Trustwave’s SpiderLabs has announced the availability of version 2.8.0 of ModSecurity, the open-source, cross-platform Web application firewall (WAF) engine for IIS, Apache and Nginx.
The latest version comes with status reporting, a JSON request body parser and @detectXSS operator. The list of new features also includes FULL_REQUEST and FULL_REQUEST_LENGTH variables, and SecConnReadStateLimit and SecConnWriteStateLimit directives.
The status reporting feature enables the tools…