Integrating Vulnerability Scanners and Web Application Firewalls

June 06, 2008 | Trustwave SpiderLabs

In case you missed it, Breach Security has teamed up with WhiteHat Security so ...

ModSecurity Is Blooming

June 05, 2008 | SpiderLabs Anterior

OWASP AppSec Europe 2008 in Ghent, which I wrote about in a previous post, ...

What's the Score of the Game - Part 2: Web Security Metrics

May 31, 2008 | SpiderLabs Anterior

In my earlier post entitled "What's the Score of the Game?" I presented the ...

ModSecurity Training at Blackhat USA

May 27, 2008 | SpiderLabs Anterior

We are excited to announce that Breach Security will be running the 2-day ...

What's the Score of the Game?

May 21, 2008 | SpiderLabs Anterior

We, as the webappsec community, should try and move away from "Holy Wars" ...

ModSecurity 2.6 RoadMap

May 09, 2008 | SpiderLabs Anterior

ModSecurity 2.6 will likely be the last branch before ModSecurity 3. The 2.6 ...

ModSecurity 2.5 Phrase Match Operator Performance

May 09, 2008 | SpiderLabs Anterior

Quite a few people have asked about the performance differences between using ...

ModSecurity Party in Ghent on May 20th

May 07, 2008 | SpiderLabs Anterior

In my previous post, in which I was commenting on the OWASP AppSec agenda, I ...

ModSecurity Training at OWASP AppSec Europe

April 15, 2008 | SpiderLabs Anterior

We are excited to announce that a ModSecurity 2-day training class has been ...

ModSecurity Community Console v1.0.3 Now Available

April 15, 2008 | SpiderLabs Anterior

I've just released an update to ModSecurity Community Console, our free audit ...

ApacheCon Europe: Web Intrusion Detection with ModSecurity

April 11, 2008 | SpiderLabs Anterior

I've had a pleasure of participating in ApacheCon Europe in Amsterdam this ...

Web Application Firewall Concepts

March 11, 2008

I went through all my ModSecurity Blog posts yesterday, partly to admire myself ...

ModSecurity User Survey

February 22, 2008

With the release of ModSecurity 2.5 yesterday, this seemed like the perfect ...

ModSecurity 2.5 Released

February 21, 2008 | SpiderLabs Anterior

The final version of ModSecurity 2.5.0, the long awaited next stable version of ...

Web Hacking Incidents Database Annual Report for 2007

February 18, 2008 | SpiderLabs Anterior

Breach Labs which sponsors WHID has issued an analysis of the Web Hacking ...

ModSecurity 2.5 Status

January 30, 2008 | SpiderLabs Anterior

The ModSecurity 2.5 release is scheduled for early/mid February. With the ...

Content Injection Use Case Example

January 25, 2008

ModSecurity 2.5 introduces a really cool, yet somewhat obscure feature called ...

Yes, the Tide for Web Application Firewalls is Turning

January 22, 2008

Some time ago I decided to start a new blog, a place where I would be able to ...

ModSecurity Data Formats

January 11, 2008 | SpiderLabs Anterior

I have just added a new section to the ModSecurity v2.5 Reference Manual, ...

Speaking About ModSecurity at ApacheCon Europe 2008

January 09, 2008 | SpiderLabs Anterior

I will be speaking about ModSecurity at ApacheCon Europe in Amsterdam later ...

SQL Injection Attack Infects Thousands of Websites

January 08, 2008 | SpiderLabs Anterior

Here is a snippet from the just released SANS NewsBites letter:

Set-based Pattern Matching Example

January 02, 2008 | SpiderLabs Anterior

Large Wordlist Example You will find the greatest benefit of using the set ...

OWASP London Chapter December 6th Presentations Now Online

December 29, 2007 | SpiderLabs Anterior

We've had a couple of very interesting presentations on the OWASP London ...

Initial Release Candidate for ModSecurity 2.5.0 (2.5.0-rc1)

December 22, 2007 | SpiderLabs Anterior

The first release candidate for the ModSecurity 2.5 release is now available. ...

Using Transactional Variables Instead of SecRuleRemoveById

December 04, 2007 | SpiderLabs Anterior

Using SecRuleRemoveById to handle false positives The SecRuleRemoveById ...

ModSecurity 2.1.4 Now Available

November 30, 2007 | SpiderLabs Anterior

ModSecurity 2.1.4 is the latest stable release of ModSecurity. The 2.1.4 ...

Installling ModSecurity

November 07, 2007 | SpiderLabs Anterior

ModSecurity is a really powerful beast. It can do anything you want, at least ...

WASC Distributed Open Proxy Honeypot: Blind SQL Injection Attempt (Update)

November 06, 2007 | SpiderLabs Anterior

As some of you may know, I am heading up the WASC Distributed Open Proxy ...