ModSecurity in Hosting
ModSecurity is available with every single hosting package that we offer and it's activated by default for any domain or subdomain that you add via your Hepsia CP. In case it disrupts any of your apps or you'd like to disable it for whatever reason, you will be able to accomplish that through the ModSecurity section of Hepsia with only a mouse click. You may also activate a passive mode, so the firewall will discover possible attacks and maintain a log, but will not take any action. You'll be able to see detailed logs in the same section, including the IP address where the attack originated from, exactly what the attacker aimed to do and at what time, what ModSecurity did, and so forth. For maximum protection of our clients we use a collection of commercial firewall rules mixed with custom ones which are added by our system admins.
ModSecurity in Semi-dedicated Hosting
Any web program which you install within your new semi-dedicated hosting account will be protected by ModSecurity since the firewall comes with all our hosting plans and is turned on by default for any domain and subdomain that you add or create using your Hepsia hosting Control Panel. You shall be able to manage ModSecurity through a dedicated section within Hepsia where not simply could you activate or deactivate it fully, but you may also switch on a passive mode, so the firewall shall not stop anything, but it'll still keep an archive of possible attacks. This normally requires only a click and you shall be able to look at the logs regardless if ModSecurity is in passive or active mode through the same section - what the attack was and where it originated from, how it was handled, and so forth. The firewall uses 2 groups of rules on our servers - a commercial one which we get from a third-party web security provider and a custom one which our admins update manually as to respond to recently discovered risks immediately.
ModSecurity in VPS
Protection is vital to us, so we set up ModSecurity on all virtual private servers which are made available with the Hepsia CP by default. The firewall can be managed through a dedicated section in Hepsia and is turned on automatically when you add a new domain or generate a subdomain, so you'll not need to do anything by hand. You shall also be able to deactivate it or switch on the so-called detection mode, so it will keep a log of possible attacks that you can later examine, but will not stop them. The logs in both passive and active modes offer info about the type of the attack and how it was stopped, what IP it came from and other valuable data that could help you to tighten the security of your sites by updating them or blocking IPs, as an example. Beyond the commercial rules we get for ModSecurity from a third-party security firm, we also use our own rules as once in a while we discover specific attacks that aren't yet present inside the commercial group. This way, we could increase the protection of your VPS in a timely manner as opposed to waiting for an official update.
ModSecurity in Dedicated Hosting
All of our dedicated servers which are set up with the Hepsia hosting Control Panel come with ModSecurity, so any application you upload or set up shall be properly secured from the very beginning and you won't have to worry about common attacks or vulnerabilities. An individual section in Hepsia will enable you to start or stop the firewall for any domain or subdomain, or turn on a detection mode so that it records info about intrusions, but doesn't take actions to prevent them. What you'll find in the logs shall allow you to to secure your Internet sites better - the IP an attack originated from, what site was attacked and exactly how, what ModSecurity rule was triggered, etc. With this information, you'll be able to see if an Internet site needs an update, if you need to block IPs from accessing your web server, etc. Besides the third-party commercial security rules for ModSecurity we use, our administrators include custom ones as well every time they come across a new threat that is not yet included in the commercial bundle.