ModSecurity 2.5 Phrase Match Operator Performance

May 09, 2008 | SpiderLabs Anterior

Quite a few people have asked about the performance differences between using ...

ModSecurity Party in Ghent on May 20th

May 07, 2008 | SpiderLabs Anterior

In my previous post, in which I was commenting on the OWASP AppSec agenda, I ...

ModSecurity Community Console v1.0.3 Now Available

April 15, 2008 | SpiderLabs Anterior

I've just released an update to ModSecurity Community Console, our free audit ...

ModSecurity Training at OWASP AppSec Europe

April 15, 2008 | SpiderLabs Anterior

We are excited to announce that a ModSecurity 2-day training class has been ...

ApacheCon Europe: Web Intrusion Detection with ModSecurity

April 11, 2008 | SpiderLabs Anterior

I've had a pleasure of participating in ApacheCon Europe in Amsterdam this ...

Web Application Firewall Concepts

March 11, 2008

I went through all my ModSecurity Blog posts yesterday, partly to admire myself ...

ModSecurity User Survey

February 22, 2008 | SpiderLabs Anterior

With the release of ModSecurity 2.5 yesterday, this seemed like the perfect ...

ModSecurity 2.5 Released

February 21, 2008 | SpiderLabs Anterior

The final version of ModSecurity 2.5.0, the long awaited next stable version of ...

Web Hacking Incidents Database Annual Report for 2007

February 18, 2008 | SpiderLabs Anterior

Breach Labs which sponsors WHID has issued an analysis of the Web Hacking ...

ModSecurity 2.5 Status

January 30, 2008 | SpiderLabs Anterior

The ModSecurity 2.5 release is scheduled for early/mid February. With the ...

Content Injection Use Case Example

January 25, 2008 | SpiderLabs Anterior

ModSecurity 2.5 introduces a really cool, yet somewhat obscure feature called ...

Yes, the Tide for Web Application Firewalls is Turning

January 22, 2008 | SpiderLabs Anterior

Some time ago I decided to start a new blog, a place where I would be able to ...

ModSecurity Data Formats

January 12, 2008 | SpiderLabs Anterior

I have just added a new section to the ModSecurity v2.5 Reference Manual, ...

Speaking About ModSecurity at ApacheCon Europe 2008

January 09, 2008 | SpiderLabs Anterior

I will be speaking about ModSecurity at ApacheCon Europe in Amsterdam later ...

SQL Injection Attack Infects Thousands of Websites

January 08, 2008 | SpiderLabs Anterior

Here is a snippet from the just released SANS NewsBites letter:

Set-based Pattern Matching Example

January 02, 2008 | SpiderLabs Anterior

Large Wordlist Example You will find the greatest benefit of using the set ...

OWASP London Chapter December 6th Presentations Now Online

December 29, 2007 | SpiderLabs Anterior

We've had a couple of very interesting presentations on the OWASP London ...

Initial Release Candidate for ModSecurity 2.5.0 (2.5.0-rc1)

December 22, 2007 | SpiderLabs Anterior

The first release candidate for the ModSecurity 2.5 release is now available. ...

Using Transactional Variables Instead of SecRuleRemoveById

December 04, 2007 | SpiderLabs Anterior

Using SecRuleRemoveById to handle false positives The SecRuleRemoveById ...

ModSecurity 2.1.4 Now Available

November 30, 2007 | SpiderLabs Anterior

ModSecurity 2.1.4 is the latest stable release of ModSecurity. The 2.1.4 ...

Installling ModSecurity

November 07, 2007 | SpiderLabs Anterior

ModSecurity is a really powerful beast. It can do anything you want, at least ...

WASC Distributed Open Proxy Honeypot: Blind SQL Injection Attempt (Update)

November 06, 2007 | SpiderLabs Anterior

As some of you may know, I am heading up the WASC Distributed Open Proxy ...

ModSecurity Training at OWASP/WASC AppSec 2007

October 18, 2007 | SpiderLabs Anterior

I am very excited to announce that I will be instructing a live 2-day ...

ModSecurity 2.1.3 Now Available

September 13, 2007 | SpiderLabs Anterior

ModSecurity 2.1.3 is the latest stable release of ModSecurity. The 2.1.3 ...

Web Services Security

August 31, 2007 | SpiderLabs Anterior

NIST has released a new guide on securing Web Services. It is a pretty good ...

Virtual Patching During Incident Response: United Nations Defacement

August 27, 2007 | SpiderLabs Anterior

Virtual Patching is a policy for a web application firewall (in this case ...

ModSecurity 2.1.2 Released

August 27, 2007 | SpiderLabs Anterior

Today I released ModSecurity 2.1.2. This is the latest stable release of ...

On Your Marks, Get Set, Go: Vulnerability Mitigation Race

July 28, 2007 | SpiderLabs Anterior

In many ways vulnerability remediation is like a Track and Field race and the ...