ModSecurity is a plugin for Apache web servers which acts as a web app layer firewall. It is used to prevent attacks against script-driven websites by employing security rules that contain specific expressions. This way, the firewall can block hacking and spamming attempts and shield even Internet sites that aren't updated often. As an example, several failed login attempts to a script admin area or attempts to execute a certain file with the purpose to get access to the script shall trigger certain rules, so ModSecurity will block out these activities the second it detects them. The firewall is very efficient because it screens the whole HTTP traffic to an Internet site in real time without slowing it down, so it can easily prevent an attack before any damage is done. It also keeps an incredibly detailed log of all attack attempts that includes more info than conventional Apache logs, so you can later examine the data and take further measures to boost the security of your sites if required.

ModSecurity in Cloud Website Hosting

ModSecurity is offered with every cloud website hosting solution which we provide and it's activated by default for every domain or subdomain which you add through your Hepsia CP. In case it interferes with any of your applications or you'd like to disable it for any reason, you'll be able to accomplish that through the ModSecurity area of Hepsia with just a mouse click. You may also enable a passive mode, so the firewall will identify possible attacks and keep a log, but will not take any action. You can view comprehensive logs in the very same section, including the IP address where the attack came from, what precisely the attacker attempted to do and at what time, what ModSecurity did, and so forth. For maximum safety of our clients we use a collection of commercial firewall rules blended with custom ones that are included by our system administrators.

ModSecurity in Semi-dedicated Hosting

We have incorporated ModSecurity by default in all semi-dedicated hosting packages, so your web applications shall be protected the instant you set them up under any domain or subdomain. The Hepsia CP which comes with the semi-dedicated accounts will allow you to switch on or disable the firewall for any website with a click. You shall also be able to switch on a passive detection mode with which ModSecurity will keep a log of possible attacks without actually stopping them. The comprehensive logs include the nature of the attack and what ModSecurity response this attack triggered, where it originated from, etc. The list of rules which we employ is regularly updated in order to match any new threats which may appear on the Internet and it consists of both commercial rules that we get from a security corporation and custom-written ones which our admins add in the event that they discover a threat which is not present in the commercial list yet.

ModSecurity in VPS

ModSecurity comes with all Hepsia-based virtual private servers we offer and it shall be turned on automatically for every new domain or subdomain that you add on the web server. That way, any web application which you install shall be secured from the very beginning without doing anything by hand on your end. The firewall may be managed from the section of the CP that has the same name. This is the area whereyou'll be able to turn off ModSecurity or let its passive mode, so it will not take any action toward threats, but will still maintain a thorough log. The recorded data is available inside the same section as well and you'll be able to see what IPs any attacks came from so that you can stop them, what the nature of the attempted attacks was and based on what security rules ModSecurity reacted. The rules that we use on our servers are a combination between commercial ones we obtain from a security organization and custom ones that are added by our admins to improve the security of any web applications hosted on our end.

ModSecurity in Dedicated Hosting

When you opt to host your websites on a dedicated server with the Hepsia CP, your web apps will be protected right from the start as ModSecurity is provided with all Hepsia-based plans. You'll be able to manage the firewall easily and if needed, you shall be able to turn it off or enable its passive mode when it will only keep a log of what's happening without taking any action to prevent potential attacks. The logs that you will find inside the same section of the Control Panel are extremely detailed and feature info about the attacker IP address, what site and file were attacked and in what ways, what rule the firewall employed to stop the intrusion, and so on. This info will allow you to take measures and enhance the protection of your sites even more. To be on the safe side, we use not only commercial rules, but also custom-made ones which our administrators add every time they identify attacks which haven't yet been included inside the commercial pack.