Great writeup. It's clear, it's concise and it's not overly dramatic. Thanks for taking the time to write this up and share it.<p>I have invested a bit of time installing and tuning mod_security. I'd love to know how it'd have faired against this attack, probably it wouldn't have stopped the upload, but it might have stopped a lot of payload/control commands from working.