New blog post on Passive Vulnerability Scanning. Adds ModSecurity functionality that monitors for the use of vulnerable applications, using OSVDB as a data source. Combined with the ability to detect exploitation attempts, this feature provides a more holistic view of a web application's security condition.
http://blog.spiderlabs.com/2011/02/modsecurity-advanced-topic-of-the-week-passive-vulnerability-scanning-part-1-osvdb-checks.html -- Ryan Barnett Senior Security Researcher Trustwave - SpiderLabs _______________________________________________ Owasp-modsecurity-core-rule-set mailing list [email protected] https://lists.owasp.org/mailman/listinfo/owasp-modsecurity-core-rule-set
