ModSecurity
Learn what ModSecurity is, how it functions and just what it does in order to protect your sites and applications.
ModSecurity is a powerful web application layer firewall for Apache web servers. It monitors the entire HTTP traffic to a site without affecting its functionality and if it discovers an intrusion attempt, it blocks it. The firewall additionally maintains a more detailed log for the site visitors than any web server does, so you shall manage to keep track of what's happening with your sites better than if you rely only on standard logs. ModSecurity uses security rules based on which it prevents attacks. For instance, it identifies if anyone is attempting to log in to the administrator area of a given script a number of times or if a request is sent to execute a file with a specific command. In such situations these attempts trigger the corresponding rules and the firewall software blocks the attempts in real time, then records detailed details about them inside its logs. ModSecurity is amongst the very best software firewalls available and it can easily protect your web apps against thousands of threats and vulnerabilities, particularly in case you don’t update them or their plugins often.
-
ModSecurity in Shared Hosting
We offer ModSecurity with all
shared hosting plans, so your Internet apps shall be protected against harmful attacks. The firewall is switched on as standard for all domains and subdomains, but in case you'd like, you will be able to stop it through the respective area of your Hepsia CP. You could also activate a detection mode, so ModSecurity will keep a log as intended, but will not take any action. The logs that you will find within Hepsia are very detailed and offer info about the nature of any attack, when it happened and from what IP address, the firewall rule that was triggered, and so on. We employ a group of commercial rules that are constantly updated, but sometimes our admins include custom rules as well in order to efficiently protect the sites hosted on our servers.
-
ModSecurity in Dedicated Hosting
ModSecurity is provided with all
dedicated servers that are set up with our Hepsia CP and you will not need to do anything specific on your end to employ it since it is switched on by default whenever you include a new domain or subdomain on your server. If it disrupts some of your programs, you will be able to stop it through the respective area of Hepsia, or you can leave it operating in passive mode, so it'll identify attacks and shall still maintain a log for them, but won't prevent them. You can look at the logs later to find out what you can do to boost the security of your websites as you will find information such as where an intrusion attempt originated from, what site was attacked and based upon what rule ModSecurity responded, and so forth. The rules which we employ are commercial, thus they are constantly updated by a security company, but to be on the safe side, our administrators also include custom rules once in a while in order to deal with any new threats they have found.