ModSecurity Data Formats

January 11, 2008 | SpiderLabs Anterior

I have just added a new section to the ModSecurity v2.5 Reference Manual, ...

Speaking About ModSecurity at ApacheCon Europe 2008

January 09, 2008 | SpiderLabs Anterior

I will be speaking about ModSecurity at ApacheCon Europe in Amsterdam later ...

SQL Injection Attack Infects Thousands of Websites

January 08, 2008 | SpiderLabs Anterior

Here is a snippet from the just released SANS NewsBites letter:

Set-based Pattern Matching Example

January 02, 2008 | SpiderLabs Anterior

Large Wordlist Example You will find the greatest benefit of using the set ...

OWASP London Chapter December 6th Presentations Now Online

December 29, 2007 | SpiderLabs Anterior

We've had a couple of very interesting presentations on the OWASP London ...

Initial Release Candidate for ModSecurity 2.5.0 (2.5.0-rc1)

December 22, 2007 | SpiderLabs Anterior

The first release candidate for the ModSecurity 2.5 release is now available. ...

Using Transactional Variables Instead of SecRuleRemoveById

December 04, 2007 | SpiderLabs Anterior

Using SecRuleRemoveById to handle false positives The SecRuleRemoveById ...

ModSecurity 2.1.4 Now Available

November 30, 2007 | SpiderLabs Anterior

ModSecurity 2.1.4 is the latest stable release of ModSecurity. The 2.1.4 ...

Installling ModSecurity

November 07, 2007 | SpiderLabs Anterior

ModSecurity is a really powerful beast. It can do anything you want, at least ...

WASC Distributed Open Proxy Honeypot: Blind SQL Injection Attempt (Update)

November 06, 2007 | SpiderLabs Anterior

As some of you may know, I am heading up the WASC Distributed Open Proxy ...

ModSecurity Training at OWASP/WASC AppSec 2007

October 18, 2007 | SpiderLabs Anterior

I am very excited to announce that I will be instructing a live 2-day ...

Web Services Security

August 31, 2007 | SpiderLabs Anterior

NIST has released a new guide on securing Web Services. It is a pretty good ...

Virtual Patching During Incident Response: United Nations Defacement

August 27, 2007 | SpiderLabs Anterior

Virtual Patching is a policy for a web application firewall (in this case ...

ModSecurity 2.1.2 Released

August 27, 2007 | SpiderLabs Anterior

Today I released ModSecurity 2.1.2. This is the latest stable release of ...

On Your Marks, Get Set, Go: Vulnerability Mitigation Race

July 28, 2007 | SpiderLabs Anterior

In many ways vulnerability remediation is like a Track and Field race and the ...

ScallyWhack: ModSecurity Rules Package to Deal with Trac Comment Spam

June 29, 2007 | SpiderLabs Anterior

Michael Renzmann wrote to the ModSecurity mailing list recently announcing ...

Apache Process Infection

June 27, 2007 | SpiderLabs Anterior

A very interesting research paper titled "Apache Prefork MPM Vulnerabilities" ...

Optimizing Regular Expressions

June 27, 2007 | Admin

As many of you have noticed, the Core Rule Set contains very complex regular ...

Managing ModSecurity Alerts: More Console Tuning

June 22, 2007 | SpiderLabs Anterior

In a previous Blog entry, I outlined a number of steps that you could take to ...

Extended Validation Certificates: A Change for the Better (But Not Enough)

June 15, 2007 | SpiderLabs Anterior

On June 12th, 2007, the CA/Browser Forum (a group that consists of leading ...

Universal PDF XSS Revisited

June 13, 2007 | SpiderLabs Anterior

The Universal PDF XSS vulnerability was a tipping point for most people ...

ModSecurity Rule for Full-width/Half-width Unicode Evasion Detection

May 23, 2007 | SpiderLabs Anterior

You have probably heard it by now, but US-CERT released a Vulnerability Note ...

ModSecurity 2.2.0 Development Releases

May 15, 2007 | SpiderLabs Anterior

Hello all. As this is my first official blog entry, let me first start off with ...

ModSecurity Console Performance Tuning

May 10, 2007 | SpiderLabs Anterior

Help, my ModSecurity Community Console is not responding!" Perhaps you have ...

ModSecurity Migration Matrix

April 11, 2007 | SpiderLabs Anterior

For all of you who are using ModSecurity 1.x and looking for information on ...

Webinar Featuring WHID on the Top Trends in Web Application Threats

April 03, 2007 | SpiderLabs Anterior

On April 11th I'm going to present a webinar on web application security, with ...

Regular Expression Development Tools

March 30, 2007 | SpiderLabs Anterior

Since ModSecurity is based on regular expressions. Writing rules requires ...

2.1/1.x Rule Differences For Identifying Missing/Empty Headers and Variables

March 22, 2007 | SpiderLabs Anterior

There are certain scenarios where you might want to create white-listed ...