ModSecurity Trustwave's SpiderLabs



News and Updates

Availability of ModSecurity 2.7.4 Stable Release
(May 27, 2013)
The ModSecurity Development Team is pleased to announce the availability of ModSecurity 2.7.4 Stable Release.The stability of this release is good, includes many bug fixes and some new features.
NGINX module version is now STABLE. We added support to libinjection as a new operator @detectSQLi. There is a security issue fixed with this release, please check CVE-2013-2765 for more information.
Please see the release notes included into CHANGES file. For known problems and more information about bug fixes, please see the online ModSecurity Jira. Please report any bug to mod-security-developers@lists.sourceforge.net.

Availability of ModSecurity 2.7.3 Stable Release
(March 29, 2013)
The ModSecurity Development Team is pleased to announce the availability of ModSecurity 2.7.3 Stable Release.The stability of this release is good and includes many bug fixes.
Many issues and missing features for NGINX module were fixed. NGINX module version is now RC. We have fixed some minor issues for IIS. We also added some important new features, the ability to load some specific directives into .htaccess files and the SecXmlExternalEntity security feature that will disable by default the possibility to load xml external entities. We recommend all users use this version.
Please see the release notes included into CHANGES file. For known problems and more information about bug fixes, please see the online ModSecurity Jira. Please report any bug to mod-security-developers@lists.sourceforge.net.

Trustwave SpiderLabs Releases Commercial Rules Feed and Support
(September 22, 2011)

Trustwave is now offering both ModSecurity Rules from Trustwave SpiderLabs and ModSecurity Support. The pricing for these services are $200.00 per instance and $2,000.00 per instance respectively - volume discounts available.


ModSecurity Blog

Support/Mailing lists

Community support is available on the mod-security-users/lists.sourceforge.net mailing list. You must subscribe first (by clicking here) in order to post. The list archives are available as News (NNTP), Threaded HTTP, Bloggy HTTP, and RSS.

NOTE: Support for the Core Rule Set has moved to a the owasp-modsecurity-core-rule-set mail list.
ModSecurity Status (v2.7.4)
Apache (Stable): download
IIS (Stable): download
Nginx (Stable): download