ModSecurity is a highly effective firewall for Apache web servers which is employed to stop attacks toward web apps. It keeps track of the HTTP traffic to a particular website in real time and stops any intrusion attempts as soon as it detects them. The firewall relies on a set of rules to accomplish that - as an example, attempting to log in to a script administrator area without success several times activates one rule, sending a request to execute a certain file that may result in gaining access to the site triggers a different rule, and so forth. ModSecurity is amongst the best firewalls available on the market and it will preserve even scripts that are not updated on a regular basis because it can prevent attackers from using known exploits and security holes. Quite comprehensive data about every single intrusion attempt is recorded and the logs the firewall maintains are far more comprehensive than the conventional logs provided by the Apache server, so you may later examine them and decide if you need to take additional measures so as to increase the safety of your script-driven Internet sites.

ModSecurity in Shared Hosting

ModSecurity is supplied with all shared hosting web servers, so if you choose to host your Internet sites with our firm, they'll be shielded from a wide range of attacks. The firewall is turned on by default for all domains and subdomains, so there will be nothing you will have to do on your end. You shall be able to stop ModSecurity for any website if required, or to activate a detection mode, so all activity shall be recorded, but the firewall will not take any real action. You'll be able to view specific logs via your Hepsia Control Panel including the IP address where the attack originated from, what the attacker wished to do and how ModSecurity dealt with the threat. As we take the security of our customers' sites very seriously, we employ a group of commercial rules which we take from one of the best firms that maintain this sort of rules. Our admins also add custom rules to make sure that your websites will be shielded from as many threats as possible.

ModSecurity in Semi-dedicated Servers

ModSecurity is a part of our semi-dedicated server plans and if you decide to host your sites with our company, there won't be anything special you will have to do as the firewall is turned on by default for all domains and subdomains which you add using your hosting Control Panel. If required, you'll be able to disable ModSecurity for a particular Internet site or switch on the so-called detection mode in which case the firewall shall still operate and record information, but will not do anything to stop potential attacks against your sites. Detailed logs will be available inside your CP and you'll be able to see what type of attacks happened, what security rules were triggered and how the firewall dealt with the threats, what IP addresses the attacks came from, and so on. We employ 2 kinds of rules on our servers - commercial ones from an organization that operates in the field of web security, and customized ones which our administrators sometimes include to respond to newly discovered risks in a timely manner.

ModSecurity in VPS Servers

All VPS servers that are offered with the Hepsia Control Panel include ModSecurity. The firewall is installed and switched on by default for all domains which are hosted on the server, so there won't be anything special that you'll have to do to protect your Internet sites. It shall take you a mouse click to stop ModSecurity if required or to activate its passive mode so that it records what occurs without taking any measures to stop intrusions. You'll be able to view the logs produced in passive or active mode from the corresponding section of Hepsia and discover more about the type of the attack, where it came from, what rule the firewall used to take care of it, and so forth. We employ a mixture of commercial and custom rules in order to make certain that ModSecurity shall block as many risks as possible, thus increasing the security of your web applications as much as possible.

ModSecurity in Dedicated Servers

ModSecurity is included with all dedicated servers which are integrated with our Hepsia CP and you'll not need to do anything specific on your end to use it as it's enabled by default whenever you include a new domain or subdomain on your hosting server. In the event that it interferes with some of your apps, you'll be able to stop it through the respective part of Hepsia, or you can leave it operating in passive mode, so it will identify attacks and will still keep a log for them, but shall not stop them. You could examine the logs later to determine what you can do to improve the safety of your Internet sites since you shall find details such as where an intrusion attempt came from, what site was attacked and based on what rule ModSecurity reacted, etc. The rules we employ are commercial, hence they are regularly updated by a security provider, but to be on the safe side, our administrators also include custom rules from time to time as to deal with any new threats they have identified.