CRS3


Techniques for a CRS 4 Migration When Things Get Hairy   Recently updated !

Here at netnea, our job is to help customers run and manage their ModSecurity / OWASP CRS based WAFs. Right now, the migration of existing installations to CRS 4 is a major concern for many of them. And it rarely comes alone: There are business constraints, tight schedules, a lack of resources (and in-house know-how), […]


An A7 First Aid Kit

Let’s consider Dave Wichers and the OWASP Top 10 project resists all the pressure and the 2017 edition of OWASP Top 10 will include the new A7 “Insufficient Attack Protection”. Lately the discussion has turned more constructive so maybe that prospect is not all that unrealistic. But honestly, I can not tell if A7 will […]


Securing Drupal with ModSecurity and the Core Rule Set (CRS3)

The new Core Rule Set 3.0 (CRS3) release simplifies ModSecurity/Drupal integration tremendously. Here is a guide aimed at the Drupal community to learn how to work with ModSecurity. This guide and the rule file it is based on currently covers Drupal Core. Modules / Plugins are not yet supported. But count on the Drupal community […]