Andrew Howe

Hello! I'm Andrew, a:

among other things.

Talk to me about WAF consultancy and ModSecurity WAFs!
🖄 andrew [at] ahowe.org

GitHub | LinkedIn | Stack Overflow | Alignment | 🔑 PGP key

Things I've written

9 November 2023

Interview: Meet the CRS team: Andrew, the technical writer who loves Eurovision and Doom II

26 October 2023

Release announcement at coreruleset.org:
CRS version 4.0.0 release candidate 2 available

24 July 2023

Release announcement at coreruleset.org:
CRS version 3.3.5 released

17 July 2023

CVE blog post at coreruleset.org:
CVE-2023-38199 – Multiple Content-Type Headers

13 June 2023

Why you shouldn't lose sleep over the commercial end-of-life of ModSecurity

26 May 2023

Three scenarios for implementing time-based security and content switching on your load balancer

24 February 2023

Report back from the OWASP Core Rule Set Community Summit and OWASP Global AppSec Dublin 2023

14 February 2023

(Video) Talk delivered at the CRS Community Summit: A CRS Integrator's Perspective: Changing Real World Customer Needs

19 September 2022

Co-wrote CVE advisories and blog post over at coreruleset.org:
CRS Version 3.3.3 and 3.2.2 (covering several CVEs)

9 June 2022

Handling large requests with a WAF while avoiding denial-of-service attacks

28 February 2022

Achieving unrivaled performance with media and video streaming on demand

21 January 2022

ModSecurity DoS vulnerability (CVE-2021-42717)

17 January 2022

Simplifying web application security with the Core Rule Set v3

6 January 2022

The importance of outreach: Introducing students to load balancing

13 August 2021

(With video) Extending ModSecurity: How to add completely custom WAF functionality

30 June 2021

I discovered my first CVE-worthy vulnerability!
Announcing CVE-2021-35368: OWASP ModSecurity Core Rule Set Bypass

26 February 2021

(Video) Round table discussion about FLOSS ("Open source software: myth-busting, business benefits and FOSDEM '21")

8 January 2021

ModSecurity and the Case of the Never Decreasing Variables

21 May 2020

(With video) Layer 4 vs Layer 7 load balancing - we still love DSR, but…

23 December 2019

HAProxy Conference 2019

3 December 2019

Security through geography: blocking traffic by country, continent, or IP address using ModSecurity

20 June 2019

SACK Panic: What is it, and is it actually time to panic?

20 December 2018

15 years later, we still love DSR