ModSecurity Console: Purpose and Deployment

March 17, 2007 | SpiderLabs Anterior

If you have more then 1 ModSecurity installation, you have undoubtedly run into ...

ModSecurity ASCIIZ Evasion

March 08, 2007 | SpiderLabs Anterior

It has been brought to our attention that a fault in the ModSecurity parsing ...

ModSecurity Status Report

February 23, 2007 | SpiderLabs Anterior

I enjoyed talked about ModSecurity (and web application firewalls) in front of ...

Handling False Positives and Creating Custom Rules

February 17, 2007 | SpiderLabs Anterior

It is inevitable; you will run into some False Positive hits when using web ...

Dealing with Impedance Mismatch

February 07, 2007 | SpiderLabs Anterior

In my previous post I described a potential problem with web application ...

Testing Core Rules Protection For An Example SQL Injection Vulnerability

February 07, 2007 | SpiderLabs Anterior

SANS released their 6th edition of the @RISK Weekly News Letter. In it, there ...

PHP Peculiarities for ModSecurity Users

February 06, 2007 | SpiderLabs Anterior

As I was reviewing the ModSecurity 2.1.0-rc7 Reference Manual I realised it did ...

ModSecurity 2.1.0 Improvements

February 05, 2007 | SpiderLabs Anterior

I have just packaged and released ModSecurity for Apache v2.1.0-rc7, in ...

SANS @Risk Web Vulnerabilities List Mitigation Steps

January 30, 2007 | SpiderLabs Anterior

This is a listing of Web Application Vulnerabilities that were released by SANS ...

Top 10 Web Hacks of 2006

January 23, 2007 | SpiderLabs Anterior

Jeremiah Grossman gives an excellent overview of the top Web hacks of 2006. If ...

Key Advantages of the Core Rule Set

January 03, 2007 | SpiderLabs Anterior

Following a question on the core rule set on the ModSecuirty mailing list, I ...

Using ModSecurity 2 Collections in Rules

December 28, 2006 | Trustwave SpiderLabs

A recent posting on the ModSecurity mailing list by K.C. Li is a very good ...

ModSecurity v2.0 Webcast

December 07, 2006 | Trustwave SpiderLabs

In response to many of the common questions and issues posted to the mail-list, ...

Talking About ModSecurity 2.0 With Federico Biancuzzi for SecurityFocus

October 24, 2006 | SpiderLabs Anterior

A while ago Federico Biancuzzi contacted me to ask if I'd be interested to give ...

ModSecurity Cookie and Link Protection Patch

August 18, 2006 | SpiderLabs Anterior

A significant event occurred on the mod-security-users mailing list in July: a ...

ModSecurity Performance Tip

August 17, 2006 | SpiderLabs Anterior

I was asked recently to investigate performance of an ModSecurity installation ...

Apache Reverse Proxy Memory Consumption Observations

August 14, 2006 | SpiderLabs Anterior

Last week I spent some time stress-testing Apache 2.2.3 configured to work as a ...

ModSecurity 1.9.x Performance Testing

August 07, 2006 | SpiderLabs Anterior

You can tell that I am too busy when I take almost three months to blog about ...

Forrester Research Q2 2006 Web Application Firewall Evaluation

July 24, 2006 | SpiderLabs Anterior

Back in March 2006 I was approached by Forrester Research and invited to ...

Yahoo Small Business offers 'ModSecurity-like' functionality

July 12, 2006 | SpiderLabs Anterior

I just came across this and can't help but make a note about it: A web hosting ...

ModSecurity Console Now Available

July 04, 2006 | SpiderLabs Anterior

I love the command line, I do. But there are some tasks where this type of user ...

ModSecurity 2: Explicit Normalisation Options

June 28, 2006 | SpiderLabs Anterior

One of the things I realy dislike in ModSecurity 1.x is that its anti-evasion ...

Secure Browsing Mode Proposal

June 27, 2006 | SpiderLabs Anterior

It's very well known (and even widely accepted) that our current web ...

Jailing Apache On Windows

June 13, 2006 | SpiderLabs Anterior

Yury Zaytsev wrote to me recently to tell me about his experiences in jailing ...

ModSecurity for Apache 2.0.0-beta-3 now available!

May 23, 2006 | SpiderLabs Anterior

I have been awfully quiet recently, having made my last post to this blog in ...

Apache suEXEC chroot patch

March 28, 2006 | SpiderLabs Anterior

I was recently involved with a project where we needed to configure an Apache ...

First development release of ModSecurity 2.x

March 08, 2006 | SpiderLabs Anterior

It's that time of year again, when I get to work on new features (instead of ...

Small but important improvements in ModSecurity 1.9.3

March 07, 2006 | SpiderLabs Anterior

I have just released ModSecurity for Apache 1.9.3-rc1, a release candidate, as ...