ModSecurity
Discover what ModSecurity is, how it works and exactly what it does to protect your websites and applications.
ModSecurity is a plugin for Apache web servers that functions as a web application layer firewall. It is employed to stop attacks toward script-driven websites by using security rules that contain particular expressions. That way, the firewall can stop hacking and spamming attempts and preserve even Internet sites that aren't updated often. For instance, numerous unsuccessful login attempts to a script admin area or attempts to execute a certain file with the purpose to get access to the script shall trigger particular rules, so ModSecurity will block out these activities the minute it discovers them. The firewall is quite efficient because it tracks the whole HTTP traffic to a site in real time without slowing it down, so it could prevent an attack before any harm is done. It additionally maintains an incredibly comprehensive log of all attack attempts which features more info than typical Apache logs, so you could later analyze the data and take further measures to enhance the security of your Internet sites if required.
-
ModSecurity in Web Hosting
We provide ModSecurity with all
web hosting packages, so your Internet applications will be shielded from malicious attacks. The firewall is switched on by default for all domains and subdomains, but if you would like, you shall be able to stop it using the respective section of your Hepsia Control Panel. You could also switch on a detection mode, so ModSecurity will keep a log as intended, but will not take any action. The logs which you shall find in Hepsia are very detailed and feature information about the nature of any attack, when it occurred and from what IP address, the firewall rule which was triggered, and so on. We employ a group of commercial rules which are often updated, but sometimes our admins add custom rules as well in order to efficiently protect the websites hosted on our servers.
-
ModSecurity in Semi-dedicated Hosting
Any web program which you install inside your new
semi-dedicated hosting account shall be protected by ModSecurity since the firewall is included with all our hosting plans and is turned on by default for any domain and subdomain you add or create using your Hepsia hosting CP. You'll be able to manage ModSecurity through a dedicated section within Hepsia where not only can you activate or deactivate it fully, but you could also activate a passive mode, so the firewall shall not block anything, but it will still keep an archive of potential attacks. This takes only a click and you'll be able to look at the logs regardless of if ModSecurity is in passive or active mode through the same section - what the attack was and where it originated from, how it was addressed, etcetera. The firewall uses two groups of rules on our web servers - a commercial one that we get from a third-party web security company and a custom one that our administrators update manually in order to respond to newly discovered risks as fast as possible.
-
ModSecurity in VPS Web Hosting
Security is of the utmost importance to us, so we set up ModSecurity on all
virtual private servers that are provided with the Hepsia CP as a standard. The firewall can be managed via a dedicated section in Hepsia and is turned on automatically when you include a new domain or generate a subdomain, so you will not need to do anything personally. You'll also be able to disable it or switch on the so-called detection mode, so it shall keep a log of possible attacks you can later examine, but will not block them. The logs in both passive and active modes offer information about the form of the attack and how it was prevented, what IP address it originated from and other useful information which could help you to tighten the security of your websites by updating them or blocking IPs, for instance. Besides the commercial rules we get for ModSecurity from a third-party security firm, we also use our own rules as once in a while we detect specific attacks that are not yet present in the commercial package. This way, we can increase the protection of your Virtual private server instantly as opposed to waiting for a certified update.
-
ModSecurity in Dedicated Servers Hosting
ModSecurity is offered as standard with all
dedicated servers which are set up with the Hepsia CP and is set to “Active” automatically for any domain you host or subdomain that you create on the hosting server. Just in case that a web application doesn't work adequately, you can either turn off the firewall or set it to function in passive mode. The latter means that ModSecurity will maintain a log of any potential attack that could take place, but will not take any action to prevent it. The logs produced in passive or active mode shall give you additional details about the exact file which was attacked, the form of the attack and the IP it came from, etcetera. This info will allow you to choose what actions you can take to improve the safety of your sites, for instance blocking IPs or performing script and plugin updates. The ModSecurity rules which we employ are updated constantly with a commercial pack from a third-party security company we work with, but from time to time our admins include their own rules as well in case they discover a new potential threat.