ModSecurity is a plugin for Apache web servers that acts as a web app layer firewall. It's used to prevent attacks against script-driven sites through the use of security rules which contain particular expressions. That way, the firewall can prevent hacking and spamming attempts and shield even websites which aren't updated on a regular basis. For instance, numerous failed login attempts to a script administrative area or attempts to execute a certain file with the intention to get access to the script shall trigger certain rules, so ModSecurity will block out these activities the second it identifies them. The firewall is incredibly efficient as it screens the entire HTTP traffic to a website in real time without slowing it down, so it can prevent an attack before any harm is done. It furthermore maintains an exceptionally comprehensive log of all attack attempts which features more info than conventional Apache logs, so you can later examine the data and take further measures to boost the security of your websites if required.

ModSecurity in Hosting

ModSecurity is offered with every single hosting solution which we provide and it is activated by default for any domain or subdomain which you include through your Hepsia Control Panel. In the event that it interferes with any of your applications or you'd like to disable it for whatever reason, you shall be able to do this through the ModSecurity section of Hepsia with merely a mouse click. You can also activate a passive mode, so the firewall will detect potential attacks and maintain a log, but won't take any action. You could see comprehensive logs in the same section, including the IP address where the attack came from, what exactly the attacker tried to do and at what time, what ModSecurity did, and so forth. For optimum protection of our clients we use a group of commercial firewall rules combined with custom ones which are added by our system admins.

ModSecurity in Semi-dedicated Hosting

We've integrated ModSecurity by default inside all semi-dedicated hosting products, so your web apps shall be protected whenever you install them under any domain or subdomain. The Hepsia Control Panel that is included with the semi-dedicated accounts will allow you to enable or turn off the firewall for any site with a click. You shall also have the ability to turn on a passive detection mode with which ModSecurity shall maintain a log of possible attacks without really stopping them. The thorough logs include the nature of the attack and what ModSecurity response this attack triggered, where it originated from, and so on. The list of rules which we employ is frequently updated as to match any new threats that may appear on the Internet and it comes with both commercial rules that we get from a security corporation and custom-written ones that our admins add in case they discover a threat that's not present within the commercial list yet.

ModSecurity in VPS Web Hosting

All virtual private servers which are offered with the Hepsia Control Panel include ModSecurity. The firewall is set up and turned on by default for all domains which are hosted on the server, so there won't be anything special which you'll have to do to protect your websites. It'll take you a mouse click to stop ModSecurity if needed or to switch on its passive mode so that it records what occurs without taking any steps to stop intrusions. You shall be able to view the logs produced in passive or active mode through the corresponding section of Hepsia and find out more about the type of the attack, where it came from, what rule the firewall used to deal with it, etc. We employ a mix of commercial and custom rules in order to make sure that ModSecurity will block out as many risks as possible, consequently boosting the protection of your web programs as much as possible.

ModSecurity in Dedicated Servers Hosting

All of our dedicated servers which are set up with the Hepsia hosting CP come with ModSecurity, so any program which you upload or install will be protected from the very beginning and you will not need to concern yourself with common attacks or vulnerabilities. A separate section in Hepsia will allow you to start or stop the firewall for any domain or subdomain, or turn on a detection mode so that it records information regarding intrusions, but does not take actions to prevent them. What you shall find in the logs can allow you to to secure your sites better - the IP an attack originated from, what website was attacked and in what way, what ModSecurity rule was triggered, etcetera. With this info, you'll be able to see whether a website needs an update, whether you should block IPs from accessing your server, etcetera. In addition to the third-party commercial security rules for ModSecurity we use, our admins add custom ones too if they find a new threat that's not yet included in the commercial bundle.