Fire every shipped WAF test case (GET and POST) at this host and see, live, what the WAF stops — matched rule, violation code and support id. The lab tests the host that serves it (same-origin is the only way a browser can read a WAF block); use the switch to flip between the protected and unprotected host.
| Attack | Method | Expect | Status | Result | Rule / violation | Verdict |
|---|
Same-origin only: a browser can read a WAF 403 block and the
x-waf-* headers just for the host serving this page. One case
(scanner User-Agent) can't run in-browser because scripts may not set
User-Agent — run it with curl. For the machine-readable matrix
and the open-host control, use test_waf_live.py. Generated by
gen_waf_lab.py from test_waf_live.py.