ModSecurity is a plugin for Apache web servers which acts as a web app layer firewall. It's used to stop attacks against script-driven websites by employing security rules that contain specific expressions. That way, the firewall can block hacking and spamming attempts and shield even sites which are not updated regularly. For instance, several unsuccessful login attempts to a script administrator area or attempts to execute a particular file with the purpose to get access to the script will trigger specific rules, so ModSecurity will block these activities the second it discovers them. The firewall is extremely efficient as it tracks the entire HTTP traffic to a website in real time without slowing it down, so it could prevent an attack before any damage is done. It also keeps an exceptionally comprehensive log of all attack attempts that features more info than conventional Apache logs, so you could later examine the data and take additional measures to increase the security of your Internet sites if needed.

ModSecurity in Shared Hosting

ModSecurity comes standard with all shared hosting packages which we supply and it shall be turned on automatically for any domain or subdomain which you add/create inside your Hepsia hosting CP. The firewall has 3 different modes, so you can switch on and disable it with a mouse click or set it to detection mode, so it'll keep a log of all attacks, but it shall not do anything to prevent them. The log for any of your websites shall feature detailed info such as the nature of the attack, where it came from, what action was taken by ModSecurity, etc. The firewall rules which we use are regularly updated and include both commercial ones that we get from a third-party security company and custom ones our system admins include in case that they detect a new kind of attacks. This way, the websites you host here shall be a lot more protected without any action needed on your end.