ModSecurity
Learn how having ModSecurity allowed within your website hosting account will help silently with your web site protection.
ModSecurity is a plugin for Apache web servers which functions as a web application layer firewall. It is used to stop attacks toward script-driven websites by using security rules which contain particular expressions. This way, the firewall can block hacking and spamming attempts and protect even Internet sites which are not updated often. As an example, numerous failed login attempts to a script administrator area or attempts to execute a specific file with the intention to get access to the script will trigger specific rules, so ModSecurity will block these activities the minute it identifies them. The firewall is very efficient as it screens the entire HTTP traffic to a site in real time without slowing it down, so it can prevent an attack before any harm is done. It furthermore keeps an incredibly comprehensive log of all attack attempts that includes more information than typical Apache logs, so you could later examine the data and take further measures to improve the security of your sites if required.
-
ModSecurity in Website Hosting
ModSecurity can be found with every
website hosting plan which we provide and it is turned on by default for every domain or subdomain which you add through your Hepsia CP. In the event that it disrupts any of your programs or you would like to disable it for any reason, you shall be able to do that through the ModSecurity area of Hepsia with merely a click. You may also use a passive mode, so the firewall will recognize possible attacks and maintain a log, but shall not take any action. You could see comprehensive logs in the exact same section, including the IP address where the attack came from, exactly what the attacker aimed to do and at what time, what ModSecurity did, and so on. For max protection of our clients we use a set of commercial firewall rules blended with custom ones that are provided by our system administrators.
-
ModSecurity in Dedicated Hosting
ModSecurity comes with all
dedicated servers which are set up with our Hepsia CP and you won't have to do anything specific on your end to use it since it is switched on by default whenever you add a new domain or subdomain on your hosting server. In the event that it interferes with any of your apps, you will be able to stop it through the respective part of Hepsia, or you can leave it working in passive mode, so it'll identify attacks and will still maintain a log for them, but will not prevent them. You can analyze the logs later to learn what you can do to increase the safety of your websites as you'll find details such as where an intrusion attempt came from, what site was attacked and in accordance with what rule ModSecurity responded, and so on. The rules we employ are commercial, therefore they are frequently updated by a security provider, but to be on the safe side, our administrators also add custom rules every now and then in order to react to any new threats they have identified.