ModSecurity is a plugin for Apache web servers that functions as a web app layer firewall. It is used to stop attacks toward script-driven Internet sites by using security rules that contain certain expressions. This way, the firewall can block hacking and spamming attempts and shield even websites that are not updated frequently. For instance, multiple unsuccessful login attempts to a script administrator area or attempts to execute a certain file with the intention to get access to the script shall trigger specific rules, so ModSecurity will stop these activities the second it discovers them. The firewall is extremely efficient because it screens the whole HTTP traffic to a site in real time without slowing it down, so it can prevent an attack before any damage is done. It additionally keeps an exceptionally thorough log of all attack attempts that features more information than conventional Apache logs, so you can later check out the data and take extra measures to increase the security of your sites if required.

ModSecurity in Hosting

ModSecurity is available with each hosting package which we provide and it is switched on by default for every domain or subdomain that you add through your Hepsia Control Panel. In case it disrupts any of your programs or you would like to disable it for some reason, you will be able to accomplish that through the ModSecurity section of Hepsia with simply a click. You can also enable a passive mode, so the firewall will detect potential attacks and keep a log, but shall not take any action. You'll be able to see extensive logs in the exact same section, including the IP where the attack came from, what precisely the attacker attempted to do and at what time, what ModSecurity did, and so forth. For maximum safety of our clients we use a group of commercial firewall rules mixed with custom ones that are included by our system admins.

ModSecurity in Semi-dedicated Hosting

All semi-dedicated hosting solutions that we offer feature ModSecurity and since the firewall is enabled by default, any site you build under a domain or a subdomain will be secured immediately. An independent section inside the Hepsia CP which comes with the semi-dedicated accounts is dedicated to ModSecurity and it shall permit you to start and stop the firewall for any website or switch on a detection mode. With the last mentioned, ModSecurity shall not take any action, but it'll still detect possible attacks and shall keep all info in a log as if it were 100% active. The logs can be found in the exact same section of the Control Panel and they feature information about the IP where an attack originated from, what its nature was, what rule ModSecurity applies to identify and stop it, and so on. The security rules we use on our machines are a mix between commercial ones from a security company and custom ones developed by our system administrators. For that reason, we provide increased security for your web applications as we can defend them from attacks even before security businesses release updates for brand new threats.

ModSecurity in VPS

All virtual private servers that are set up with the Hepsia Control Panel feature ModSecurity. The firewall is set up and activated by default for all domains which are hosted on the server, so there won't be anything special which you shall have to do to protect your Internet sites. It shall take you a mouse click to stop ModSecurity if required or to turn on its passive mode so that it records what happens without taking any measures to stop intrusions. You'll be able to see the logs created in active or passive mode from the corresponding section of Hepsia and learn more about the form of the attack, where it came from, what rule the firewall used to handle it, and so forth. We use a combination of commercial and custom rules so as to ensure that ModSecurity shall prevent as many risks as possible, therefore increasing the security of your web programs as much as possible.

ModSecurity in Dedicated Hosting

ModSecurity comes with all dedicated servers which are integrated with our Hepsia CP and you won't have to do anything specific on your end to use it because it is switched on by default every time you include a new domain or subdomain on your web server. In case it disrupts some of your applications, you will be able to stop it through the respective area of Hepsia, or you can leave it operating in passive mode, so it will recognize attacks and shall still maintain a log for them, but shall not stop them. You'll be able to analyze the logs later to find out what you can do to increase the security of your Internet sites since you'll find info such as where an intrusion attempt originated from, what Internet site was attacked and in accordance with what rule ModSecurity responded, etcetera. The rules that we employ are commercial, therefore they're constantly updated by a security company, but to be on the safe side, our staff also add custom rules once in a while as to respond to any new threats they have discovered.