Bot management · F5 Networks
F5 (Shape / BIG-IP ASM)
Difficulty 5/5
Shape Security under the F5 badge. Common in banking, airlines and telco, where the tolerance for false negatives is close to zero.
- TLS fingerprinting
- JS challenge required
- Behavioural scoring
- IP reputation weight: high
How it decides
-
A heavily obfuscated telemetry payload posted to the origin, encrypted per session.
-
Deep device fingerprinting joined against F5’s cross-customer view of credential-stuffing traffic.
-
BIG-IP ASM in front of it contributes classic WAF rules and the `TS*` cookie family.
-
Deployments are frequently tuned to observe first and block later, so early success is not proof of anything.
What you see when it stops you
- “The requested URL was rejected. Please consult with your administrator.” plus a support id
- `TS01xxxxxx` or `BIGipServer*` cookies
- A large opaque JS bundle posted back on every navigation
- Blocks that appear only after hours of apparently fine traffic
Signatures the detector matches
Publicly observable artefacts F5 (Shape / BIG-IP ASM) sends to every visitor. Paste a response into the analyser and these are what it looks for.
| Where | Signal | Weight |
|---|---|---|
| Page markup | BIG-IP ASM rejection page | 75 |
| Cookie | BIGipServer* persistence cookie | 55 |
| Cookie | TS01* ASM cookie | 50 |
| Header | x-distil-cs header (legacy Distil) | 65 |
| Page markup | Distil challenge markup | 65 |
| Header | server: BigIP | 45 |
| Status | 403 rejection | 10 |
What actually gets through
-
Real browsers only, and expect per-target work — F5 deployments are individually tuned.
-
Residential or ISP exits depending on the vertical; banking deployments weigh ASN heavily.
-
Very low concurrency per identity. This product is built around credential-stuffing patterns, and burst traffic looks exactly like that.
-
Assume delayed enforcement when you test, and measure over days rather than minutes.
Hosts on record running it
From the detector's curated database. Observed, not live — stacks change, and large sites often run different protection per market.
Not sure this is what
is blocking you?
Paste the response you actually got. The detector names the vendor from its own headers, cookies and challenge markup — no account, nothing uploaded.