ModSecurity Elevator Pitch at EUSecWest

February 25, 2006 | SpiderLabs Anterior

I spent some time this week at the EUSecWest conference here in London. ...

Web application firewalls primer

January 26, 2006 | SpiderLabs Anterior

(IN)SECURE Magazine Issue 1.5 has just been published. I wrote the cover story, ...

ModSecurity Rules subproject added

January 09, 2006 | SpiderLabs Anterior

If you are a ModSecurity user you may have noticed that I am distributing ...

Massive performance improvements for Apache 1.x users in ModSecurity 1.9.2-rc2

December 23, 2005 | SpiderLabs Anterior

Some ModSecurity users like to run really large rule sets, where the number of ...

ModSecurity 1.9 article on O'Reilly Network

December 02, 2005 | SpiderLabs Anterior

My article ("What's New in ModSecurity"), which describes the most important ...

Positive security model in ModSecurity

November 28, 2005 | SpiderLabs Anterior

One of the major improvements in the next release of ModSecurity (v2.0) will be ...

A few more features made it into ModSecurity 1.9

September 21, 2005 | SpiderLabs Anterior

A small number of new features made it into 1.9 at the very last minute. ...

Apache 2.1.7 beta released

September 13, 2005 | SpiderLabs Anterior

A new beta version of the Apache web server has been released. This release is ...

What's new in ModSecurity 1.9

September 08, 2005 | SpiderLabs Anterior

You may have noticed it's been a while since ModSecurity has had a major ...

Major updates to ModSecurity in 1.9dev3

August 19, 2005 | SpiderLabs Anterior

This version implements the final batch of major improvements to the 1.9.x ...

Improvements to the Servlet specification

August 08, 2005 | SpiderLabs Anterior

A while ago Greg Murray (the Servlet specification lead) asked for ideas for ...

Web Security Improvement Ideas

July 12, 2005 | SpiderLabs Anterior

I have been keeping a list of web security improvement ideas for some time now. ...

PHP chapter from Apache Security available for download

June 13, 2005 | SpiderLabs Anterior

I have made the PHP chapter from Apache Security available for free download. ...

More on impedance mismatch

June 10, 2005 | SpiderLabs Anterior

Recently there has been increased interest in the impedance mismatch problem, ...

The future of web application firewalls

June 07, 2005 | SpiderLabs Anterior

It always pays off to visit Richard Bejtlich's blog once in a while. (Or, even ...

External Web Application Protection: Impedance Mismatch

March 09, 2005 | SpiderLabs Anterior

Web application firewalls have a difficult job trying to make sense of data ...

Mod_security 1.8.7RC2 available

February 28, 2005 | SpiderLabs Anterior

Second release candidate for mod_security 1.8.7 is available for download. I ...

ModSecurity for Java Milestone 3 now available

January 05, 2005 | SpiderLabs Anterior

I have just released an updated version of ModSecurity for Java. This version ...

mod_security and the PHPBB worm (Santy.A)

December 22, 2004 | Admin

I have been asked to design a mod_security rule to protect sites from the ...

Portable web firewall rule format

September 03, 2004 | Trustwave SpiderLabs

For some time now I've been working on a portable web firewall rule format as ...

WASC releases Threat Classification

July 29, 2004 | Admin

They've been very quiet for a number of months and now you know what they have ...

AVDL becomes a standard

June 16, 2004 | Admin

Application Vulnerability Description Language (AVDL) has been approved as an ...

Network Security Hack #93: mod_security

May 04, 2004 | Admin

O'Reilly have a new book out: Network Security Hacks. It is a really good book ...

ModSecurity audit log to MySQL parser

April 15, 2004 | SpiderLabs Anterior

Dhillon A. K. has written a new article about mod_security. The article is ...

Chroot support significantly improved in v1.8

April 08, 2004 | Admin

Last night I updated the code that provides the internal chroot functionality ...

Web Application Security Consortium Announced

February 26, 2004 | Admin

A new organisation has just been announced: the Web Application Security ...

AVDL Committee Draft is out

February 07, 2004 | Admin

This morning I got news of AVDL becoming a Committee Draft; you can get it ...

JIRA license for ModSecurity

February 04, 2004 | Admin

I am very happy to announce that I've been granted a free JIRA license to use ...