ModSecurity is an effective firewall for Apache web servers that is employed to stop attacks towards web apps. It tracks the HTTP traffic to a particular website in real time and stops any intrusion attempts the moment it detects them. The firewall relies on a set of rules to accomplish that - for example, trying to log in to a script admin area without success a few times triggers one rule, sending a request to execute a particular file that could result in getting access to the Internet site triggers another rule, and so forth. ModSecurity is among the best firewalls available and it'll protect even scripts that are not updated on a regular basis since it can prevent attackers from employing known exploits and security holes. Quite thorough info about every single intrusion attempt is recorded and the logs the firewall maintains are considerably more specific than the standard logs generated by the Apache server, so you could later take a look at them and determine whether you need to take extra measures in order to improve the protection of your script-driven sites.

ModSecurity in Shared Hosting

ModSecurity comes by default with all shared hosting solutions which we provide and it will be turned on automatically for any domain or subdomain that you add/create inside your Hepsia hosting CP. The firewall has 3 different modes, so you can switch on and deactivate it with just a mouse click or set it to detection mode, so it shall maintain a log of all attacks, but it will not do anything to prevent them. The log for each of your websites shall include elaborate info which includes the nature of the attack, where it originated from, what action was taken by ModSecurity, and so forth. The firewall rules that we use are constantly updated and include both commercial ones we get from a third-party security company and custom ones which our system administrators add in the event that they detect a new type of attacks. This way, the sites which you host here will be much more secure without any action required on your end.

ModSecurity in Semi-dedicated Hosting

ModSecurity is part of our semi-dedicated hosting plans and if you opt to host your Internet sites with us, there shall not be anything special you'll need to do since the firewall is activated by default for all domains and subdomains you include through your hosting CP. If needed, you'll be able to disable ModSecurity for a particular website or switch on the so-called detection mode in which case the firewall will still work and record info, but shall not do anything to prevent potential attacks against your websites. Thorough logs shall be readily available within your Control Panel and you'll be able to see which kind of attacks occurred, what security rules were triggered and how the firewall handled the threats, what IP addresses the attacks originated from, etcetera. We use two kinds of rules on our servers - commercial ones from a firm which operates in the field of web security, and custom made ones which our administrators occasionally add to respond to newly identified risks promptly.

ModSecurity in VPS

All virtual private servers that are offered with the Hepsia CP feature ModSecurity. The firewall is set up and switched on by default for all domains that are hosted on the server, so there will not be anything special that you shall have to do to protect your Internet sites. It'll take you a mouse click to stop ModSecurity if necessary or to switch on its passive mode so that it records what happens without taking any measures to prevent intrusions. You'll be able to view the logs produced in passive or active mode through the corresponding section of Hepsia and discover more about the form of the attack, where it originated from, what rule the firewall used to deal with it, etc. We employ a combination of commercial and custom rules so as to make certain that ModSecurity will prevent as many threats as possible, hence increasing the security of your web programs as much as possible.

ModSecurity in Dedicated Hosting

ModSecurity is available by default with all dedicated servers which are set up with the Hepsia CP and is set to “Active” automatically for any domain that you host or subdomain you create on the web server. In case that a web app doesn't operate correctly, you may either disable the firewall or set it to work in passive mode. The latter means that ModSecurity will keep a log of any potential attack which may happen, but shall not take any action to stop it. The logs generated in active or passive mode will present you with additional details about the exact file which was attacked, the form of the attack and the IP it came from, etcetera. This info shall enable you to decide what measures you can take to boost the protection of your websites, for instance blocking IPs or performing script and plugin updates. The ModSecurity rules that we employ are updated constantly with a commercial bundle from a third-party security company we work with, but sometimes our admins include their own rules too in the event that they come across a new potential threat.