Originally Posted by Philipp
I just found an easy way to check whether ModSecurity is present. Just add cmd.exe somewhere in the URL.

For example: DOMAIN/forums/ubbthreads.php/cmd.exe

This will trigger one of the more ridiculous ModSecurity rules and should return 403 Forbidden on server with enabled ModSecurity. Servers without ModSecurity will ignore this.

that results in Forbidden
You don't have permission to access this resource.


"No matter where you go, there you are."
"If you can't do something smart, Do something right"
"There are three kinds of people in the world, those who can count, and those who can't"