ModSecurity Handbook, Second Edition

ModSecurity Handbook is the definitive guide to ModSecurity, the popular open source web application firewall. Written by...
€92,28 EUR
€92,28 EUR
SKU: 9781907117077
Product Type: Books
Please hurry! Only 714 left in stock
Author: Christian Folini
Format: Paperback
Language: English
Subtotal: €92,28
10 customers are viewing this product
ModSecurity Handbook, Second Edition by Folini, Christian

ModSecurity Handbook, Second Edition

€92,28

ModSecurity Handbook, Second Edition

€92,28
Author: Christian Folini
Format: Paperback
Language: English

ModSecurity Handbook is the definitive guide to ModSecurity, the popular open source web application firewall. Written by Christian Folini and ModSecurity's original developer, Ivan Ristic, this book will teach you how to monitor activity on your web sites and protect them from attack.

Situated between your web sites and the world, web application firewalls provide an additional security layer, monitoring everything that comes in and everything that goes out in real time. They enable you to perform many advanced activities, such as access control, virtual patching, HTTP traffic logging, continuous passive security assessment, and web application hardening. Web application firewalls can be very effective in preventing application security attacks, such as SQL injection, cross-site scripting, remote file inclusion, and others that plague most web sites today.

ModSecurity Handbook covers the following topics, which will help anyone with a web site to run:

  • Installation and configuration of ModSecurity
  • Detailed guide to writing rules
  • IP address, session, and user tracking
  • Session management hardening
  • Whitelisting, blacklisting, and IP reputation management
  • Anomaly scoring and advanced blocking strategies
  • Integration with other Apache modules
  • Working with predefined rule sets
  • Virtual patching and content injection
  • Performance considerations
  • Writing rules in Lua and extending ModSecurity in C
  • Detailed coverage of ModSecurity's numerous directives, variables, transformations, and operators

The book is suitable for all reader levels: It takes newcomers by the hand to turn them into seasoned users, while seasoned users will learn advanced techniques from the top experts on the subject and find hidden clues to master the rule language. An updated ModSecurity Reference Manual is included in the second part of the book.

ABOUT THE AUTHORS

Dr. Christian Folini is a twelve-year veteran of ModSecurity. He is a renowned speaker, teacher, and system engineer who has specialized in securing high-profile web servers. Christian is one of the leaders of the OWASP ModSecurity Core Rule Set project, a key member of the ModSecurity community, program chair of the Swiss Cyber Storm conference, and vice president of Swiss Cyber Experts (a public-private partnership).

Ivan Ristic is a security researcher, engineer, and author, known especially for his contributions to the web application firewall field and development of ModSecurity, an open source web application firewall, and for his SSL/TLS and PKI research, tools and guides published on the SSL Labs web site. His latest project, Hardenize, is a security posture analysis service that makes security fun again. He is the author of three books, Apache Security, ModSecurity Handbook, and Bulletproof SSL and TLS.



Author: Christian Folini, Ivan Ristic
Publisher: Feisty Duck
Published: 07/15/2017
Pages: 454
Binding Type: Paperback
Weight: 1.71lbs
Size: 9.25h x 7.50w x 0.92d
ISBN: 9781907117077

About the Author
Folini, Christian: - Dr. Christian Folini is a partner at netnea AG in Berne, Switzerland. He holds a PhD in medieval history and enjoys defending castles across Europe. Unfortunately, defending medieval castles is not a big business these days, so Christian turned to defending web servers, which he thinks is equally challenging. With his background in humanities, Christian is able to bridge the gap between techies and nontechies. He has more than ten years of experience in this role, specializing in Apache/ModSecurity configuration, DDoS defense, and threat modeling. Christian is a frequent committer to the OWASP ModSecurity Core Rule Set, vice president of Swiss Cyber Experts (a public-private partnership), program chair of the Swiss Cyberstorm conference, and president of the Company of St. George, a well-known historical reenactment group.Ristic, Ivan: - "Ivan Ristic is a security researcher, engineer, and author, known especially for his contributions to the web application firewall field and development of ModSecurity, an open source web application firewall, and for his SSL/TLS and PKI research, tools and guides published on the SSL Labs web site. He is the author of three books, Apache Security (2005), ModSecurity Handbook (2010), and Bulletproof SSL and TLS (2014), which he publishes via Feisty Duck, his own platform for continuous writing and publishing. Ivan is an active participant in the security community and you'll often find him speaking at security conferences such as Black Hat, RSA, OWASP AppSec, and others. He is currently working on Hardenize - a brand-new comprehensive security posture analysis service that makes security fun again."

This title is not returnable

Returns Policy

You may return most new, unopened items within 30 days of delivery for a full refund. We'll also pay the return shipping costs if the return is a result of our error (you received an incorrect or defective item, etc.).

You should expect to receive your refund within four weeks of giving your package to the return shipper, however, in many cases you will receive a refund more quickly. This time period includes the transit time for us to receive your return from the shipper (5 to 10 business days), the time it takes us to process your return once we receive it (3 to 5 business days), and the time it takes your bank to process our refund request (5 to 10 business days).

If you need to return an item, simply login to your account, view the order using the "Complete Orders" link under the My Account menu and click the Return Item(s) button. We'll notify you via e-mail of your refund once we've received and processed the returned item.

Shipping

We can ship to virtually any address in the world. Note that there are restrictions on some products, and some products cannot be shipped to international destinations.

When you place an order, we will estimate shipping and delivery dates for you based on the availability of your items and the shipping options you choose. Depending on the shipping provider you choose, shipping date estimates may appear on the shipping quotes page.

Please also note that the shipping rates for many items we sell are weight-based. The weight of any such item can be found on its detail page. To reflect the policies of the shipping companies we use, all weights will be rounded up to the next full pound.

Related Products

Recently Viewed Products