{"id":75,"date":"2014-11-01T18:47:56","date_gmt":"2014-11-01T18:47:56","guid":{"rendered":"https:\/\/www.fastcomet.com\/blog\/?p=75"},"modified":"2022-06-10T08:12:58","modified_gmt":"2022-06-10T08:12:58","slug":"fastcomet-modsecurity-cpanel-feature","status":"publish","type":"post","link":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature","title":{"rendered":"Introducing the FastComet ModSecurity cPanel Feature"},"content":{"rendered":"\n<p class=\"has-drop-cap has-text-align-left\">Since the beginning, our Security Specialists are developing a universal solution for defending our clients\u2019 websites from malicious attacks targeting known vulnerabilities in the most used open-source applications. Every month the major security monitors are reporting tons of vulnerabilities mostly in the commonly used WordPress plugins and\/or Joomla components and every month our FastComet Security Team is implementing new rule sets in our WAF (Web Application Firewall) in order to get these vulnerabilities covered and to provide our customers with an outstanding security layer.<\/p>\n\n\n\n<!--more-->\n\n\n\n<h2 class=\"wp-block-heading\">How Does our WAF Actually Protect Your Website?<\/h2>\n\n\n\n<p class=\"has-text-align-left\">Well, using some mojo called Web Requests Filtering. Every time someone (a user typically) access your website he or she is performing a request to a resource hosted on your account with us. Our WAF is checking that request initially and after the request is verified the same is allowed to reach the server.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"236\" height=\"193\" src=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_4.gif\" alt=\"How Does our WAF Actually Protect Your Website\" class=\"wp-image-1028\"\/><\/figure>\n<\/div>\n\n\n<p>When the request reaches the server it is handled by some service \u2013 usually the web service and furthermore the PHP service. The result from that process is then sent back to the user but before the result is released from the server our WAF checks it again for any malicious code. If it contains any malicious code then the result is terminated and the user is unable to see it as the server sends an error page as a result.<\/p>\n\n\n\n<p>Do you wonder how come that some error message from the server is better for the users than your actual website? &#8211; The answer is pretty straightforward &#8211; if your website contains some malicious elements it gets penalized by Google resulting in a dramatic drop in the site rank in a normal Google search. Imagine what this can cause to your Business.<\/p>\n\n\n\n<p>So basically we got you covered in every possible way so even if your website gets hacked it will not be displayed to your users as you cannot afford to lose any of them.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Changes we Have Implemented and How You Will be able to Benefit from Those?<\/h2>\n\n\n\n<p class=\"has-text-align-left\">Until now the WAF was Active by default for all our <a href=\"https:\/\/www.fastcomet.com\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">Shared Hosting Packages<\/a> &#8211; Single Website Package, Multiple Websites Package and our E-Commerce Package with no option for the firewall to be disabled natively using the cPanel service.<\/p>\n\n\n\n<p>From this point on that protection can be fully managed via the newly implemented security Feature in the cPanel service called \u201c<strong>ModSecurity<\/strong>\u201d which most probably some of our customers might have already noticed.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"115\" src=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_1.jpg\" alt=\"New Security Feature in the cPanel Service ModSecurity\" class=\"wp-image-1029\" srcset=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_1.jpg 770w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_1-300x45.jpg 300w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_1-768x115.jpg 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n<\/div>\n\n\n<p>You are probably wondering why in the world you will need to disable that feature and to lift off the protection from your account.<\/p>\n\n\n\n<p>Many of the custom installations such as plugins, modules, themes and so on are products of third-party developers who are not familiar with our WAF. In some cases, the installation procedures of these components will result in an error message from our WAF due to the fact that the components are triggering some security rule. In that particular case, our customers can disable <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.modsecurity.org\/\" target=\"_blank\">ModSecurity<\/a> for a brief period of time \u2013 until the installation\/update\/deletion lasts and then to enable it again.<\/p>\n\n\n\n<p class=\"has-text-align-left\">To be even more beneficial that feature allows the customers to enable\/disable the feature only for concrete domain or subdomain so for example if you are trying to install some plugin which is resulting in an error from our WAF on a subdomain you can simply disable ModSecurity for that subdomain in particular. This allows for your entire account to remain under the protection except for the subdomain you are currently using.<\/p>\n\n\n\n<p class=\"has-text-align-left\">The same goes for every other domain or subdomain you have configured in your cPanel service.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Let\u2019s see How the Feature Actually Looks like and What Options it Provides<\/h2>\n\n\n\n<p class=\"has-text-align-left\">Right, when you access the ModSecurity feature you will probably notice that it is already enabled for your account.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"301\" src=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_2.jpg\" alt=\"ModSecurity Enabled by Default\" class=\"wp-image-1030\" srcset=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_2.jpg 770w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_2-300x117.jpg 300w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_2-768x300.jpg 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n<\/div>\n\n\n<p>By default, every account on our Shared Hosting environment will have that feature enabled for all of the domains\/subdomains included in the account. If you would like to disable <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.modsecurity.org\/\" target=\"_blank\">ModSecurity<\/a> for all of your domains\/subdomains, simply use the <strong>Disable<\/strong> button.<\/p>\n\n\n\n<p class=\"has-text-align-left\">Then you will be presented with a simple list containing all of your domains and subdomains. The items are sorted on pages and also you will be able to search for a particular domain or subdomain with the implemented search feature.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"427\" src=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_3.jpg\" alt=\"List of All Domains and Subdomains in ModSecurity\" class=\"wp-image-1045\" srcset=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_3.jpg 770w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_3-300x166.jpg 300w, https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/mod_sec_3-768x426.jpg 768w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n<\/div>\n\n\n<p>In order to enable or disable the WAF for a particular domain or subdomain, you will need to simply click on the \u201cOn\u201d button for enabling and the <strong>Off<\/strong> button for disabling. The current state of the service for a particular domain or subdomain will be colored in dark blue color so you can be completely sure if it is enabled or disabled before performing any change.