ModSecurity
Find out what ModSecurity is, how it works and precisely what it does to protect your websites and apps.
ModSecurity is a powerful firewall for Apache web servers which is employed to stop attacks towards web applications. It monitors the HTTP traffic to a given website in real time and stops any intrusion attempts as soon as it detects them. The firewall uses a set of rules to accomplish that - as an example, trying to log in to a script administrator area without success several times activates one rule, sending a request to execute a particular file that could result in getting access to the Internet site triggers a different rule, etc. ModSecurity is amongst the best firewalls on the market and it'll secure even scripts that aren't updated often since it can prevent attackers from using known exploits and security holes. Very thorough information about each and every intrusion attempt is recorded and the logs the firewall maintains are much more specific than the regular logs provided by the Apache server, so you may later analyze them and determine if you need to take extra measures in order to enhance the security of your script-driven Internet sites.
-
ModSecurity in Cloud Web Hosting
ModSecurity is available on all
cloud web hosting machines, so when you choose to host your Internet sites with our organization, they shall be resistant to a wide range of attacks. The firewall is enabled as standard for all domains and subdomains, so there will be nothing you'll have to do on your end. You shall be able to stop ModSecurity for any site if necessary, or to activate a detection mode, so all activity shall be recorded, but the firewall shall not take any real action. You will be able to view detailed logs from your Hepsia Control Panel including the IP address where the attack originated from, what the attacker wanted to do and how ModSecurity addressed the threat. As we take the safety of our clients' websites seriously, we use a collection of commercial rules that we get from one of the best firms that maintain this kind of rules. Our admins also include custom rules to ensure that your sites shall be protected against as many risks as possible.
-
ModSecurity in Semi-dedicated Hosting
ModSecurity is a part of our
semi-dedicated hosting solutions and if you choose to host your Internet sites with us, there shall not be anything special you'll have to do as the firewall is turned on by default for all domains and subdomains which you add using your hosting CP. If needed, you could disable ModSecurity for a particular website or turn on the so-called detection mode in which case the firewall will still operate and record data, but shall not do anything to prevent possible attacks against your sites. In depth logs shall be accessible within your CP and you will be able to see which kind of attacks occurred, what security rules were triggered and how the firewall addressed the threats, what Internet protocol addresses the attacks originated from, etc. We use 2 kinds of rules on our servers - commercial ones from an organization that operates in the field of web security, and customized ones which our administrators sometimes include to respond to newly found threats in a timely manner.
-
ModSecurity in VPS
ModSecurity is pre-installed on all
virtual private servers which are provided with the Hepsia hosting CP, so your web programs shall be secured from the moment your server is ready. The firewall is turned on by default for any domain or subdomain on the VPS, but if needed, you could deactivate it with a mouse click from the corresponding section of Hepsia. You could also set it to work in detection mode, so it'll keep an extensive log of any potential attacks without taking any action to stop them. The logs can be found within the same section and include details about the nature of the attack, what IP address it originated from and what ModSecurity rule was initiated to stop it. For optimum security, we employ not just commercial rules from a business operating in the field of web security, but also custom ones that our administrators include personally so as to respond to new risks which are still not addressed in the commercial rules.
-
ModSecurity in Dedicated Hosting
ModSecurity is provided by default with all
dedicated servers that are set up with the Hepsia Control Panel and is set to “Active” automatically for any domain which you host or subdomain which you create on the web server. In the event that a web application doesn't work correctly, you can either disable the firewall or set it to operate in passive mode. The latter means that ModSecurity will keep a log of any potential attack that could occur, but will not take any action to stop it. The logs generated in active or passive mode shall present you with more details about the exact file that was attacked, the type of the attack and the IP address it originated from, and so on. This info will enable you to determine what measures you can take to boost the security of your sites, for instance blocking IPs or performing script and plugin updates. The ModSecurity rules which we use are updated frequently with a commercial pack from a third-party security firm we work with, but sometimes our staff include their own rules also in case they come across a new potential threat.