Apache 2.1.7 beta released

A new beta version of the Apache web server has been released. This release is important because it ...

Read More

What's new in ModSecurity 1.9

You may have noticed it's been a while since ModSecurity has had a major release. This does not ...

Read More

Portable Web Application Firewall Rule Format News

As some of you may know, I've been working on the portable web application firewall (WAF) rule ...

Read More

Major updates to ModSecurity in 1.9dev3

This version implements the final batch of major improvements to the 1.9.x series. These include a ...

Read More

Improvements to the Servlet specification

A while ago Greg Murray (the Servlet specification lead) asked for ideas for Servlet improvements. ...

Read More

Web Security Improvement Ideas

I have been keeping a list of web security improvement ideas for some time now. It's a list that ...

Read More

PHP chapter from Apache Security available for download

I have made the PHP chapter from Apache Security available for free download. When we made the ...

Read More

More on impedance mismatch

Recently there has been increased interest in the impedance mismatch problem, which occurs between ...

Read More

The future of web application firewalls

It always pays off to visit Richard Bejtlich's blog once in a while. (Or, even better, subscribe to ...

Read More

External Web Application Protection: Impedance Mismatch

Web application firewalls have a difficult job trying to make sense of data that passes by, without ...

Read More

Mod_security 1.8.7RC2 available

Second release candidate for mod_security 1.8.7 is available for download. I performed a detailed ...

Read More

ModSecurity for Java Milestone 3 now available

I have just released an updated version of ModSecurity for Java. This version implements the core ...

Read More

mod_security and the PHPBB worm (Santy.A)

I have been asked to design a mod_security rule to protect sites from the recent PHPBB worm. Now, I ...

Read More

Portable web firewall rule format

For some time now I've been working on a portable web firewall rule format as part of the OASIS WAS ...

Read More

WASC releases Threat Classification

They've been very quiet for a number of months and now you know what they have been doing - working ...

Read More

AVDL becomes a standard

Application Vulnerability Description Language (AVDL) has been approved as an OASIS standard last ...

Read More

Network Security Hack #93: mod_security

O'Reilly have a new book out: Network Security Hacks. It is a really good book (I read it on Safari ...

Read More

ModSecurity audit log to MySQL parser

Dhillon A. K. has written a new article about mod_security. The article is essentially a brief ...

Read More

Chroot support significantly improved in v1.8

Last night I updated the code that provides the internal chroot functionality in mod_security. I am ...

Read More

Web Application Security Consortium Announced

A new organisation has just been announced: the Web Application Security Consortium. The ...

Read More

Paper on passive information gathering

TechicalInfo.Net is an excellent resource for Web Security information. Gunter Ollmann has provided ...

Read More

AVDL Committee Draft is out

This morning I got news of AVDL becoming a Committee Draft; you can get it here. AVDL (Application ...

Read More

JIRA license for ModSecurity

I am very happy to announce that I've been granted a free JIRA license to use with ModSecurity! I ...

Read More

Free Apache hardening utility

Syhunt, a security tool company from Brazil, have released a free Apache configuration hardening ...

Read More

New Apache module: mod_log_forensic

A new module has been added to the Apache CVS repository: mod_log_forensic. It is a standard module ...

Read More

End of year post!

I thought a post to mark the end of the year would be in order. It has been a very good year for ...

Read More

File interception supported

Building on the multipart/form-data support I added to mod_security the other day, today I added ...

Read More

Multipart support added

Over the weekend I worked on adding the multipart/form-data support to mod_security. As a result, ...

Read More