🛡
Hosting

Every website open to internet traffic is a constant target for attack bots, regardless of size. A Web Application Firewall (WAF) is a non-negotiable protection layer — and cPGuard WAF is what AsiaGB runs on every server to automatically protect customer websites.

cPGuard WAF runs on the ModSecurity engine with a commercial Malware.Expert rule set of 750+ rules built from real-world traffic analysis across more than 100,000 domains — far more accurate than free rule sets.

What is a WAF and how does it work?

A Web Application Firewall sits between the internet and your web application, inspecting every HTTP/HTTPS request and comparing it against a ruleset. If a request matches an attack pattern, the WAF drops it before it ever reaches your PHP code or database.

Unlike a network firewall that only sees IP addresses and ports, a WAF works at Layer 7 (Application Layer) and reads request content — detecting SQL injection in query parameters or malicious JavaScript in form fields.

cPGuard WAF is powered by ModSecurity, the globally trusted open-source WAF engine, combined with Malware.Expert commercial rules built from real traffic analysis. This delivers far better detection than generic free rule sets.

Attack types cPGuard WAF blocks

CMS-specific rulesets

CMSRules covered
WordPressXML-RPC abuse, wp-login brute force, REST API attacks, plugin exploit patterns
JoomlaAdmin login brute force, component exploits, SQL injection via Joomla params
DrupalDrupalgeddon patterns, node injection, module exploits

Automatic cloud rule updates

cPGuard WAF updates rules automatically from the cloud when new vulnerabilities or attack patterns emerge. OPSShield pushes updates to all servers without requiring a web server restart or any admin action — meaning your server is protected against new exploits faster than waiting for vendor patches.

Bandwidth bonus: cPGuard WAF also reduces CPU and bandwidth by blocking bad bots and scrapers before they reach the application layer, freeing resources for real traffic.

View WAF logs and manage via App Portal

Admins can review all WAF activity in the cPGuard App Portal: blocked requests with rule IDs, source IPs and countries, target URLs and payloads, and a real-time attack timeline. Individual site owners can also view logs for their own domains through the DirectAdmin plugin without needing server admin access.

Whitelisting false positives

Occasionally a WAF may block a legitimate request (false positive), common with apps that accept special-format input like HTML in form fields. cPGuard supports granular whitelisting: whitelist specific rules for a domain or URL, whitelist trusted IP addresses such as your office, or toggle individual rule sets on/off.

Frequently Asked Questions

What is cPGuard WAF?

cPGuard WAF (Web Application Firewall) is a filtering layer that sits between the internet and your website. It inspects every incoming HTTP request and blocks those matching attack patterns before they reach your PHP code or database. It runs on the ModSecurity engine with Malware.Expert commercial rules.

How is WAF different from a regular firewall?

A regular firewall operates at the network layer, blocking IPs and ports. A WAF operates at the application layer (Layer 7), reading HTTP request content and blocking based on attack patterns — such as SQL injection in query parameters or XSS scripts in URLs.

Does cPGuard WAF update rules automatically?

Yes — cPGuard WAF rules update automatically from the cloud when new threats emerge, with no web server restart or manual action required.

Does WAF affect site speed?

Impact is minimal. ModSecurity runs in-process with the web server; each request inspection takes only a few milliseconds and adds no extra round-trip because it is not a separate reverse proxy.

What if WAF blocks my legitimate site traffic?

This is a false positive. Check the WAF log in the App Portal to identify which rule triggered, then whitelist that rule for the affected domain. Contact support if you need help identifying the rule.

AsiaGB Hosting Includes cPGuard WAF on Every Plan

AsiaGB installs cPGuard WAF on every server. Your websites are automatically protected against SQL injection, XSS and other web attacks — on SSD from 500 THB/year.

See Hosting Plans

View all cheap Thailand web hosting plans →