Announcing the ModSecurity XSS Evasion Challenge
The SpiderLabs Research Team is pleased to announce the release of the ModSecurity XSS Evasion ...
Read MoreThe SpiderLabs Research Team is pleased to announce the release of the ModSecurity XSS Evasion ...
Read MoreContent Security Policy (CSP) Implementation Challenges CSP is an extremely powerful tool for ...
Read MoreIn a previous blog post, we discussed the common lifecycle of web server botnet recruitment. While ...
Read MoreLast week, hacker "kingcope" provided PoC expliot code for a Plesk 0-day on the Full Disclosure ...
Read MoreAvailability of ModSecurity 2.7.4: Nginx Stable Release The ModSecurity Development Team is pleased ...
Read MoreOn February 27, 2013, the ModSecurity project team was notified by security researchers from ...
Read MoreNote that the vulnerability described here was fixed by Zemanta.
Read MoreAs has been reported by many news outlets , WordPress login pages have been under a heavy brute ...
Read MoreOne of the many useful features of a web application firewall (WAF) is its ability to add on ...
Read MoreThe ModSecurity web application firewall project has grown a lot in the past year including, ...
Read MoreTrustwave is a corporate sponsor of the National Collegiate Cyber Defense Competition (CCDC) where ...
Read MoreIn a previous Honeypot Alert blog post, I showed an example of attackers using LFI attacks to ...
Read MoreClient-Side JS Overriding Limitations In a previous blog post, I outlined how you could use ...
Read MoreIn a previous blog post, I outlined some ModSecurity defenses to help protect Ruby on Rails users ...
Read MoreThere is big trouble in Ruby on Rails (RoR) land... The issue is related to XML parsing of YAML ...
Read MoreThis blog post will show an easy configuration update that you can make to your web servers running ...
Read MoreWhich web application attack type is more severe: Local File Inclusion (LFI) or Code Execution? ...
Read MoreNormally for these Web Honeypot alert blog posts, I show snippets of the Apache access_log file ...
Read MoreThe following SQL Injection attack payloads targeting Joomla components were identified in our web ...
Read MoreOur web honeypots picked up some more XSS attacks today:
Read MoreDo you know when an attacker or security researcher successfully finds a Cross-site Scripting (XSS) ...
Read MoreModSecurity for Nginx ModSecurity for Nginx is a web server plug-in for the Nginx web server ...
Read MoreI have been asked this question more and more over the years as organizations are dealing with both ...
Read MoreThis blog post has also been posted on the Microsoft Security Research and Defense site: By: Greg ...
Read MoreThe Trustwave SpiderLabs Research Team is proud to announce that, through a collaboration with the ...
Read MoreThanks to my SpiderLabs Research colleague @claudijd for collaborating with this analysis.
Read More