Fixing Both Missing HTTPOnly and Secure Cookie Flags
In a previous post I showed how you can use both ModSecurity and Apache together to identify/modify ...
Read MoreIn a previous post I showed how you can use both ModSecurity and Apache together to identify/modify ...
Read MoreIf you are unfamiliar with what the HTTPOnly cookie flag is or why your web apps should use it, ...
Read MoreThis year, the OWASP's Summer of Code event contains one project that's of particular interest to ...
Read MoreI spent the last week importing ModSecurity's source code repository into subversion at Source ...
Read MoreIn a few weeks' time I will present my favourite talk, Web Intrusion Detection with ModSecurity, at ...
Read MoreI will be giving the updated version of our ModProfiler presentation this Sunday (14th) at the ...
Read MoreSeveral years ago, a few more than I'd like to admit, I realised our chances for writing completely ...
Read MoreI am happy to announce that we've just launched a public issue tracking facility for ModSecurity. ...
Read MoreBefore I talk to the title of this post, I have to provide a little back story. I have had an ...
Read MoreThe ModSecurity Log Collector (mlogc) is used to send ModSecurity audit log data to a console or ...
Read MoreWe have just released ModSecurity 2.5.6 to address several issues with transformation caching: the ...
Read MoreAlthough Solaris has been supported as a platform for ModSecurity since the very beginning, it has ...
Read MoreA revised version (but still a draft) of the Enough With Default Allow in Web Applications! paper ...
Read MoreThere are three aspects of the ModSecurity Rule Language we are not very happy with. One comes from ...
Read MoreThe title of this blog post is also the title of a research paper we are currently working on. ...
Read MoreWe all agree that cross-site scripting is a serious problem, but what continues to amaze me is the ...
Read MoreWe receive questions about ModSecurity running on HP-UX from time to time, but since we don't have ...
Read MoreAs you may know, ModSecurity is licensed under GPL version 2. This license has served us reasonably ...
Read MoreIn case you missed it, Breach Security has teamed up with WhiteHat Security so that their Sentinel ...
Read MoreOWASP AppSec Europe 2008 in Ghent, which I wrote about in a previous post, indeed felt like a ...
Read MoreIn my earlier post entitled "What's the Score of the Game?" I presented the concept that what ...
Read MoreWe are excited to announce that Breach Security will be running the 2-day ModSecurity Bootcamp ...
Read MoreWe, as the webappsec community, should try and move away from "Holy Wars" debating that there is ...
Read MoreModSecurity 2.6 will likely be the last branch before ModSecurity 3. The 2.6 branch will ...
Read MoreQuite a few people have asked about the performance differences between using the regular ...
Read MoreIn my previous post, in which I was commenting on the OWASP AppSec agenda, I forgot to mention the ...
Read MoreI've just released an update to ModSecurity Community Console, our free audit log aggregation ...
Read MoreWe are excited to announce that a ModSecurity 2-day training class has been added to the upcoming ...
Read More