ApacheCon Europe: Web Intrusion Detection with ModSecurity
I've had a pleasure of participating in ApacheCon Europe in Amsterdam this week. Paradoxically, ...
Read MoreI've had a pleasure of participating in ApacheCon Europe in Amsterdam this week. Paradoxically, ...
Read MoreI went through all my ModSecurity Blog posts yesterday, partly to admire myself for blogging ...
Read MoreWith the release of ModSecurity 2.5 yesterday, this seemed like the perfect time to get feedback ...
Read MoreThe final version of ModSecurity 2.5.0, the long awaited next stable version of ModSecurity, is now ...
Read MoreBreach Labs which sponsors WHID has issued an analysis of the Web Hacking landscape in 2007 based ...
Read MoreThe ModSecurity 2.5 release is scheduled for early/mid February. With the ModSecurity 2.5 release ...
Read MoreModSecurity 2.5 introduces a really cool, yet somewhat obscure feature called Content Injection. ...
Read MoreSome time ago I decided to start a new blog, a place where I would be able to address the topics ...
Read MoreI have just added a new section to the ModSecurity v2.5 Reference Manual, describing the data ...
Read MoreI will be speaking about ModSecurity at ApacheCon Europe in Amsterdam later this year. I hear ...
Read MoreHere is a snippet from the just released SANS NewsBites letter:
Read MoreLarge Wordlist Example You will find the greatest benefit of using the set based matching opertors ...
Read MoreWe've had a couple of very interesting presentations on the OWASP London Chapter December 6th ...
Read MoreThe first release candidate for the ModSecurity 2.5 release is now available. It has been a while ...
Read MoreUsing SecRuleRemoveById to handle false positives The SecRuleRemoveById directive is most often ...
Read MoreModSecurity 2.1.4 is the latest stable release of ModSecurity. The 2.1.4 release includes an ...
Read MoreModSecurity is a really powerful beast. It can do anything you want, at least when what you want ...
Read MoreAs some of you may know, I am heading up the WASC Distributed Open Proxy Honeypot Project. The ...
Read MoreI am very excited to announce that I will be instructing a live 2-day ModSecurity Training class at ...
Read MoreModSecurity 2.1.3 is the latest stable release of ModSecurity. The 2.1.3 release contains some ...
Read MoreNIST has released a new guide on securing Web Services. It is a pretty good read for anyone who is ...
Read MoreVirtual Patching is a policy for a web application firewall (in this case ModSecurity) that is able ...
Read MoreToday I released ModSecurity 2.1.2. This is the latest stable release of ModSecurity. The 2.1.2 ...
Read MoreIn many ways vulnerability remediation is like a Track and Field race and the firing of the ...
Read MoreMichael Renzmann wrote to the ModSecurity mailing list recently announcing project ScallyWhack. ...
Read MoreLast week I released the second ModSecurity development release, 2.5.0-dev2, in preparation for the ...
Read MoreA very interesting research paper titled "Apache Prefork MPM Vulnerabilities" was released a few ...
Read MoreAs many of you have noticed, the Core Rule Set contains very complex regular expressions. For ...
Read More