Audit WAF Block Logs Before a Model Sees the Cookie You Stopped
This story is from 2026-09-11. It is preserved in the archive; the latest stories are on the live feed.
The WAF did its job. The request never hit the app. Then I copied the block log into a coding model and asked a reasonable question: is this SQLi, or a noisy false positive? The model answered. It also received a Cookie header, a Bearer token, and a session id hanging off the query string. The atta…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-11 15:12 · DEV Community — AI
Audit WAF Block Logs Before a Model Sees the Cookie You Stopped