ModSecurity is a potent web application layer firewall for Apache web servers. It monitors the whole HTTP traffic to an Internet site without affecting its performance and if it discovers an intrusion attempt, it prevents it. The firewall additionally keeps a more comprehensive log for the website visitors than any web server does, so you shall be able to keep an eye on what's happening with your sites a lot better than if you rely merely on conventional logs. ModSecurity employs security rules based on which it prevents attacks. For instance, it detects whether somebody is attempting to log in to the admin area of a particular script multiple times or if a request is sent to execute a file with a specific command. In these circumstances these attempts set off the corresponding rules and the firewall software blocks the attempts instantly, after that records comprehensive info about them inside its logs. ModSecurity is among the most effective software firewalls on the market and it can protect your web apps against thousands of threats and vulnerabilities, particularly in case you don’t update them or their plugins frequently.

ModSecurity in Shared Web Hosting

We offer ModSecurity with all shared web hosting solutions, so your Internet applications shall be resistant to destructive attacks. The firewall is turned on as standard for all domains and subdomains, but in case you'd like, you will be able to stop it using the respective area of your Hepsia Control Panel. You can also switch on a detection mode, so ModSecurity shall keep a log as intended, but will not take any action. The logs which you will discover in Hepsia are quite detailed and offer info about the nature of any attack, when it occurred and from what IP, the firewall rule which was triggered, etcetera. We employ a set of commercial rules that are regularly updated, but sometimes our administrators include custom rules as well in order to better protect the Internet sites hosted on our machines.

ModSecurity in Semi-dedicated Hosting

Any web application that you set up within your new semi-dedicated hosting account shall be protected by ModSecurity since the firewall comes with all our hosting solutions and is turned on by default for any domain and subdomain you include or create through your Hepsia hosting Control Panel. You shall be able to manage ModSecurity via a dedicated area within Hepsia where not simply could you activate or deactivate it entirely, but you could also enable a passive mode, so the firewall will not stop anything, but it shall still maintain an archive of possible attacks. This requires simply a mouse click and you will be able to view the logs regardless of if ModSecurity is in passive or active mode through the same section - what the attack was and where it originated from, how it was addressed, etc. The firewall uses two sets of rules on our servers - a commercial one which we get from a third-party web security provider and a custom one that our administrators update manually as to respond to recently discovered risks as soon as possible.

ModSecurity in VPS Web Hosting

All virtual private servers that are offered with the Hepsia CP include ModSecurity. The firewall is installed and switched on by default for all domains which are hosted on the machine, so there won't be anything special that you shall have to do to protect your websites. It'll take you simply a click to stop ModSecurity if necessary or to turn on its passive mode so that it records what occurs without taking any measures to stop intrusions. You will be able to see the logs generated in active or passive mode through the corresponding section of Hepsia and discover more about the type of the attack, where it came from, what rule the firewall employed to deal with it, and so forth. We employ a mix of commercial and custom rules so as to ensure that ModSecurity will prevent as many threats as possible, hence boosting the protection of your web programs as much as possible.

ModSecurity in Dedicated Servers Hosting

ModSecurity is offered as standard with all dedicated servers that are set up with the Hepsia Control Panel and is set to “Active” automatically for any domain that you host or subdomain which you create on the hosting server. In the event that a web application doesn't work correctly, you may either disable the firewall or set it to function in passive mode. The latter means that ModSecurity will maintain a log of any possible attack which may occur, but shall not take any action to prevent it. The logs created in active or passive mode shall give you more details about the exact file that was attacked, the form of the attack and the IP it originated from, and so on. This info will allow you to decide what steps you can take to increase the safety of your sites, for instance blocking IPs or carrying out script and plugin updates. The ModSecurity rules that we use are updated constantly with a commercial package from a third-party security provider we work with, but from time to time our staff add their own rules also when they discover a new potential threat.