ModSecurity is a plugin for Apache web servers which acts as a web app layer firewall. It's employed to stop attacks against script-driven sites by employing security rules which contain specific expressions. This way, the firewall can block hacking and spamming attempts and shield even sites which are not updated on a regular basis. As an example, multiple failed login attempts to a script admin area or attempts to execute a certain file with the intention to get access to the script will trigger certain rules, so ModSecurity shall block out these activities the second it discovers them. The firewall is quite efficient since it screens the whole HTTP traffic to an Internet site in real time without slowing it down, so it can prevent an attack before any damage is done. It additionally maintains an exceptionally thorough log of all attack attempts which contains more info than standard Apache logs, so you can later examine the data and take extra measures to improve the security of your Internet sites if required.

ModSecurity in Cloud Web Hosting

ModSecurity is supplied with all cloud web hosting machines, so if you decide to host your sites with our firm, they will be shielded from a wide range of attacks. The firewall is enabled by default for all domains and subdomains, so there will be nothing you will need to do on your end. You'll be able to stop ModSecurity for any Internet site if required, or to switch on a detection mode, so that all activity will be recorded, but the firewall shall not take any real action. You shall be able to view specific logs via your Hepsia CP including the IP address where the attack came from, what the attacker planned to do and how ModSecurity dealt with the threat. Since we take the security of our clients' sites seriously, we employ a group of commercial rules which we take from one of the best companies which maintain this sort of rules. Our admins also add custom rules to make sure that your Internet sites shall be shielded from as many risks as possible.

ModSecurity in Semi-dedicated Servers

ModSecurity is part of our semi-dedicated server packages and if you choose to host your sites with us, there will not be anything special you'll have to do given that the firewall is activated by default for all domains and subdomains you add via your hosting Control Panel. If required, you can disable ModSecurity for a given Internet site or switch on the so-called detection mode in which case the firewall shall still operate and record information, but won't do anything to stop potential attacks on your websites. Detailed logs shall be readily available in your CP and you will be able to see which kind of attacks occurred, what security rules were triggered and how the firewall dealt with the threats, what IP addresses the attacks came from, and so forth. We employ 2 sorts of rules on our servers - commercial ones from a firm that operates in the field of web security, and custom made ones that our admins often add to respond to newly identified risks promptly.

ModSecurity in VPS Servers

ModSecurity is pre-installed on all VPS servers that are offered with the Hepsia hosting Control Panel, so your web programs will be secured from the instant your server is in a position. The firewall is activated by default for any domain or subdomain on the Virtual Private Server, but if needed, you can deactivate it with a mouse click from the corresponding section of Hepsia. You may also set it to function in detection mode, so it shall maintain a detailed log of any possible attacks without taking any action to stop them. The logs can be found in the very same section and provide information regarding the nature of the attack, what IP it came from and what ModSecurity rule was triggered to stop it. For optimum security, we employ not only commercial rules from a company working in the field of web security, but also custom ones our admins add personally in order to react to new threats which are still not dealt with in the commercial rules.

ModSecurity in Dedicated Servers

ModSecurity comes with all dedicated servers which are integrated with our Hepsia CP and you will not need to do anything specific on your end to employ it since it's switched on by default every time you add a new domain or subdomain on your web server. In case it interferes with some of your applications, you will be able to stop it through the respective part of Hepsia, or you could leave it working in passive mode, so it shall recognize attacks and shall still keep a log for them, but shall not prevent them. You'll be able to look at the logs later to determine what you can do to enhance the protection of your websites since you shall find information such as where an intrusion attempt came from, what site was attacked and based on what rule ModSecurity reacted, etc. The rules that we employ are commercial, hence they're constantly updated by a security company, but to be on the safe side, our staff also add custom rules occasionally as to deal with any new threats they have identified.