ModSecurity is a plugin for Apache web servers which acts as a web app layer firewall. It is employed to prevent attacks toward script-driven Internet sites by employing security rules which contain specific expressions. In this way, the firewall can prevent hacking and spamming attempts and protect even websites which aren't updated regularly. For instance, numerous unsuccessful login attempts to a script administrative area or attempts to execute a certain file with the objective to get access to the script will trigger particular rules, so ModSecurity shall block out these activities the moment it discovers them. The firewall is quite efficient as it monitors the entire HTTP traffic to a site in real time without slowing it down, so it can prevent an attack before any damage is done. It also maintains a very thorough log of all attack attempts which features more information than conventional Apache logs, so you can later examine the data and take further measures to enhance the security of your Internet sites if necessary.

ModSecurity in Cloud Hosting

We provide ModSecurity with all cloud hosting packages, so your Internet apps shall be shielded from destructive attacks. The firewall is turned on as standard for all domains and subdomains, but if you'd like, you will be able to stop it through the respective area of your Hepsia CP. You could also switch on a detection mode, so ModSecurity will keep a log as intended, but will not take any action. The logs that you shall discover in Hepsia are incredibly detailed and feature information about the nature of any attack, when it took place and from what IP address, the firewall rule which was triggered, etcetera. We employ a group of commercial rules that are often updated, but sometimes our admins add custom rules as well so as to efficiently protect the websites hosted on our machines.

ModSecurity in Semi-dedicated Hosting

We have incorporated ModSecurity as a standard in all semi-dedicated hosting products, so your web applications will be protected as soon as you set them up under any domain or subdomain. The Hepsia Control Panel which is included with the semi-dedicated accounts will permit you to enable or disable the firewall for any Internet site with a click. You shall also be able to turn on a passive detection mode with which ModSecurity will maintain a log of potential attacks without really stopping them. The comprehensive logs include things like the nature of the attack and what ModSecurity response that attack initiated, where it came from, and so forth. The list of rules we use is regularly updated as to match any new risks that may appear on the Internet and it includes both commercial rules that we get from a security corporation and custom-written ones that our admins add in case they find a threat that's not present within the commercial list yet.

ModSecurity in VPS Hosting

ModSecurity is pre-installed on all virtual private servers that are offered with the Hepsia hosting Control Panel, so your web applications will be secured from the second your server is ready. The firewall is turned on by default for any domain or subdomain on the Virtual Private Server, but if required, you could deactivate it with a click from the corresponding section of Hepsia. You may also set it to work in detection mode, so it'll keep an extensive log of any potential attacks without taking any action to prevent them. The logs are available within the very same section and include information regarding the nature of the attack, what IP it came from and what ModSecurity rule was initiated to stop it. For optimum security, we use not just commercial rules from a business operating in the field of web security, but also custom ones our admins include manually in order to react to new threats which are still not dealt with in the commercial rules.

ModSecurity in Dedicated Web Hosting

ModSecurity comes with all dedicated servers that are set up with our Hepsia CP and you'll not need to do anything specific on your end to use it because it's enabled by default every time you add a new domain or subdomain on your server. In case it disrupts some of your apps, you will be able to stop it via the respective area of Hepsia, or you could leave it in passive mode, so it shall detect attacks and shall still maintain a log for them, but shall not block them. You can analyze the logs later to determine what you can do to enhance the safety of your sites since you shall find details such as where an intrusion attempt came from, what site was attacked and based on what rule ModSecurity responded, etcetera. The rules which we employ are commercial, thus they are constantly updated by a security provider, but to be on the safe side, our staff also add custom rules occasionally in order to deal with any new threats they have identified.