Hello! I'm Andrew, a:
among other things.
Talk to me about WAF consultancy, ModSecurity, and WAFs!
π
andrew [at] ahowe.org
GitHub | LinkedIn | Stack Overflow | π PGP key
11 LoadMaster Protections for AI Workloads and APIs (Part I)
Virtual Patching with LoadMaster WAF: A Case Study on WordPress CVE-2026-63030
(Video) π¬ Webinar: Security at Your Fingertips: Defending APIs with LoadMaster
LoadMaster βClusteringβ Feature Being Deprecated in July 2026
(Video) π¬ The LoadMaster WAF: Anomaly Scoring and Strategies for Rule Tuning
(Video) π¬ The LoadMaster WAF: False Positives and Rule Tuning
(Video) π¬ The LoadMaster Web Application Firewall (WAF): First Steps in 2 Minutes
Unlocking Web Application Firewall Essentials: From Beginner to Advanced
(Video) π¬ Webinar: WAF Essentials Unlocked: Everything You Need from Beginner to Advanced
Improve Protection Against React2Shell Vulnerability Using Progress Kemp LoadMaster WAF
Defending AI Applications from Invisible Prompt Injection Using LoadMaster WAF
Help Protect SharePoint from CVE-2025-53770 with LoadMaster WAF
What Are WAF False Positives, Why Should I Care and How Can I Fix Them?
(Video) π¬ Webinar: Defending Web Apps and APIs: A Flexible Web Application Firewall
Retired "Legacy WAF" Option Being Removed in LMOS Version 7.2.61.0
Interview: Meet the CRS team: Andrew, the technical writer who loves Eurovision and Doom II
Release announcement at coreruleset.org:
CRS
version 4.0.0 release candidate 2 available
Release announcement at coreruleset.org:
CRS
version 3.3.5 released
CVE blog post at coreruleset.org:
CVE-2023-38199
β Multiple Content-Type Headers
Why you shouldn't lose sleep over the commercial end-of-life of ModSecurity
Three scenarios for implementing time-based security and content switching on your load balancer
Report back from the OWASP Core Rule Set Community Summit and OWASP Global AppSec Dublin 2023
Co-wrote CVE advisories and blog post over at coreruleset.org:
CRS
Version 3.3.3 and 3.2.2 (covering several CVEs)
Handling large requests with a WAF while avoiding denial-of-service attacks
Achieving unrivaled performance with media and video streaming on demand
Simplifying web application security with the Core Rule Set v3
The importance of outreach: Introducing students to load balancing
(With video) π¬ Extending ModSecurity: How to add completely custom WAF functionality
I discovered my first CVE-worthy vulnerability!
Announcing
CVE-2021-35368: OWASP ModSecurity Core Rule Set Bypass
(With video) π¬ Layer 4 vs Layer 7 load balancing - we still love DSR, butβ¦
Security through geography: blocking traffic by country, continent, or IP address using ModSecurity