How can I create a precise WAF exception for a legitimate API request ?

BILL Bella 40 Reputation points
2026-09-30T03:05:54.6066667+00:00

I'm trying to allow a legitimate API request through our cloud WAF. The payload contains a base64-encoded string, but the WAF keeps blocking it because it detects what looks like a SQL injection signature. I'm not sure exactly which part of the request is triggering the rule or how to exclude only this specific payload. How can I create a precise exception rule without weakening the WAF protection for other requests ?

Windows for business | Windows 365 Enterprise
0 comments No comments

1 answer

Sort by: Most helpful
  1. Jason Nguyen Tran 27,050 Reputation points Independent Advisor
    2026-09-30T03:57:41.1766667+00:00

    Hi BILL Bella,

    What you're describing is a common scenario where a Web Application Firewall flags a Base64-encoded payload because, once decoded or pattern-matched, it resembles a SQL injection signature. While it may be tempting to disable the rule entirely, I strongly recommend identifying the exact rule ID and request component (header, query parameter, JSON field, or request body section) that is triggering the detection before making any exceptions.

    The safest approach is to review the WAF logs and examine the request details to determine precisely which parameter is causing the alert. Once identified, create a narrowly scoped exception that applies only to the specific API endpoint and parameter involved, rather than disabling SQL injection protection globally. If your WAF supports it, consider excluding inspection for that particular field while keeping all other SQL injection signatures active for the remainder of the request.

    I would also recommend validating whether the Base64 content is expected to contain high-entropy or encoded application data and ensuring that it cannot be manipulated by external users to bypass protections. Testing the exception in a staging environment is important to confirm that legitimate requests are allowed while malicious payloads continue to be blocked. In many environments, using parameter-level exclusions combined with endpoint-specific matching provides the best balance between security and functionality.

    As a best practice, document the reason for the exception, monitor the affected endpoint after deployment, and periodically review the WAF logs to ensure the exception remains appropriate. This helps avoid a situation where a temporary workaround becomes an unintended long-term security gap.

    I hope the response provided some helpful insight. If you find this answer useful, please hit “accept answer” so I know it addressed your concern.

    Jason

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.