Web Application Firewall (ModSecurity)

Back

The web application firewall (ModSecurity) checks every request to the websites and stops attacks such as SQL injection, cross-site scripting and remote code execution.

Web application firewall mode
Requests are not checked.
Requests are checked and events are logged, but nothing is blocked.
Requests are checked and those that break the rules are blocked (403 Forbidden).
Rule set
Configuration preset
Only the address and the headers of requests are checked: the least load.
Recommended. The request body (forms, uploads) is checked too.
Also the responses are checked (data leaks) and more rules are logged without blocking: more load.

Switch off security rules

Rules that block legitimate requests (false positives) can be switched off for the whole server here, or for one domain on its Web Application Firewall page. The IDs are in the log.

One per line, or a range, e.g. 942100 or 941100-941199.
One per line, e.g. attack-xss.
One per line: the rule's message (regular expression).
ModSecurity directives added after the rule set (e.g. your own SecRule). They are checked before they are applied.

The latest requests the firewall blocked or detected (newest first). A request opens its details: the rules and what they matched.