ModSecurity Cookie and Link Protection Patch
A significant event occurred on the mod-security-users mailing list in July: a large code ...
Read MoreA significant event occurred on the mod-security-users mailing list in July: a large code ...
Read MoreI was asked recently to investigate performance of an ModSecurity installation in order to see if ...
Read MoreLast week I spent some time stress-testing Apache 2.2.3 configured to work as a reverse proxy. I ...
Read MoreYou can tell that I am too busy when I take almost three months to blog about something interesting ...
Read MoreBack in March 2006 I was approached by Forrester Research and invited to participate in their Q2 ...
Read MoreI just came across this and can't help but make a note about it: A web hosting package offered by ...
Read MoreVariables and collections are concepts new to ModSecurity 2. ModSecurity 1.x does allow you to use ...
Read MoreI love the command line, I do. But there are some tasks where this type of user interface is simply ...
Read MoreOne of the things I realy dislike in ModSecurity 1.x is that its anti-evasion features are ...
Read MoreIt's very well known (and even widely accepted) that our current web application deployment model ...
Read MoreYury Zaytsev wrote to me recently to tell me about his experiences in jailing Apache on Windows. ...
Read MoreSome of you may remember I wrote about impedance mismatch that occurs between security layers. Ryan ...
Read MoreI have been awfully quiet recently, having made my last post to this blog in late March. I have a ...
Read MoreI was recently involved with a project where we needed to configure an Apache server that was ...
Read MoreIt's that time of year again, when I get to work on new features (instead of supporting the old ...
Read MoreI have just released ModSecurity for Apache 1.9.3-rc1, a release candidate, as I always do when ...
Read MoreI spent some time this week at the EUSecWest conference here in London. EUSecWest is a ...
Read More(IN)SECURE Magazine Issue 1.5 has just been published. I wrote the cover story, titled "Web ...
Read MoreIf you are a ModSecurity user you may have noticed that I am distributing ModSecurity without any ...
Read MoreSome ModSecurity users like to run really large rule sets, where the number of rules runs into ...
Read MoreMy article ("What's New in ModSecurity"), which describes the most important improvements in 1.9, ...
Read MoreOne of the major improvements in the next release of ModSecurity (v2.0) will be the support for a ...
Read MoreFinally. I already wrote about many new features available in this release. Relieved from the ...
Read MoreThe web application firewall (WAF) market is a bit confusing at the moment since it is not clear ...
Read MoreA small number of new features made it into 1.9 at the very last minute. Initially I intended to ...
Read MoreA new beta version of the Apache web server has been released. This release is important because it ...
Read MoreYou may have noticed it's been a while since ModSecurity has had a major release. This does not ...
Read MoreThis version implements the final batch of major improvements to the 1.9.x series. These include a ...
Read More