What is ModSecurity

Web Application Firewall: Protects against common attacks (SQLi, XSS).

Enable in WHM (Root Required)

WHM → Security Center → ModSecurity → Enable for all vendors.

Per-Domain Control (If Available)

Some hosts allow disabling for specific domains if false positives occur.

Handling False Positives

Check ModSecurity Hits

Look in ModSecurity Tools → Hits List → Find rule ID → Disable specific rule.

Protection Types Table

Attack TypeBlocked By
SQL InjectionSQLi rules
XSSScripting rules
Path TraversalFile access rules
Brute ForceCombined with cPHulk