ModSecurity is a highly effective firewall for Apache web servers that's used to prevent attacks against web apps. It tracks the HTTP traffic to a particular site in real time and prevents any intrusion attempts the moment it detects them. The firewall uses a set of rules to do that - as an illustration, trying to log in to a script administrator area without success many times activates one rule, sending a request to execute a certain file that may result in accessing the site triggers a different rule, etc. ModSecurity is amongst the best firewalls available and it'll protect even scripts which aren't updated often since it can prevent attackers from employing known exploits and security holes. Quite comprehensive data about each intrusion attempt is recorded and the logs the firewall keeps are a lot more comprehensive than the regular logs provided by the Apache server, so you could later analyze them and decide if you need to take additional measures in order to boost the security of your script-driven websites.

ModSecurity in Web Hosting

ModSecurity is provided with all web hosting machines, so when you decide to host your websites with our business, they shall be resistant to an array of attacks. The firewall is turned on by default for all domains and subdomains, so there'll be nothing you'll need to do on your end. You'll be able to stop ModSecurity for any site if required, or to enable a detection mode, so that all activity will be recorded, but the firewall will not take any real action. You shall be able to view comprehensive logs using your Hepsia CP including the IP address where the attack came from, what the attacker wished to do and how ModSecurity addressed the threat. Since we take the security of our customers' websites very seriously, we employ a selection of commercial rules that we take from one of the top companies that maintain such rules. Our admins also add custom rules to make sure that your websites shall be resistant to as many risks as possible.

ModSecurity in Semi-dedicated Hosting

We've included ModSecurity as a standard within all semi-dedicated hosting plans, so your web apps will be protected the instant you set them up under any domain or subdomain. The Hepsia Control Panel that comes with the semi-dedicated accounts shall allow you to switch on or turn off the firewall for any Internet site with a mouse click. You will also have the ability to switch on a passive detection mode in which ModSecurity will keep a log of potential attacks without actually stopping them. The comprehensive logs include the nature of the attack and what ModSecurity response that attack triggered, where it came from, etcetera. The list of rules which we employ is constantly updated in order to match any new risks that could appear on the Internet and it features both commercial rules that we get from a security corporation and custom-written ones that our admins include in case they find a threat that's not present within the commercial list yet.

ModSecurity in VPS Hosting

All virtual private servers that are provided with the Hepsia CP feature ModSecurity. The firewall is set up and activated by default for all domains which are hosted on the machine, so there will not be anything special which you'll have to do to protect your websites. It'll take you simply a mouse click to stop ModSecurity if necessary or to turn on its passive mode so that it records what happens without taking any steps to stop intrusions. You shall be able to look at the logs produced in active or passive mode via the corresponding section of Hepsia and learn more about the type of the attack, where it originated from, what rule the firewall employed to tackle it, etcetera. We use a mix of commercial and custom rules in order to make certain that ModSecurity will stop as many threats as possible, therefore boosting the protection of your web programs as much as possible.

ModSecurity in Dedicated Web Hosting

ModSecurity is included with all dedicated servers which are integrated with our Hepsia CP and you won't need to do anything specific on your end to employ it since it's activated by default each time you add a new domain or subdomain on your server. In the event that it interferes with some of your applications, you will be able to stop it through the respective section of Hepsia, or you can leave it operating in passive mode, so it will detect attacks and shall still maintain a log for them, but shall not prevent them. You could analyze the logs later to learn what you can do to improve the security of your Internet sites since you will find information such as where an intrusion attempt came from, what website was attacked and based on what rule ModSecurity responded, etcetera. The rules which we use are commercial, hence they're constantly updated by a security firm, but to be on the safe side, our staff also add custom rules from time to time as to react to any new threats they have identified.