HI Haupt,
The snippet injection policy is used to profile and fingerprint clients.
A snippet of javascript is injected into the response. The client must process this script and return proof of a work. (a token)
There are
many parameters, or unique values that can be derived from JS. To see an example of some of the information that can be collected from a client via JS, please visit:
https://amiunique.org/ and click "view my browser fingerprint".
Imperva CloudWAF injects this JS into the response automatically, where as it must be configured manually with WAF GW. (securesphere)
------------------------------
JairedAnderson
Imperva
------------------------------