ModSecurity is a highly effective web application layer firewall for Apache web servers. It monitors the whole HTTP traffic to an Internet site without affecting its performance and if it discovers an intrusion attempt, it blocks it. The firewall additionally keeps a more comprehensive log for the website visitors than any server does, so you will manage to keep track of what is going on with your sites much better than if you rely merely on conventional logs. ModSecurity uses security rules based on which it helps prevent attacks. For instance, it detects if someone is attempting to log in to the administration area of a certain script a number of times or if a request is sent to execute a file with a certain command. In these situations these attempts trigger the corresponding rules and the firewall program hinders the attempts instantly, then records in-depth details about them in its logs. ModSecurity is one of the most effective software firewalls out there and it can easily protect your web apps against thousands of threats and vulnerabilities, particularly if you don’t update them or their plugins often.

ModSecurity in Shared Hosting

ModSecurity comes standard with all shared hosting plans that we provide and it'll be turned on automatically for any domain or subdomain that you add/create in your Hepsia hosting CP. The firewall has three different modes, so you can switch on and disable it with just a mouse click or set it to detection mode, so it'll maintain a log of all attacks, but it'll not do anything to prevent them. The log for any of your sites will contain in-depth information such as the nature of the attack, where it originated from, what action was taken by ModSecurity, and so on. The firewall rules which we use are regularly updated and consist of both commercial ones which we get from a third-party security company and custom ones which our system administrators add in the event that they detect a new type of attacks. This way, the websites that you host here will be a lot more protected without any action expected on your end.