LinkedIn Tag
cside partners with Chargebacks 911 to counter chargeback fraud

Why doesn't my WAF flag third-party scripts that become compromised?

WAFs analyze incoming requests to determine if they're malicious, but third-party scripts are delivered from external CDNs and domains that your WAF considers legitimate. When a trusted script source like a popular analytics library gets compromised, your WAF continues to allow those requests because they're coming from a previously approved domain. The WAF has no way to analyze the actual JavaScript code content to determine if it has become malicious since the last time it was delivered.

Questions left?
Get answers from our experts