ModSecurity acts as a web application firewall at the server level. Learn what it protects against and how to enable it in WHM.
What ModSecurity Does
ModSecurity is an open-source web application firewall (WAF) module that inspects incoming HTTP requests in real time, blocking common attack patterns such as SQL injection, cross-site scripting (XSS), and other exploit attempts before they ever reach your website’s code.
Why It’s a Critical Layer
Many website vulnerabilities exist in third-party plugins, outdated CMS versions, or custom code that hasn’t been fully audited. ModSecurity provides a protective layer that can catch and block malicious requests targeting these weaknesses, even before a patch is available.
How to Enable ModSecurity in WHM
- Log in to WHM and navigate to Security Center > ModSecurity Configuration.
- Toggle ModSecurity to Enabled for the server or for specific accounts/domains as needed.
- Under Security Center > ModSecurity Vendors, install a maintained rule set such as the OWASP Core Rule Set (CRS) or Comodo’s rule set.
- Review any active rules that may be too aggressive for your specific applications and adjust as needed to reduce false positives.
Managing False Positives
- Monitor the ModSecurity audit log after enabling to catch legitimate traffic being blocked incorrectly.
- Use WHM’s ModSecurity Tools to review and selectively disable specific rules causing issues, rather than disabling ModSecurity entirely.
- Test critical site functionality (forms, checkout flows, login pages) after enabling to confirm nothing is broken.
Long-Term Value
ModSecurity requires occasional tuning, but the protection it provides against common exploitation techniques makes it one of the highest-value security features available on a cPanel server.