Virtual Patch for ASP.Net Forms Authentication Bypass Vulnerability (CVE-2011-3416)
Last Thursday, Microsoft released an out-of-band security patch (MS11-100) which includes a fix for ...
Read MoreLast Thursday, Microsoft released an out-of-band security patch (MS11-100) which includes a fix for ...
Read MoreThe SpiderLabs Research Team has identified active scanning for the phpThumb() 'fltr[]' Parameter ...
Read MoreWe have identified active scanning for the recent Plone and Zope Remote Command Execution ...
Read MoreWhile reviewing today's web honeypot logs, SpiderLabs Research identified two new attack variations.
Read MoreThe SpiderLabs Research Team is pleased to announce the ModSecurity OWASP Core Rule Set v2.2.3 ...
Read MoreWe have seen a number of scans probing for phpAlbum code execution vulns in our web honeypot logs:
Read MoreIssue Detected Our daily web honeypot analysis has detected an increase in scanning looking for ...
Read MoreOur web honeypot analysis today detected scanning looking for SQL Injection flaws in a number of ...
Read MoreOur web honeypot analysis today detected scanning looking for SQL Injection flaws in a number of ...
Read MoreJoomla Component LFI Vulnerabilities Joomla has hundreds of Controller components. Check out the ...
Read MoreRemote file inclusion (RFI) is a popular technique used to attack web applications (especially php ...
Read MoreThis is a follow-up to a previous blog post entitled "Real-time Application Profiling" that ...
Read MoreUPDATE - since this original post, we added new data manipulation capabilities to v2.6.0 with the ...
Read MoreUpdate After deeper research into the underlying vulnerability and analyzing customer traffic, ...
Read MoreUPDATE - since this original post, we added new exception handling capabilities to v2.6.0 which are ...
Read MoreAutomated Virtual Patching Example Script
Read MoreThis is an updated section from my previous book Preventing Web Attacks with Apache and discusses a ...
Read MoreThis week's installment of Detecting Malice with ModSecurity will discuss how to implement ...
Read MoreModSecurity is participating in the upcoming Blackhat Arsenal Tools Demo next week in Las Vegas.
Read MoreThis is a post-mortem blog post to discuss the successful Level II evasions found by participants ...
Read MoreUpdated - the information in this blog has been updated to reflect the current RBL enhancement ...
Read MoreAvailability of ModSecurity 2.6.1-RC1 Release (July 18, 2011) The ModSecurity Development Team is ...
Read MoreUpdate - the latest version of the ModSecurity 2.6 has a new directive called SecWriteStateLimit ...
Read MoreThe ModSecurity Project Team is happy to announce our first community hacking challenge!
Read MoreApplication Defense Response Actions What is the best way to respond to suspicious transactions ...
Read MoreSpot the Vuln -> Patch the Vuln SpotTheVuln This blog post series is designed to be a companion ...
Read More