ModSecurity is a plugin for Apache web servers which functions as a web app layer firewall. It is employed to stop attacks against script-driven sites through the use of security rules which contain particular expressions. In this way, the firewall can stop hacking and spamming attempts and shield even Internet sites that aren't updated on a regular basis. As an example, a number of failed login attempts to a script administrative area or attempts to execute a specific file with the purpose to get access to the script will trigger certain rules, so ModSecurity shall stop these activities the instant it discovers them. The firewall is incredibly efficient since it monitors the entire HTTP traffic to a website in real time without slowing it down, so it can prevent an attack before any damage is done. It furthermore maintains a very detailed log of all attack attempts that includes more info than conventional Apache logs, so you could later examine the data and take extra measures to increase the security of your sites if necessary.
ModSecurity in Hosting
ModSecurity is provided with all hosting web servers, so if you choose to host your Internet sites with our firm, they will be protected against an array of attacks. The firewall is turned on as standard for all domains and subdomains, so there will be nothing you shall have to do on your end. You'll be able to stop ModSecurity for any website if required, or to activate a detection mode, so all activity will be recorded, but the firewall will not take any real action. You'll be able to view detailed logs via your Hepsia CP including the IP where the attack came from, what the attacker wished to do and how ModSecurity handled the threat. Since we take the protection of our customers' websites seriously, we employ a collection of commercial rules that we get from one of the best companies that maintain this kind of rules. Our admins also add custom rules to make sure that your sites will be protected against as many risks as possible.
ModSecurity in Semi-dedicated Servers
We have integrated ModSecurity as a standard within all semi-dedicated server products, so your web apps shall be protected whenever you install them under any domain or subdomain. The Hepsia Control Panel which comes with the semi-dedicated accounts shall allow you to switch on or disable the firewall for any Internet site with a mouse click. You'll also be able to activate a passive detection mode in which ModSecurity shall keep a log of possible attacks without really preventing them. The thorough logs include the nature of the attack and what ModSecurity response this attack caused, where it originated from, and so forth. The list of rules we use is regularly updated in order to match any new risks which could appear on the Internet and it consists of both commercial rules that we get from a security firm and custom-written ones that our admins add in the event that they discover a threat that's not present in the commercial list yet.
ModSecurity in VPS Servers
All VPS servers which are set up with the Hepsia CP come with ModSecurity. The firewall is set up and activated by default for all domains which are hosted on the web server, so there shall not be anything special which you will have to do to protect your websites. It will take you just a click to stop ModSecurity if required or to activate its passive mode so that it records what occurs without taking any actions to prevent intrusions. You shall be able to look at the logs produced in active or passive mode via the corresponding section of Hepsia and discover more about the type of the attack, where it originated from, what rule the firewall employed to tackle it, and so forth. We employ a combination of commercial and custom rules in order to ensure that ModSecurity will prevent as many threats as possible, therefore improving the security of your web programs as much as possible.
ModSecurity in Dedicated Servers
All our dedicated servers that are set up with the Hepsia hosting CP include ModSecurity, so any app that you upload or install shall be secured from the very beginning and you'll not need to bother about common attacks or vulnerabilities. An independent section in Hepsia will allow you to start or stop the firewall for each domain or subdomain, or turn on a detection mode so that it records details about intrusions, but doesn't take actions to prevent them. What you'll find in the logs can allow you to to secure your websites better - the IP an attack originated from, what site was attacked and how, what ModSecurity rule was triggered, etcetera. With this data, you could see if an Internet site needs an update, if you ought to block IPs from accessing your web server, and so forth. On top of the third-party commercial security rules for ModSecurity that we use, our admins include custom ones as well if they find a new threat that's not yet a part of the commercial bundle.