I work in security and recently had a false positive happen where a certain word that was being tested occurred in the session id. Matching is not case sensitive.
The character ranges that can be used in the session id:
0-9, A-Z, a-z, +, /. (no comma or period)
The security check was...