  1. Yeah, don't do that. See if your hosting provider is willing (and able) to turn off mod_security for you: it's a great thing in theory but reports so many false positives that it just ends up being a pain in the ass. If that's not an option, all you have to do to bypass this particular security measure is to encode the data. For example, with base 64. Submit the data encoded and have your PHP decode it.
  2. Congratulations, you have mod_security installed. Are you on shared hosting or do you have a dedicated server you can control?
  3. 'false' is a string value, not a boolean false. From the PHP manual...