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Since the beginning, our Security Specialists are developing a universal solution for defending our clients\u2019 websites from malicious attacks targeting known vulnerabilities in the most used open-source applications. Every month the major security monitors are reporting tons of vulnerabilities mostly in the commonly used WordPress plugins and\/or Joomla components and every month our FastComet Security [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":547,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4726],"tags":[8,9],"class_list":["post-75","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-service-updates","tag-cpanel","tag-security"],"featured_image_src":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/ModSecurity.jpg","author_info":{"display_name":"Christopher","author_link":"https:\/\/www.fastcomet.com\/blog\/author\/christopher"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Introducing the FastComet ModSecurity cPanel Feature | FastComet<\/title>\n<meta name=\"description\" content=\"From this point on WAF protection can be fully managed via the newly implemented security Feature in the cPanel service called \u201cModSecurity\u201d.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Introducing the FastComet ModSecurity cPanel Feature | FastComet\" \/>\n<meta property=\"og:description\" content=\"From this point on WAF protection can be fully managed via the newly implemented security Feature in the cPanel service called \u201cModSecurity\u201d.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature\" \/>\n<meta property=\"og:site_name\" content=\"FastComet Blog\" \/>\n<meta property=\"article:published_time\" content=\"2014-11-01T18:47:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-06-10T08:12:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/ModSecurity.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"576\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Christopher\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christopher\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Introducing the FastComet ModSecurity cPanel Feature | FastComet","description":"From this point on WAF protection can be fully managed via the newly implemented security Feature in the cPanel service called \u201cModSecurity\u201d.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature","og_locale":"en_US","og_type":"article","og_title":"Introducing the FastComet ModSecurity cPanel Feature | FastComet","og_description":"From this point on WAF protection can be fully managed via the newly implemented security Feature in the cPanel service called \u201cModSecurity\u201d.","og_url":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature","og_site_name":"FastComet Blog","article_published_time":"2014-11-01T18:47:56+00:00","article_modified_time":"2022-06-10T08:12:58+00:00","og_image":[{"width":1024,"height":576,"url":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/ModSecurity.jpg","type":"image\/jpeg"}],"author":"Christopher","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christopher","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#article","isPartOf":{"@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature"},"author":{"name":"Christopher","@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/e70bae8b5451b247e36928e336317827"},"headline":"Introducing the FastComet ModSecurity cPanel Feature","datePublished":"2014-11-01T18:47:56+00:00","dateModified":"2022-06-10T08:12:58+00:00","mainEntityOfPage":{"@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature"},"wordCount":794,"commentCount":0,"image":{"@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#primaryimage"},"thumbnailUrl":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/ModSecurity.jpg","keywords":["cpanel","security"],"articleSection":["Service Updates"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature","url":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature","name":"Introducing the FastComet ModSecurity cPanel Feature | FastComet","isPartOf":{"@id":"https:\/\/www.fastcomet.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#primaryimage"},"image":{"@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#primaryimage"},"thumbnailUrl":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/ModSecurity.jpg","datePublished":"2014-11-01T18:47:56+00:00","dateModified":"2022-06-10T08:12:58+00:00","author":{"@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/e70bae8b5451b247e36928e336317827"},"description":"From this point on WAF protection can be fully managed via the newly implemented security Feature in the cPanel service called \u201cModSecurity\u201d.","breadcrumb":{"@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#primaryimage","url":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/ModSecurity.jpg","contentUrl":"https:\/\/www.fastcomet.com\/blog\/wp-content\/uploads\/2014\/11\/ModSecurity.jpg","width":1024,"height":576},{"@type":"BreadcrumbList","@id":"https:\/\/www.fastcomet.com\/blog\/fastcomet-modsecurity-cpanel-feature#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.fastcomet.com\/blog"},{"@type":"ListItem","position":2,"name":"Introducing the FastComet ModSecurity cPanel Feature"}]},{"@type":"WebSite","@id":"https:\/\/www.fastcomet.com\/blog\/#website","url":"https:\/\/www.fastcomet.com\/blog\/","name":"FastComet Blog","description":"FastComet Web Hosting Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.fastcomet.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/e70bae8b5451b247e36928e336317827","name":"Christopher","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fastcomet.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/99f135e26f1ad748551251c1956e4aae0bd3bcc11af8e071075359b134894941?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/99f135e26f1ad748551251c1956e4aae0bd3bcc11af8e071075359b134894941?s=96&d=mm&r=g","caption":"Christopher"},"description":"Christopher has many years of experience leading teams in the fields of Technical support, Server Administration, and Product Development. He mainly works on the backend, helping to create the infrastructure that powers FastComet. He is responsible for flawless migrations and quick and efficient answers to client questions. He also monitors our network status and jumps in to solve time-sensitive issues like DDoS attacks and stops malicious attempts in their tracks. Christopher\u2019s primarily responsible for making sure that our servers purr along, and has worked tirelessly to improve automation at FastComet.","sameAs":["https:\/\/www.fastcomet.com"],"url":"https:\/\/www.fastcomet.com\/blog\/author\/christopher"}]}},"_links":{"self":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts\/75","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/comments?post=75"}],"version-history":[{"count":10,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts\/75\/revisions"}],"predecessor-version":[{"id":7992,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/posts\/75\/revisions\/7992"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/media\/547"}],"wp:attachment":[{"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/media?parent=75"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/categories?post=75"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.fastcomet.com\/blog\/wp-json\/wp\/v2\/tags?post=75"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}