ModSecurity Data Formats
January 11, 2008 | SpiderLabs Anterior
I have just added a new section to the ModSecurity v2.5 Reference Manual, ...
Speaking About ModSecurity at ApacheCon Europe 2008
January 09, 2008 | SpiderLabs Anterior
I will be speaking about ModSecurity at ApacheCon Europe in Amsterdam later ...
SQL Injection Attack Infects Thousands of Websites
January 08, 2008 | SpiderLabs Anterior
Here is a snippet from the just released SANS NewsBites letter:
Set-based Pattern Matching Example
January 02, 2008 | SpiderLabs Anterior
Large Wordlist Example You will find the greatest benefit of using the set ...
OWASP London Chapter December 6th Presentations Now Online
December 29, 2007 | SpiderLabs Anterior
We've had a couple of very interesting presentations on the OWASP London ...
Initial Release Candidate for ModSecurity 2.5.0 (2.5.0-rc1)
December 22, 2007 | SpiderLabs Anterior
The first release candidate for the ModSecurity 2.5 release is now available. ...
Using Transactional Variables Instead of SecRuleRemoveById
December 04, 2007 | SpiderLabs Anterior
Using SecRuleRemoveById to handle false positives The SecRuleRemoveById ...
ModSecurity 2.1.4 Now Available
November 30, 2007 | SpiderLabs Anterior
ModSecurity 2.1.4 is the latest stable release of ModSecurity. The 2.1.4 ...
Installling ModSecurity
November 07, 2007 | SpiderLabs Anterior
ModSecurity is a really powerful beast. It can do anything you want, at least ...
WASC Distributed Open Proxy Honeypot: Blind SQL Injection Attempt (Update)
November 06, 2007 | SpiderLabs Anterior
As some of you may know, I am heading up the WASC Distributed Open Proxy ...
ModSecurity Training at OWASP/WASC AppSec 2007
October 18, 2007 | SpiderLabs Anterior
I am very excited to announce that I will be instructing a live 2-day ...
Web Services Security
August 31, 2007 | SpiderLabs Anterior
NIST has released a new guide on securing Web Services. It is a pretty good ...
Virtual Patching During Incident Response: United Nations Defacement
August 27, 2007 | SpiderLabs Anterior
Virtual Patching is a policy for a web application firewall (in this case ...
ModSecurity 2.1.2 Released
August 27, 2007 | SpiderLabs Anterior
Today I released ModSecurity 2.1.2. This is the latest stable release of ...
On Your Marks, Get Set, Go: Vulnerability Mitigation Race
July 28, 2007 | SpiderLabs Anterior
In many ways vulnerability remediation is like a Track and Field race and the ...
ScallyWhack: ModSecurity Rules Package to Deal with Trac Comment Spam
June 29, 2007 | SpiderLabs Anterior
Michael Renzmann wrote to the ModSecurity mailing list recently announcing ...
Apache Process Infection
June 27, 2007 | SpiderLabs Anterior
A very interesting research paper titled "Apache Prefork MPM Vulnerabilities" ...
Optimizing Regular Expressions
June 27, 2007 | Admin
As many of you have noticed, the Core Rule Set contains very complex regular ...
Managing ModSecurity Alerts: More Console Tuning
June 22, 2007 | SpiderLabs Anterior
In a previous Blog entry, I outlined a number of steps that you could take to ...
Extended Validation Certificates: A Change for the Better (But Not Enough)
June 15, 2007 | SpiderLabs Anterior
On June 12th, 2007, the CA/Browser Forum (a group that consists of leading ...
Universal PDF XSS Revisited
June 13, 2007 | SpiderLabs Anterior
The Universal PDF XSS vulnerability was a tipping point for most people ...
ModSecurity Rule for Full-width/Half-width Unicode Evasion Detection
May 23, 2007 | SpiderLabs Anterior
You have probably heard it by now, but US-CERT released a Vulnerability Note ...
ModSecurity 2.2.0 Development Releases
May 15, 2007 | SpiderLabs Anterior
Hello all. As this is my first official blog entry, let me first start off with ...
ModSecurity Console Performance Tuning
May 10, 2007 | SpiderLabs Anterior
Help, my ModSecurity Community Console is not responding!" Perhaps you have ...
ModSecurity Migration Matrix
April 11, 2007 | SpiderLabs Anterior
For all of you who are using ModSecurity 1.x and looking for information on ...
Webinar Featuring WHID on the Top Trends in Web Application Threats
April 03, 2007 | SpiderLabs Anterior
On April 11th I'm going to present a webinar on web application security, with ...
Regular Expression Development Tools
March 30, 2007 | SpiderLabs Anterior
Since ModSecurity is based on regular expressions. Writing rules requires ...
2.1/1.x Rule Differences For Identifying Missing/Empty Headers and Variables
March 22, 2007 | SpiderLabs Anterior
There are certain scenarios where you might want to create white-listed ...