Posted by Jozef Sudolsky on Aug 18
Dear community,
I’d like to share a small tool I’ve recently released – CRSprober.
This utility is designed to remotely detect the version of the OWASP
CRS as well as the configured paranoia level on a target protected by
ModSecurity + CRS.
It works by sending specific payloads and analyzing the WAF’s
responses to determine this information. This can be useful for
testing, research, or verification purposes, especially when…
– Read More – Full Disclosure



