Security
42 articles in this section
This section covers how to keep a site or server from being compromised at three levels at once: the network perimeter, the panel or VDS itself, and the accounts used to reach it. It walks through practical scenarios — from a bot hammering SSH with password guesses to preparing for a real DDoS attack — rather than vague advice like "use a strong password".
On the server side it covers the firewall (UFW) and Fail2ban, which together stop SSH brute-forcing and Nginx login abuse, plus baseline MySQL hardening against common misconfigurations. At the application layer: ModSecurity as a WAF, Content Security Policy against XSS, and spam and bot filtering that would otherwise flood forms and the admin panel.
It also explains the difference between SSL certificate types (DV, OV, EV) and why a mixed content warning on an HTTPS site is not cosmetic but an actual security hole. For login, there are SSH keys instead of passwords on a VDS and two-factor authentication in cPanel; for DDoS, how protection works on ZevsHost's side and what else can be configured.