Apache 2.1.7 beta released
A new beta version of the Apache web server has been released. This release is important because it ...
Read MoreA new beta version of the Apache web server has been released. This release is important because it ...
Read MoreYou may have noticed it's been a while since ModSecurity has had a major release. This does not ...
Read MoreAs some of you may know, I've been working on the portable web application firewall (WAF) rule ...
Read MoreThis version implements the final batch of major improvements to the 1.9.x series. These include a ...
Read MoreA while ago Greg Murray (the Servlet specification lead) asked for ideas for Servlet improvements. ...
Read MoreI have been keeping a list of web security improvement ideas for some time now. It's a list that ...
Read MoreI have made the PHP chapter from Apache Security available for free download. When we made the ...
Read MoreRecently there has been increased interest in the impedance mismatch problem, which occurs between ...
Read MoreIt always pays off to visit Richard Bejtlich's blog once in a while. (Or, even better, subscribe to ...
Read MoreWeb application firewalls have a difficult job trying to make sense of data that passes by, without ...
Read MoreSecond release candidate for mod_security 1.8.7 is available for download. I performed a detailed ...
Read MoreI have just released an updated version of ModSecurity for Java. This version implements the core ...
Read MoreI have been asked to design a mod_security rule to protect sites from the recent PHPBB worm. Now, I ...
Read MoreFor some time now I've been working on a portable web firewall rule format as part of the OASIS WAS ...
Read MoreThey've been very quiet for a number of months and now you know what they have been doing - working ...
Read MoreApplication Vulnerability Description Language (AVDL) has been approved as an OASIS standard last ...
Read MoreO'Reilly have a new book out: Network Security Hacks. It is a really good book (I read it on Safari ...
Read MoreDhillon A. K. has written a new article about mod_security. The article is essentially a brief ...
Read MoreLast night I updated the code that provides the internal chroot functionality in mod_security. I am ...
Read MoreA new organisation has just been announced: the Web Application Security Consortium. The ...
Read MoreTechicalInfo.Net is an excellent resource for Web Security information. Gunter Ollmann has provided ...
Read MoreThis morning I got news of AVDL becoming a Committee Draft; you can get it here. AVDL (Application ...
Read MoreI am very happy to announce that I've been granted a free JIRA license to use with ModSecurity! I ...
Read MoreSyhunt, a security tool company from Brazil, have released a free Apache configuration hardening ...
Read MoreA new module has been added to the Apache CVS repository: mod_log_forensic. It is a standard module ...
Read MoreI thought a post to mark the end of the year would be in order. It has been a very good year for ...
Read MoreBuilding on the multipart/form-data support I added to mod_security the other day, today I added ...
Read MoreOver the weekend I worked on adding the multipart/form-data support to mod_security. As a result, ...
Read More