Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

SpiderLabs Blog

Explore the latest threats, critical vulnerability disclosures, cutting-edge research, and intelligence from our elite global threat experts.

circleradial-blogs

Latest Web Hacking Incident Database (WHID) Entries (1)

May 09, 2011 | Ryan Barnett

These are the lastest entries added by SpiderLabs to the Web Application ...

ModSecurity Advanced Topic of the Week: Passive Vulnerability Scanning Part 2 - Watcher Checks

May 03, 2011 | Ryan Barnett

In a previous blog post entitled "ModSecurity Advanced Topic of the Week: ...

Latest Web Hacking Incident Database (WHID) Entries(2)

May 02, 2011 | Ryan Barnett

These are the lastest entries added by SpiderLabs to the Web Application ...

Reaching Trustwave's WebDefend Minus World

April 27, 2011 | Ryan Barnett

So my inbox lit up today with a Full Disclosure note about a vulnerability in ...

Who's in the Driver's Seat?

April 26, 2011 | SpiderLabs Anterior

Events over the last seven days have dramatically underlined the pitfalls and ...

Detecting Malice with ModSecurity: Request Method Anomalies

April 26, 2011 | Ryan Barnett

This week's installment of Detecting Malice with ModSecurity will discuss how ...

Latest Web Hacking Incident Database (WHID) Entries (3)

April 25, 2011 | Ryan Barnett

These are the lastest entries added by SpiderLabs to the Web Application ...

ModSecurity Advanced Topic of the Week: Integrating IDS Signatures

April 21, 2011 | Ryan Barnett

Snort Web Attack Rules You may be familiar with the Emerging Threats project. ...

Latest Web Hacking Incident Database (WHID) Entries (4)

April 18, 2011 | Ryan Barnett

These are the lastest entries added by SpiderLabs to the Web Application ...

ModSecurity 2.6.0-rc1 is now available

April 18, 2011 | Ryan Barnett

The ModSecurity Development Team is pleased to announce the availability of ...

Securing the Fifth Domain

April 13, 2011 | SpiderLabs Anterior

In May 2010, the final disappearance of the line between physical and virtual ...

ModSecurity Advanced Topic of the Week: Integrating Content Security Policy (CSP)

April 13, 2011 | Ryan Barnett

Mozilla's Content Security Policy (CSP) Mozilla has developed a fantastic ...

Latest Web Hacking Incident Database (WHID) Entries (5)

April 11, 2011

These are the lastest entries added by SpiderLabs to the Web Application ...

CSS and XSS in Melodious Harmony

April 07, 2011

Web application penetration testers, have you ever run into a situation where ...

ModSecurity Advanced Topic of the Week: Malware Link Removal

April 06, 2011

This is a follow-up post to ModSecurity Advanced Topic of the Week: Malware ...

Analysis of LizaMoon: Stored XSS via SQL Injection

April 05, 2011 | Ryan Barnett

Blended Attacks

Latest Web Hacking Incident Database (WHID) Entries(6)

April 04, 2011 | Ryan Barnett

These are the lastest entries added by SpiderLabs to the Web Application ...

Defective By Design? - Certificate Revocation Behavior In Modern Browsers

April 04, 2011 | Paul Kehrer

With the recent fraudulent certificate incident involving one of Comodo's RAs ...

ModSecurity Update: Increasing Community Involvement

March 30, 2011

New Licensing Trustwave is commited to the development of the ModSecurity ...

ModSecurity Advanced Topic of the Week: New Community Contribution - cmdLine Transformation Function

March 30, 2011

Community Contribution - cmdLine This week's topic highlights a community ...

SpiderLabs Radio Updated - Hack It! Edition for February 2011

March 29, 2011

A new SpiderLabs Radio - Hack It! Edition podcast has been uploaded.

Latest Web Hacking Incident Database (WHID) Entries(7)

March 28, 2011 | Ryan Barnett

These are the lastest entries added by SpiderLabs to the Web Application ...

Detecting Malice with ModSecurity: Open Proxy Abuse

March 25, 2011 | Ryan Barnett

This week's installment of Detecting Malice with ModSecurity will discuss how ...

ModSecurity Advanced Topic of the Week: Malware Link Detection

March 17, 2011 | Ryan Barnett

Planting of Malware Planting of malware links into legitimate websites in order ...

WASC WHID Semi-Annual Report for 2010: July - December

March 14, 2011

SpiderLabs just released our WASC Web Hacking Incident Database (WHID) ...

ModSecurity Advanced Topic of the Week: Inbound/Outbound Correlation

March 11, 2011 | Ryan Barnett

Alert Management - Correlated Events One important alert management issue for ...

TWSL2011-003: Vulnerabilities in Avocent Cyclades ACS Web Manager

March 11, 2011 | Josh Grunzweig

The SpiderLabs team at Trustwave published a new advisory today, which details ...

Mobile Visability Limitation? There's an App for that.

March 08, 2011 | Josh Grunzweig

Last July myself and Christian Papathanasiou presented a DEF CON 18 talk ...