ModSecurity is a highly effective firewall for Apache web servers that is employed to stop attacks toward web applications. It keeps track of the HTTP traffic to a certain Internet site in real time and blocks any intrusion attempts the instant it discovers them. The firewall uses a set of rules to accomplish that - as an example, attempting to log in to a script admin area without success a few times triggers one rule, sending a request to execute a specific file that could result in gaining access to the Internet site triggers a different rule, etcetera. ModSecurity is one of the best firewalls available and it will protect even scripts that are not updated regularly because it can prevent attackers from using known exploits and security holes. Quite thorough info about every intrusion attempt is recorded and the logs the firewall keeps are considerably more detailed than the conventional logs created by the Apache server, so you could later analyze them and decide whether you need to take extra measures in order to increase the security of your script-driven Internet sites.

ModSecurity in Semi-dedicated Servers

Any web application which you install inside your new semi-dedicated server account will be protected by ModSecurity because the firewall is provided with all our hosting plans and is turned on by default for any domain and subdomain that you include or create through your Hepsia hosting Control Panel. You shall be able to manage ModSecurity through a dedicated area in Hepsia where not simply could you activate or deactivate it entirely, but you may also enable a passive mode, so the firewall shall not block anything, but it will still keep a record of possible attacks. This normally requires only a click and you will be able to view the logs no matter if ModSecurity is in active or passive mode through the same section - what the attack was and where it originated from, how it was dealt with, and so on. The firewall uses 2 groups of rules on our machines - a commercial one which we get from a third-party web security provider and a custom one that our administrators update personally in order to respond to recently discovered risks at the earliest opportunity.

ModSecurity in VPS Servers

ModSecurity is included with all Hepsia-based VPS servers we offer and it shall be activated automatically for any new domain or subdomain that you add on the server. That way, any web application you install shall be protected from the very beginning without doing anything personally on your end. The firewall could be managed via the section of the Control Panel that bears the same name. This is the area whereyou can switch off ModSecurity or activate its passive mode, so it will not take any action against threats, but will still maintain a thorough log. The recorded data is available in the same area as well and you shall be able to see what IPs any attacks originated from to enable you to block them, what the nature of the attempted attacks was and based upon what security rules ModSecurity reacted. The rules that we use on our servers are a blend between commercial ones which we obtain from a security firm and custom ones that are added by our admins to optimize the security of any web apps hosted on our end.

ModSecurity in Dedicated Servers

If you opt to host your sites on a dedicated server with the Hepsia Control Panel, your web apps shall be protected right from the start as ModSecurity is supplied with all Hepsia-based packages. You shall be able to manage the firewall easily and if necessary, you'll be able to turn it off or switch on its passive mode when it'll only maintain a log of what is taking place without taking any action to prevent potential attacks. The logs that you can find inside the very same section of the CP are quite detailed and feature information about the attacker IP, what site and file were attacked and in what ways, what rule the firewall used to stop the intrusion, and so forth. This information shall permit you to take measures and enhance the security of your websites even more. To be on the safe side, we employ not only commercial rules, but also custom-made ones that our admins add every time they identify attacks which have not yet been included inside the commercial pack.