← Prev in month ← Prev in thread
Next in thread → Next in month →

WAS Protect update

From
Ivan Ristic <>
Date
2004-07-14T19:58:32+00:00
ID
Thread
WAS Protect update
>> I'll send stuff I produce to the mailing list. My plan is to:
>>
>> 1. Produce another version of the "spec"
>> 2. Use it for the reference implementation
>> 3. Update the spec if necessary
>> 4. Document everything
>>
>> As far as mod_security/Apache is concerned, Protect will probably
>> be implemented as a wrapper around the existing functionality.

  I've started to work on WAS Protect. I have attached my best
  attempt at the protection language. Before I go and make this
  into a formal specification I would like to hear your
  opinions.

  Now is the time to make changes!  :)

  To summarize the changes: my previous effort was ambitious,
  maybe too ambitious. For most of my language constructs I was
  unable to find use cases so I decided to simplify. I did that
  and I like the result. The examples are at the bottom of
  the file, I think they demonstrate how easy it can be
  to protect an application. At the same time, I think the
  format allows for extensions, should we decide to make them
  in the future.

  There is no meta-data here. Each protection recipe relates
  to a WAS vulnerability. The role of a recipe is to inspect
  the variables at one of four (practically three) processing
  stages, and invoke an error/warning/notice where appropriate.

-- 
ModSecurity (http://www.modsecurity.org)
[ Open source IDS for Web applications ]
← Prev in month ← Prev in thread
Next in thread → Next in month →