ModSecurity is a powerful web app layer firewall for Apache web servers. It monitors the whole HTTP traffic to a site without affecting its operation and in case it identifies an intrusion attempt, it blocks it. The firewall furthermore keeps a more detailed log for the traffic than any server does, so you will be able to keep an eye on what is going on with your websites a lot better than if you rely merely on standard logs. ModSecurity works with security rules based on which it prevents attacks. For instance, it recognizes if somebody is attempting to log in to the admin area of a specific script several times or if a request is sent to execute a file with a specific command. In these cases these attempts trigger the corresponding rules and the firewall hinders the attempts in real time, after that records comprehensive details about them inside its logs. ModSecurity is one of the very best software firewalls out there and it can easily protect your web apps against thousands of threats and vulnerabilities, especially in case you don’t update them or their plugins frequently.

ModSecurity in Website Hosting

ModSecurity comes standard with all website hosting solutions that we offer and it will be switched on automatically for any domain or subdomain which you add/create within your Hepsia hosting Control Panel. The firewall has 3 different modes, so you can activate and disable it with only a mouse click or set it to detection mode, so it will keep a log of all attacks, but it'll not do anything to prevent them. The log for any of your sites shall contain comprehensive info including the nature of the attack, where it came from, what action was taken by ModSecurity, and so on. The firewall rules we use are frequently updated and include both commercial ones that we get from a third-party security firm and custom ones which our system admins add in the event that they detect a new kind of attacks. In this way, the sites which you host here will be way more protected without any action expected on your end.

ModSecurity in Semi-dedicated Servers

We've included ModSecurity by default in all semi-dedicated server products, so your web applications will be protected whenever you install them under any domain or subdomain. The Hepsia Control Panel which comes with the semi-dedicated accounts will allow you to enable or disable the firewall for any Internet site with a click. You shall also be able to activate a passive detection mode in which ModSecurity will maintain a log of potential attacks without really stopping them. The thorough logs include the nature of the attack and what ModSecurity response this attack generated, where it came from, and so forth. The list of rules we use is constantly updated in order to match any new risks which could appear on the Internet and it consists of both commercial rules that we get from a security firm and custom-written ones that our administrators include if they discover a threat that's not present in the commercial list yet.

ModSecurity in Dedicated Servers

If you decide to host your sites on a dedicated server with the Hepsia CP, your web apps shall be protected right from the start since ModSecurity is provided with all Hepsia-based plans. You'll be able to control the firewall effortlessly and if needed, you'll be able to turn it off or activate its passive mode when it shall only keep a log of what's taking place without taking any action to stop possible attacks. The logs that you can find in the exact same section of the CP are really detailed and feature information about the attacker IP address, what website and file were attacked and in what ways, what rule the firewall employed to prevent the intrusion, and so forth. This information will enable you to take measures and enhance the security of your sites even more. To be on the safe side, we use not only commercial rules, but also custom-made ones which our admins add when they detect attacks that have not yet been included in the commercial pack.