From: Ivan Ristic <ivanr@we...> - 2004-06-22 14:14:46
Mod_security 1.8.2 has been released. It is available for immediate
Version 1.8.2 is a maintenance release that fixes all the known
issues with the recently released version 1.8.
Mod_security is an Apache module whose purpose is to protect
vulnerable applications and reject human or automated attacks.
It is an open source intrusion detection and prevention system
for Apache. In addition to request filtering, it also creates Web
application audit logs. Requests are filtered using regular
expressions. Some of the things possible are:
* Apply filters against any part of the request (URI,
headers, either GET or POST)
* Apply filters against individual parameters
* Reject SQL injection attacks
* Reject Cross site scripting attacks
With few general rules mod_security can protect from both
known and unknown vulnerabilities.
* Zero-length POST payloads are now allowed.
* The Apache function ap_escape_logitem is no longer
used, allowing mod_security to be used with older Apache
* The bug resulting in the closure of stdin during
multipart/form-data requests was fixed.
* POST payload scanning during multipart/form-data requests
now works properly.
* An error in the default configuration file was fixed.
[ Open source IDS for Web applications ]