect whether the web page for this URL has been copied and send an alert to the FPS Dashboard if it determines that this happened.
- Select theEnabledcheck box for theJavaScript removal detectionsetting if you want the system to detect whether JavaScript is missing from the web page of the URL and send an alert to the FPS Dashboard if it determines that this happened.This is part of the system's phishing detection backup mechanism.
- In theLocation of Phishing Inline JavaScript and Image Injectionfield, select whether you want the phishing inline JavaScript and phishing image to be injected before or after the tag that you specify in the Tag field.The phishing inline JavaScript must be injected into the HTML after the main FPS JavaScript.
- In theInput field types to include in alertsfield, type HTML input field types (such astextorcheckbox) on the web page that you want to include in alerts.For example, if you addtext, the system attaches the values of alltextinput fields on the web page to alerts.
- ClickSave.The URL configuration settings are saved.