Join us at Gartner SEC London and discover how LevelBlue can help you secure what’s next. Learn More

SpiderLabs Blog

Explore the latest threats, critical vulnerability disclosures, cutting-edge research, and intelligence from our elite global threat experts.

circleradial-blogs

ModSecurity Migration Matrix

April 11, 2007 | SpiderLabs Anterior

For all of you who are using ModSecurity 1.x and looking for information on ...

Webinar Featuring WHID on the Top Trends in Web Application Threats

April 03, 2007 | SpiderLabs Anterior

On April 11th I'm going to present a webinar on web application security, with ...

Regular Expression Development Tools

March 30, 2007 | SpiderLabs Anterior

Since ModSecurity is based on regular expressions. Writing rules requires ...

2.1/1.x Rule Differences For Identifying Missing/Empty Headers and Variables

March 22, 2007 | SpiderLabs Anterior

There are certain scenarios where you might want to create white-listed ...

ModSecurity Console: Purpose and Deployment

March 17, 2007 | SpiderLabs Anterior

If you have more then 1 ModSecurity installation, you have undoubtedly run into ...

ModSecurity ASCIIZ Evasion

March 08, 2007 | SpiderLabs Anterior

It has been brought to our attention that a fault in the ModSecurity parsing ...

ModSecurity Status Report

February 23, 2007 | SpiderLabs Anterior

I enjoyed talked about ModSecurity (and web application firewalls) in front of ...

Handling False Positives and Creating Custom Rules

February 17, 2007 | SpiderLabs Anterior

It is inevitable; you will run into some False Positive hits when using web ...

Dealing with Impedance Mismatch

February 07, 2007 | SpiderLabs Anterior

In my previous post I described a potential problem with web application ...

Testing Core Rules Protection For An Example SQL Injection Vulnerability

February 07, 2007 | SpiderLabs Anterior

SANS released their 6th edition of the @RISK Weekly News Letter. In it, there ...

HTTPrint vs. ModSecurity

February 06, 2007

There was a great email posted to the ModSecurity user mail-list today that ...

PHP Peculiarities for ModSecurity Users

February 06, 2007 | SpiderLabs Anterior

As I was reviewing the ModSecurity 2.1.0-rc7 Reference Manual I realised it did ...

ModSecurity 2.1.0 Improvements

February 05, 2007 | SpiderLabs Anterior

I have just packaged and released ModSecurity for Apache v2.1.0-rc7, in ...

SANS @Risk Web Vulnerabilities List Mitigation Steps

January 30, 2007 | SpiderLabs Anterior

This is a listing of Web Application Vulnerabilities that were released by SANS ...

Top 10 Web Hacks of 2006

January 23, 2007 | SpiderLabs Anterior

Jeremiah Grossman gives an excellent overview of the top Web hacks of 2006. If ...

Key Advantages of the Core Rule Set

January 03, 2007 | SpiderLabs Anterior

Following a question on the core rule set on the ModSecuirty mailing list, I ...

Using ModSecurity 2 Collections in Rules

December 28, 2006 | Trustwave SpiderLabs

A recent posting on the ModSecurity mailing list by K.C. Li is a very good ...

ModSecurity v2.0 Webcast

December 07, 2006 | Trustwave SpiderLabs

In response to many of the common questions and issues posted to the mail-list, ...

Talking About ModSecurity 2.0 With Federico Biancuzzi for SecurityFocus

October 24, 2006 | SpiderLabs Anterior

A while ago Federico Biancuzzi contacted me to ask if I'd be interested to give ...

ModSecurity Cookie and Link Protection Patch

August 18, 2006 | SpiderLabs Anterior

A significant event occurred on the mod-security-users mailing list in July: a ...

ModSecurity Performance Tip

August 17, 2006 | SpiderLabs Anterior

I was asked recently to investigate performance of an ModSecurity installation ...

Apache Reverse Proxy Memory Consumption Observations

August 14, 2006 | SpiderLabs Anterior

Last week I spent some time stress-testing Apache 2.2.3 configured to work as a ...

ModSecurity 1.9.x Performance Testing

August 07, 2006 | SpiderLabs Anterior

You can tell that I am too busy when I take almost three months to blog about ...

Forrester Research Q2 2006 Web Application Firewall Evaluation

July 24, 2006 | SpiderLabs Anterior

Back in March 2006 I was approached by Forrester Research and invited to ...

Yahoo Small Business offers 'ModSecurity-like' functionality

July 12, 2006 | SpiderLabs Anterior

I just came across this and can't help but make a note about it: A web hosting ...

ModSecurity Console Now Available

July 04, 2006 | SpiderLabs Anterior

I love the command line, I do. But there are some tasks where this type of user ...

ModSecurity 2: Explicit Normalisation Options

June 28, 2006 | SpiderLabs Anterior

One of the things I realy dislike in ModSecurity 1.x is that its anti-evasion ...

Secure Browsing Mode Proposal

June 27, 2006 | SpiderLabs Anterior

It's very well known (and even widely accepted) that our current web ...