ModSecurity is a highly effective web app layer firewall for Apache web servers. It monitors the entire HTTP traffic to an Internet site without affecting its performance and in case it discovers an intrusion attempt, it blocks it. The firewall furthermore keeps a more comprehensive log for the website visitors than any server does, so you will manage to keep an eye on what is happening with your Internet sites a lot better than if you rely only on standard logs. ModSecurity employs security rules based on which it helps prevent attacks. For example, it recognizes if someone is attempting to log in to the administrator area of a particular script a number of times or if a request is sent to execute a file with a certain command. In such circumstances these attempts set off the corresponding rules and the firewall hinders the attempts right away, then records detailed info about them within its logs. ModSecurity is amongst the best software firewalls available and it can easily protect your web apps against a huge number of threats and vulnerabilities, especially if you don’t update them or their plugins regularly.

ModSecurity in Shared Web Hosting

We provide ModSecurity with all shared web hosting packages, so your web apps will be shielded from destructive attacks. The firewall is switched on by default for all domains and subdomains, but if you would like, you'll be able to stop it through the respective part of your Hepsia Control Panel. You'll be able to also activate a detection mode, so ModSecurity shall keep a log as intended, but shall not take any action. The logs which you will find within Hepsia are incredibly detailed and feature information about the nature of any attack, when it took place and from what IP address, the firewall rule which was triggered, and so forth. We use a set of commercial rules which are constantly updated, but sometimes our administrators add custom rules as well in order to better protect the Internet sites hosted on our machines.

ModSecurity in Semi-dedicated Hosting

ModSecurity is part of our semi-dedicated hosting plans and if you decide to host your websites with our company, there shall not be anything special you will have to do since the firewall is activated by default for all domains and subdomains which you add using your hosting CP. If necessary, you'll be able to disable ModSecurity for a given website or activate the so-called detection mode in which case the firewall will still function and record data, but won't do anything to stop potential attacks against your sites. In depth logs will be available in your CP and you shall be able to see what sort of attacks took place, what security rules were triggered and how the firewall dealt with the threats, what Internet protocol addresses the attacks originated from, etcetera. We employ two types of rules on our servers - commercial ones from a company which operates in the field of web security, and custom ones which our admins sometimes add to respond to newly identified risks promptly.

ModSecurity in VPS Hosting

All virtual private servers that are set up with the Hepsia CP come with ModSecurity. The firewall is installed and turned on by default for all domains which are hosted on the web server, so there won't be anything special that you shall have to do to protect your websites. It'll take you simply a mouse click to stop ModSecurity if needed or to activate its passive mode so that it records what happens without taking any measures to prevent intrusions. You shall be able to view the logs generated in active or passive mode via the corresponding section of Hepsia and learn more about the form of the attack, where it originated from, what rule the firewall employed to tackle it, etc. We use a combination of commercial and custom rules so as to make certain that ModSecurity will block out as many risks as possible, thus improving the security of your web programs as much as possible.

ModSecurity in Dedicated Web Hosting

ModSecurity comes with all dedicated servers that are set up with our Hepsia CP and you will not have to do anything specific on your end to employ it since it is activated by default each time you include a new domain or subdomain on your hosting server. If it interferes with some of your applications, you'll be able to stop it via the respective area of Hepsia, or you could leave it in passive mode, so it shall identify attacks and will still maintain a log for them, but will not prevent them. You can examine the logs later to find out what you can do to increase the safety of your websites since you shall find details such as where an intrusion attempt originated from, what website was attacked and in accordance with what rule ModSecurity reacted, and so forth. The rules that we use are commercial, thus they are frequently updated by a security firm, but to be on the safe side, our administrators also include custom rules once in a while in order to deal with any new threats they have identified.