ModSecurity is an effective firewall for Apache web servers that's employed to stop attacks against web applications. It monitors the HTTP traffic to a certain website in real time and blocks any intrusion attempts as soon as it discovers them. The firewall relies on a set of rules to accomplish that - for example, attempting to log in to a script administrator area without success several times sets off one rule, sending a request to execute a certain file that may result in accessing the site triggers another rule, etc. ModSecurity is one of the best firewalls available and it'll secure even scripts that aren't updated on a regular basis since it can prevent attackers from using known exploits and security holes. Very detailed data about each and every intrusion attempt is recorded and the logs the firewall keeps are much more specific than the conventional logs provided by the Apache server, so you could later analyze them and determine whether you need to take extra measures so as to improve the security of your script-driven sites.
ModSecurity in Website Hosting
We provide ModSecurity with all website hosting plans, so your Internet applications shall be resistant to malicious attacks. The firewall is switched on as standard for all domains and subdomains, but if you would like, you shall be able to stop it via the respective part of your Hepsia CP. You could also switch on a detection mode, so ModSecurity will keep a log as intended, but won't take any action. The logs which you shall discover in Hepsia are quite detailed and feature info about the nature of any attack, when it transpired and from what IP, the firewall rule which was triggered, and so on. We employ a group of commercial rules which are regularly updated, but sometimes our admins add custom rules as well in order to better protect the websites hosted on our machines.
ModSecurity in Semi-dedicated Servers
ModSecurity is part of our semi-dedicated server solutions and if you choose to host your sites with us, there will not be anything special you'll need to do as the firewall is switched on by default for all domains and subdomains which you include using your hosting CP. If needed, you could disable ModSecurity for a certain website or switch on the so-called detection mode in which case the firewall shall still work and record data, but will not do anything to prevent potential attacks on your sites. Thorough logs shall be available inside your CP and you will be able to see which kind of attacks took place, what security rules were triggered and how the firewall addressed the threats, what IP addresses the attacks originated from, etc. We employ two kinds of rules on our servers - commercial ones from a company which operates in the field of web security, and custom ones which our administrators sometimes include to respond to newly discovered risks promptly.
ModSecurity in VPS Servers
ModSecurity is pre-installed on all VPS servers which are offered with the Hepsia hosting Control Panel, so your web programs shall be protected from the moment your server is ready. The firewall is turned on by default for any domain or subdomain on the VPS, but if required, you'll be able to disable it with a click via the corresponding section of Hepsia. You could also set it to work in detection mode, so it'll maintain an extensive log of any potential attacks without taking any action to stop them. The logs can be found inside the very same section and offer information regarding the nature of the attack, what IP address it came from and what ModSecurity rule was activated to stop it. For maximum security, we use not simply commercial rules from a firm operating in the field of web security, but also custom ones that our admins include personally in order to respond to new risks which are still not dealt with in the commercial rules.
ModSecurity in Dedicated Servers
All our dedicated servers which are set up with the Hepsia hosting Control Panel include ModSecurity, so any app which you upload or install will be secured from the very beginning and you'll not have to worry about common attacks or vulnerabilities. A separate section in Hepsia will enable you to start or stop the firewall for each and every domain or subdomain, or turn on a detection mode so that it records information regarding intrusions, but does not take actions to stop them. What you'll see in the logs shall enable you to to secure your websites better - the IP address an attack originated from, what site was attacked and exactly how, what ModSecurity rule was triggered, etc. With this info, you could see if a site needs an update, if you ought to block IPs from accessing your server, and so forth. Besides the third-party commercial security rules for ModSecurity that we use, our admins include custom ones too every time they discover a new threat that is not yet included in the commercial bundle.