ModSecurity is a plugin for Apache web servers which acts as a web app layer firewall. It's employed to prevent attacks towards script-driven sites by employing security rules that contain particular expressions. This way, the firewall can prevent hacking and spamming attempts and protect even sites which are not updated often. For example, multiple unsuccessful login attempts to a script admin area or attempts to execute a specific file with the intention to get access to the script shall trigger certain rules, so ModSecurity will block these activities the minute it identifies them. The firewall is extremely efficient since it tracks the whole HTTP traffic to an Internet site in real time without slowing it down, so it can easily prevent an attack before any damage is done. It also keeps an incredibly detailed log of all attack attempts which includes more info than conventional Apache logs, so you could later analyze the data and take additional measures to enhance the security of your websites if needed.

ModSecurity in Web Hosting

ModSecurity comes by default with all web hosting packages that we supply and it'll be switched on automatically for any domain or subdomain that you add/create within your Hepsia hosting Control Panel. The firewall has three different modes, so you can activate and deactivate it with simply a click or set it to detection mode, so it'll maintain a log of all attacks, but it will not do anything to prevent them. The log for each of your Internet sites will feature in-depth info including the nature of the attack, where it came from, what action was taken by ModSecurity, and so forth. The firewall rules which we use are constantly updated and comprise of both commercial ones we get from a third-party security firm and custom ones which our system admins add in case that they detect a new sort of attacks. That way, the websites that you host here will be much more protected with no action required on your end.

ModSecurity in Semi-dedicated Hosting

We've incorporated ModSecurity as a standard in all semi-dedicated hosting packages, so your web applications will be protected whenever you install them under any domain or subdomain. The Hepsia CP that is included with the semi-dedicated accounts will allow you to enable or disable the firewall for any site with a click. You will also be able to switch on a passive detection mode in which ModSecurity shall maintain a log of possible attacks without really preventing them. The thorough logs include the nature of the attack and what ModSecurity response this attack caused, where it originated from, etcetera. The list of rules we use is frequently updated in order to match any new threats that may appear on the Internet and it features both commercial rules that we get from a security company and custom-written ones that our administrators add in case they discover a threat which is not present inside the commercial list yet.

ModSecurity in VPS Hosting

All virtual private servers that are set up with the Hepsia CP include ModSecurity. The firewall is installed and activated by default for all domains that are hosted on the web server, so there will not be anything special that you'll have to do to protect your sites. It'll take you simply a mouse click to stop ModSecurity if necessary or to switch on its passive mode so that it records what occurs without taking any measures to stop intrusions. You'll be able to view the logs generated in active or passive mode from the corresponding section of Hepsia and find out more about the type of the attack, where it originated from, what rule the firewall used to tackle it, etc. We employ a mixture of commercial and custom rules in order to make sure that ModSecurity will prevent as many risks as possible, hence boosting the protection of your web applications as much as possible.

ModSecurity in Dedicated Web Hosting

If you opt to host your websites on a dedicated server with the Hepsia CP, your web applications will be secured straight away since ModSecurity is provided with all Hepsia-based plans. You shall be able to regulate the firewall without difficulty and if needed, you shall be able to turn it off or enable its passive mode when it will only maintain a log of what's going on without taking any action to prevent potential attacks. The logs which you can find in the same section of the CP are quite detailed and feature info about the attacker IP address, what website and file were attacked and in what way, what rule the firewall used to stop the intrusion, and so on. This information will enable you to take measures and enhance the protection of your Internet sites even more. To be on the safe side, we use not only commercial rules, but also custom-made ones which our staff add when they detect attacks that haven't yet been included in the commercial pack.