ModSecurity is a plugin for Apache web servers that functions as a web application layer firewall. It is employed to prevent attacks towards script-driven Internet sites by employing security rules that contain particular expressions. In this way, the firewall can prevent hacking and spamming attempts and preserve even sites which are not updated regularly. For example, multiple unsuccessful login attempts to a script administrative area or attempts to execute a specific file with the purpose to get access to the script will trigger particular rules, so ModSecurity will stop these activities the minute it identifies them. The firewall is quite efficient since it monitors the whole HTTP traffic to a site in real time without slowing it down, so it can prevent an attack before any damage is done. It furthermore keeps an exceptionally comprehensive log of all attack attempts which features more information than standard Apache logs, so you can later check out the data and take additional measures to improve the security of your Internet sites if necessary.

ModSecurity in Web Hosting

ModSecurity is supplied with all web hosting servers, so when you decide to host your websites with our firm, they'll be shielded from a wide array of attacks. The firewall is enabled as standard for all domains and subdomains, so there will be nothing you'll have to do on your end. You will be able to stop ModSecurity for any Internet site if necessary, or to enable a detection mode, so all activity shall be recorded, but the firewall shall not take any real action. You will be able to view comprehensive logs through your Hepsia CP including the IP address where the attack came from, what the attacker wanted to do and how ModSecurity dealt with the threat. As we take the security of our customers' Internet sites seriously, we employ a group of commercial rules that we take from one of the leading firms that maintain this sort of rules. Our admins also include custom rules to make certain that your websites shall be shielded from as many risks as possible.

ModSecurity in Semi-dedicated Hosting

We have integrated ModSecurity as a standard in all semi-dedicated hosting packages, so your web applications will be protected the instant you install them under any domain or subdomain. The Hepsia CP that is included with the semi-dedicated accounts shall permit you to enable or disable the firewall for any website with a mouse click. You will also have the ability to switch on a passive detection mode with which ModSecurity will maintain a log of possible attacks without actually stopping them. The thorough logs include the nature of the attack and what ModSecurity response this attack caused, where it originated from, and so on. The list of rules we use is regularly updated as to match any new threats that may appear on the Internet and it includes both commercial rules that we get from a security firm and custom-written ones that our administrators include in the event that they discover a threat which is not present in the commercial list yet.

ModSecurity in VPS

ModSecurity is pre-installed on all virtual private servers that are set up with the Hepsia hosting Control Panel, so your web apps will be secured from the instant your server is in a position. The firewall is switched on by default for any domain or subdomain on the VPS, but if needed, you'll be able to deactivate it with a click from the corresponding section of Hepsia. You could also set it to work in detection mode, so it will maintain a comprehensive log of any possible attacks without taking any action to prevent them. The logs are available inside the exact same section and include details about the nature of the attack, what IP address it originated from and what ModSecurity rule was triggered to stop it. For best security, we employ not only commercial rules from a business working in the field of web security, but also custom ones our admins include personally so as to react to new threats that are still not tackled in the commercial rules.

ModSecurity in Dedicated Hosting

If you decide to host your sites on a dedicated server with the Hepsia CP, your web applications will be protected right from the start because ModSecurity is available with all Hepsia-based packages. You'll be able to regulate the firewall effortlessly and if needed, you shall be able to turn it off or switch on its passive mode when it will only maintain a log of what's going on without taking any action to prevent possible attacks. The logs that you'll find inside the exact same section of the CP are extremely detailed and contain data about the attacker IP, what website and file were attacked and in what ways, what rule the firewall employed to stop the intrusion, etc. This data shall enable you to take measures and enhance the security of your websites even more. To be on the safe side, we use not only commercial rules, but also custom-made ones that our administrators add when they detect attacks that have not yet been included within the commercial pack.