ModSecurity Handbook, Second Edition
Folini, Christian; Ristic, Ivan
Language: English
Published by Feisty Duck, 2017
- Softcover
- Used

Seller: ThriftBooks-Dallas, Dallas, TX, U.S.A.ThriftBooks-Dallas
AbeBooks seller since July 2, 2009
Condition: Used - Good
US$ 25.59
Quantity: 1 available
Add to basketItem description from seller
Seller Inventory # G1907117075I3N00
- Title
- ModSecurity Handbook, Second Edition
- Author
- Folini, Christian; Ristic, Ivan
- Publisher
- Feisty Duck
- Publication year
- 2017
- Condition
- Good
- Dust jacket
- No Jacket
- Binding
- Paperback
- Language
- English
- ISBN 10
- 1907117075
- ISBN 13
- 9781907117077
- Edition
- 2nd Edition
- Item weight
- 1.75 pounds
ModSecurity Handbook is the definitive guide to ModSecurity, the popular open source web application firewall. Written by Christian Folini and ModSecurity's original developer, Ivan Ristic, this book will teach you how to monitor activity on your web sites and protect them from attack.
Situated between your web sites and the world, web application firewalls provide an additional security layer, monitoring everything that comes in and everything that goes out in real time. They enable you to perform many advanced activities, such as access control, virtual patching, HTTP traffic logging, continuous passive security assessment, and web application hardening. Web application firewalls can be very effective in preventing application security attacks, such as SQL injection, cross-site scripting, remote file inclusion, and others that plague most web sites today.
ModSecurity Handbook covers the following topics, which will help anyone with a web site to run:
- Installation and configuration of ModSecurity
- Detailed guide to writing rules
- IP address, session, and user tracking
- Session management hardening
- Whitelisting, blacklisting, and IP reputation management
- Anomaly scoring and advanced blocking strategies
- Integration with other Apache modules
- Working with predefined rule sets
- Virtual patching and content injection
- Performance considerations
- Writing rules in Lua and extending ModSecurity in C
- Detailed coverage of ModSecurity's numerous directives, variables, transformations, and operators
The book is suitable for all reader levels: It takes newcomers by the hand to turn them into seasoned users, while seasoned users will learn advanced techniques from the top experts on the subject and find hidden clues to master the rule language. An updated ModSecurity Reference Manual is included in the second part of the book.
ABOUT THE AUTHORS
Dr. Christian Folini is a twelve-year veteran of ModSecurity. He is a renowned speaker, teacher, and system engineer who has specialized in securing high-profile web servers. Christian is one of the leaders of the OWASP ModSecurity Core Rule Set project, a key member of the ModSecurity community, program chair of the Swiss Cyber Storm conference, and vice president of Swiss Cyber Experts (a public-private partnership).
Ivan Ristic is a security researcher, engineer, and author, known especially for his contributions to the web application firewall field and development of ModSecurity, an open source web application firewall, and for his SSL/TLS and PKI research, tools and guides published on the SSL Labs web site. His latest project, Hardenize, is a security posture analysis service that makes security fun again. He is the author of three books, Apache Security, ModSecurity Handbook, and Bulletproof SSL and TLS.
"Synopsis" may belong to another edition of this title.
About the Author
Ivan Ristic is a security researcher, engineer, and author, known especially for his contributions to the web application firewall field and development of ModSecurity, an open source web application firewall, and for his SSL/TLS and PKI research, tools and guides published on the SSL Labs web site. He is the author of three books, Apache Security (2005), ModSecurity Handbook (2010), and Bulletproof SSL and TLS (2014), which he publishes via Feisty Duck, his own platform for continuous writing and publishing. Ivan is an active participant in the security community and you'll often find him speaking at security conferences such as Black Hat, RSA, OWASP AppSec, and others. He is currently working on Hardenize - a brand-new comprehensive security posture analysis service that makes security fun again.
"About the title" may belong to another edition of this title.
ThriftBooks-Dallas
Dallas, TX, U.S.A.
AbeBooks seller since July 2, 2009
Shipping rates within U.S.A.
| Item | 4 to 8 business days | 4 to 8 business days |
|---|---|---|
| First item | US$ 0.00 | US$ 0.00 |
Payment methods
Store description
Seller's business information
Thrift Books Global LLC
18300 Cascade Ave S
Seattle, WA U.S.A. 98188
Terms of sale
We guarantee each book that we send you. If you have any problems, please contact
our dedicated customer service department. They will do everything possible to
ensure you are happy with your order.
Shipping terms
All domestic Standard shipments are distributed from our warehouses by OSM, then handed off to the USPS for final delivery.
2-Day Shipping is delivered by FedEx, which does not deliver to PO boxes.
International shipments are tendered to the local postal service in the destination country for final delivery – We do not use courier services for international deliveries.