ModSecurity is a plugin for Apache web servers which functions as a web app layer firewall. It is used to prevent attacks against script-driven Internet sites through the use of security rules that contain specific expressions. That way, the firewall can stop hacking and spamming attempts and shield even websites which aren't updated often. For example, several unsuccessful login attempts to a script administrative area or attempts to execute a specific file with the intention to get access to the script will trigger certain rules, so ModSecurity will block out these activities the second it identifies them. The firewall is very efficient because it screens the whole HTTP traffic to a site in real time without slowing it down, so it can easily stop an attack before any damage is done. It additionally keeps a very comprehensive log of all attack attempts which features more info than traditional Apache logs, so you could later analyze the data and take additional measures to boost the security of your Internet sites if needed.
ModSecurity in Shared Hosting
ModSecurity comes standard with all shared hosting solutions that we offer and it'll be switched on automatically for any domain or subdomain you add/create within your Hepsia hosting CP. The firewall has 3 different modes, so you'll be able to activate and deactivate it with simply a click or set it to detection mode, so it'll keep a log of all attacks, but it shall not do anything to prevent them. The log for each of your sites will include elaborate info including the nature of the attack, where it originated from, what action was taken by ModSecurity, and so on. The firewall rules that we use are regularly updated and include both commercial ones which we get from a third-party security firm and custom ones that our system admins include in the event that they detect a new type of attacks. That way, the websites which you host here shall be far more secure without any action needed on your end.
ModSecurity in Semi-dedicated Servers
We have incorporated ModSecurity as a standard inside all semi-dedicated server products, so your web applications shall be protected as soon as you install them under any domain or subdomain. The Hepsia CP that comes with the semi-dedicated accounts shall permit you to enable or turn off the firewall for any Internet site with a mouse click. You shall also be able to activate a passive detection mode through which ModSecurity shall keep a log of potential attacks without actually stopping them. The detailed logs include the nature of the attack and what ModSecurity response this attack triggered, where it came from, etc. The list of rules which we employ is regularly updated in order to match any new threats that might appear on the Internet and it includes both commercial rules that we get from a security firm and custom-written ones that our admins include in case they discover a threat which is not present within the commercial list yet.
ModSecurity in VPS Servers
All VPS servers that are offered with the Hepsia CP come with ModSecurity. The firewall is set up and turned on by default for all domains which are hosted on the web server, so there shall not be anything special which you'll need to do to protect your sites. It shall take you simply a click to stop ModSecurity if required or to switch on its passive mode so that it records what occurs without taking any steps to stop intrusions. You shall be able to look at the logs created in passive or active mode from the corresponding section of Hepsia and find out more about the form of the attack, where it came from, what rule the firewall employed to tackle it, and so on. We employ a mix of commercial and custom rules so as to make certain that ModSecurity will stop as many risks as possible, consequently boosting the security of your web apps as much as possible.
ModSecurity in Dedicated Servers
All of our dedicated servers which are set up with the Hepsia hosting Control Panel include ModSecurity, so any application that you upload or install will be protected from the very beginning and you won't need to concern yourself with common attacks or vulnerabilities. An independent section inside Hepsia will permit you to start or stop the firewall for any domain or subdomain, or activate a detection mode so that it records information about intrusions, but does not take actions to stop them. What you will find in the logs can easily allow you to to secure your sites better - the IP address an attack originated from, what website was attacked and how, what ModSecurity rule was triggered, and so on. With this information, you can see whether a website needs an update, whether you should block IPs from accessing your hosting server, etc. In addition to the third-party commercial security rules for ModSecurity which we use, our administrators include custom ones as well if they come across a new threat which is not yet included in the commercial bundle.