<?xml version="1.0"?>
<rss version="2.0">
<channel>
  <title>WebSecurity Blog @ jwall.org</title>
  <link>https://secure.jwall.org/blog/</link>
  <description>WebSecurity Blog @ jwall.org</description>
  <language>en</language>
  <copyright>Christian Bockermann</copyright>
  <lastBuildDate>Wed, 10 Dec 2008 20:04:19 GMT</lastBuildDate>
  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  
  
  <item>
    <title>Positive Security Models and ModSecurity</title>
    <link>https://secure.jwall.org/blog/2008/12/10/1228939459690.html</link>
    
      
      
        <description>
          The ModSecurity Apache tools is a powerful and effective weapon against a variety of threats to web-applications - if setup properly and fitted with the right rulesets. Unfortunately does the creation of rulesets require a lot of low-level expert knowledge, which makes rules often appear complicated and error-prone. 

In this blog-post I want to introduce the concept of abstract web-application profiles and provide an easy tutorial on how rulesets can be enhanced using white-listing approaches and the WebProfileEditor, developed at jwall.org.&lt;p&gt;&lt;a href=&#034;https://secure.jwall.org/blog/2008/12/10/1228939459690.html&#034;&gt;Read more...&lt;/a&gt;&lt;/p&gt;
        </description>
      
    
    
    
    <comments>https://secure.jwall.org/blog/2008/12/10/1228939459690.html#comments</comments>
    <guid isPermaLink="true">https://secure.jwall.org/blog/2008/12/10/1228939459690.html</guid>
    <pubDate>Wed, 10 Dec 2008 20:04:19 GMT</pubDate>
  </item>
  
  <item>
    <title>Speaking at OWASP Conference in Frankfurt</title>
    <link>https://secure.jwall.org/blog/2008/11/28/1227861105807.html</link>
    
      
      
        <description>
          &lt;p&gt;
Thanks to Thomas, Boris and Georg for re-launching the OWASP chapter Germany! The first
German conference on Web-Application Security raised big interest, taking into account the little preparation time.
&lt;/p&gt;
&lt;p&gt;
Having been a &lt;i&gt;passive observer&lt;/i&gt; of OWASP and its activities in the last years I have been given the opportunity to actively take part at the OWASP conference in Frankfurt.
&lt;/p&gt;&lt;p&gt;&lt;a href=&#034;https://secure.jwall.org/blog/2008/11/28/1227861105807.html&#034;&gt;Read more...&lt;/a&gt;&lt;/p&gt;
        </description>
      
    
    
    <enclosure url="http://www.jwall.org/OWASP_Germany_2008_LearningPositiveModels.pdf" length="433569" type="pdf" />
    
    
    <comments>https://secure.jwall.org/blog/2008/11/28/1227861105807.html#comments</comments>
    <guid isPermaLink="true">https://secure.jwall.org/blog/2008/11/28/1227861105807.html</guid>
    <pubDate>Fri, 28 Nov 2008 08:31:45 GMT</pubDate>
  </item>
  
  <item>
    <title>BugFixes in web-audit Library and AuditViewer</title>
    <link>https://secure.jwall.org/blog/2008/11/19/1227113482919.html</link>
    
      
      
        <description>
          &lt;p&gt;
A few bugs have been reported in the AuditViewer all of which were related to errors in the web-audit library. These have been fixed in the current release 0.2.15 of the library.
&lt;/p&gt;
&lt;p&gt;
The lastest binary release (0.3.3c) of the AuditViewer now does include the 0.2.15 version of the audit library and the bugfixes. 
&lt;/p&gt;&lt;p&gt;&lt;a href=&#034;https://secure.jwall.org/blog/2008/11/19/1227113482919.html&#034;&gt;Read more...&lt;/a&gt;&lt;/p&gt;
        </description>
      
    
    
    
    <comments>https://secure.jwall.org/blog/2008/11/19/1227113482919.html#comments</comments>
    <guid isPermaLink="true">https://secure.jwall.org/blog/2008/11/19/1227113482919.html</guid>
    <pubDate>Wed, 19 Nov 2008 16:51:22 GMT</pubDate>
  </item>
  
  </channel>
</rss>
