LinkedIn Tag
cside partners with Chargebacks 911 to counter chargeback fraud

Can a WAF detect when malicious JavaScript is stealing user data from my website?

No, because the data theft happens entirely within the user's browser after your WAF has finished its job. When a malicious script collects credit card information from your checkout form and sends it to an attacker's server, that outbound request comes directly from the user's browser to the attacker's infrastructure. Your WAF only monitors traffic between users and your servers, so it never sees this malicious data exfiltration happening in real-time.

Questions left?
Get answers from our experts