ModSecurity is an effective firewall for Apache web servers that's used to prevent attacks toward web apps. It tracks the HTTP traffic to a certain Internet site in real time and blocks any intrusion attempts the moment it detects them. The firewall uses a set of rules to accomplish that - for example, attempting to log in to a script administration area without success a few times sets off one rule, sending a request to execute a specific file which may result in getting access to the site triggers another rule, and so on. ModSecurity is amongst the best firewalls available on the market and it'll preserve even scripts that aren't updated regularly since it can prevent attackers from using known exploits and security holes. Incredibly thorough info about every intrusion attempt is recorded and the logs the firewall keeps are far more specific than the regular logs generated by the Apache server, so you can later examine them and determine whether you need to take additional measures so as to increase the protection of your script-driven sites.

ModSecurity in Hosting

We provide ModSecurity with all hosting plans, so your Internet applications will be resistant to harmful attacks. The firewall is activated as standard for all domains and subdomains, but if you would like, you will be able to stop it through the respective area of your Hepsia CP. You can also switch on a detection mode, so ModSecurity will keep a log as intended, but shall not take any action. The logs that you'll find inside Hepsia are extremely detailed and include info about the nature of any attack, when it happened and from what IP address, the firewall rule which was triggered, and so forth. We employ a group of commercial rules which are constantly updated, but sometimes our administrators add custom rules as well so as to better protect the sites hosted on our machines.

ModSecurity in Semi-dedicated Hosting

ModSecurity is a part of our semi-dedicated hosting solutions and if you opt to host your Internet sites with our company, there won't be anything special you will have to do as the firewall is activated by default for all domains and subdomains you include through your hosting CP. If necessary, you can disable ModSecurity for a particular website or switch on the so-called detection mode in which case the firewall will still function and record info, but will not do anything to stop potential attacks against your sites. In depth logs shall be available inside your Control Panel and you shall be able to see which kind of attacks happened, what security rules were triggered and how the firewall addressed the threats, what Internet protocol addresses the attacks originated from, and so on. We employ two kinds of rules on our servers - commercial ones from an organization which operates in the field of web security, and custom ones which our admins occasionally add to respond to newly found threats promptly.

ModSecurity in VPS

ModSecurity is provided with all Hepsia-based virtual private servers we offer and it shall be switched on automatically for every new domain or subdomain you include on the hosting server. This way, any web application you install shall be secured from the very beginning without doing anything by hand on your end. The firewall can be managed via the section of the Control Panel that has the same name. This is the area whereyou could turn off ModSecurity or activate its passive mode, so it shall not take any action toward threats, but will still maintain a detailed log. The recorded information is available within the same area as well and you'll be able to see what IPs any attacks originated from to enable you to block them, what the nature of the attempted attacks was and based upon what security rules ModSecurity reacted. The rules that we use on our servers are a mixture between commercial ones we get from a security company and custom ones that are added by our administrators to maximize the security of any web apps hosted on our end.

ModSecurity in Dedicated Hosting

If you choose to host your Internet sites on a dedicated server with the Hepsia CP, your web apps will be protected straight away since ModSecurity is provided with all Hepsia-based packages. You'll be able to manage the firewall with ease and if necessary, you shall be able to turn it off or enable its passive mode when it'll only maintain a log of what's taking place without taking any action to stop possible attacks. The logs which you'll find within the exact same section of the Control Panel are quite detailed and contain details about the attacker IP, what site and file were attacked and in what ways, what rule the firewall used to stop the intrusion, etc. This information will allow you to take measures and enhance the protection of your websites even more. To be on the safe side, we use not just commercial rules, but also custom-made ones that our staff add when they recognize attacks that haven't yet been included inside the commercial pack.