ModSecurity is an efficient firewall for Apache web servers that's used to prevent attacks against web applications. It keeps track of the HTTP traffic to a particular Internet site in real time and blocks any intrusion attempts the instant it discovers them. The firewall uses a set of rules to do that - for instance, trying to log in to a script administration area without success a few times triggers one rule, sending a request to execute a specific file which could result in getting access to the Internet site triggers a different rule, etcetera. ModSecurity is one of the best firewalls available and it will protect even scripts which are not updated on a regular basis since it can prevent attackers from employing known exploits and security holes. Very detailed data about every single intrusion attempt is recorded and the logs the firewall maintains are considerably more comprehensive than the standard logs created by the Apache server, so you could later take a look at them and determine if you need to take extra measures in order to increase the protection of your script-driven Internet sites.

ModSecurity in Cloud Web Hosting

ModSecurity is available with every single cloud web hosting package which we offer and it's activated by default for any domain or subdomain that you add via your Hepsia CP. In the event that it disrupts any of your apps or you would like to disable it for whatever reason, you shall be able to do that through the ModSecurity area of Hepsia with simply a mouse click. You can also activate a passive mode, so the firewall will identify possible attacks and keep a log, but will not take any action. You'll be able to see comprehensive logs in the very same section, including the IP where the attack originated from, exactly what the attacker aimed to do and at what time, what ModSecurity did, and so forth. For optimum safety of our customers we use a group of commercial firewall rules blended with custom ones which are added by our system admins.

ModSecurity in Semi-dedicated Hosting

All semi-dedicated hosting solutions which we offer come with ModSecurity and given that the firewall is enabled by default, any website you create under a domain or a subdomain shall be protected immediately. An independent section within the Hepsia Control Panel which comes with the semi-dedicated accounts is devoted to ModSecurity and it shall permit you to stop and start the firewall for any site or enable a detection mode. With the latter, ModSecurity won't take any action, but it'll still identify possible attacks and will keep all info inside a log as if it were 100% active. The logs can be found within the very same section of the CP and they offer information regarding the IP where an attack came from, what its nature was, what rule ModSecurity applies to detect and stop it, etcetera. The security rules that we use on our web servers are a mix between commercial ones from a security company and custom ones made by our system admins. As a result, we offer higher security for your web apps as we can defend them from attacks even before security firms release updates for brand new threats.

ModSecurity in VPS Hosting

ModSecurity is pre-installed on all virtual private servers which are provided with the Hepsia hosting CP, so your web apps will be protected from the moment your server is in a position. The firewall is switched on by default for any domain or subdomain on the VPS, but if required, you'll be able to disable it with a click through the corresponding section of Hepsia. You may also set it to function in detection mode, so it shall maintain a comprehensive log of any potential attacks without taking any action to prevent them. The logs can be found in the same section and offer details about the nature of the attack, what IP address it came from and what ModSecurity rule was triggered to stop it. For optimum security, we employ not just commercial rules from a business operating in the field of web security, but also custom ones that our admins include manually so as to respond to new risks which are still not addressed in the commercial rules.

ModSecurity in Dedicated Web Hosting

All our dedicated servers which are set up with the Hepsia hosting CP include ModSecurity, so any application that you upload or set up shall be protected from the very beginning and you won't need to worry about common attacks or vulnerabilities. A separate section inside Hepsia will allow you to start or stop the firewall for each and every domain or subdomain, or activate a detection mode so that it records information regarding intrusions, but does not take actions to prevent them. What you will see in the logs can allow you to to secure your sites better - the IP address an attack originated from, what website was attacked and how, what ModSecurity rule was triggered, and so forth. With this information, you could see if a site needs an update, whether you should block IPs from accessing your server, etc. Besides the third-party commercial security rules for ModSecurity that we use, our admins add custom ones too every time they find a new threat that's not yet in the commercial bundle.