Knowledge Base · Your Sites

Attack Protection

Requests are inspected on the NetSSL server before they reach your site. This guide explains the protection levels, the additional rules and how to test a rule before you start blocking with it.

What does this screen do?

The host's Security page decides which rules the requests to that site go through. The rules run on the NetSSL server and take effect a few seconds after you save. Each protection has its own on/off switch for each site.

Security settings: protection level and trusted countries


Protection level

Level What happens?
Standard Visitors enter without being asked for verification. Attack rules and automatic attack protection stay on.
Smart protection (recommended) Visitors from your trusted countries enter directly. Others go through a browser verification that takes a few seconds.
Attack mode Everyone goes through a short browser verification. It stays on until you turn it off.

If you leave the Trusted countries list empty, Türkiye counts as selected. All 249 countries are on the list.


Protections that turn on by themselves

  • If one IP sends too many requests: an IP that goes over 1,000 requests in 10 seconds is asked for browser verification. An IP that goes over 3,000 requests is banned.
  • Mass attack: automatic attack protection asks everyone for verification once. It turns itself off 30 minutes after the attack ends, and you get an email.
  • Persistent attackers: an IP that gets caught 120 times in 1 minute is banned at the firewall. The ban time doubles each time, up to 24 hours.
  • Scan protection: an IP that probes addresses such as .env, .git, backup files or phpmyadmin gets verification after 3 attempts in 10 minutes and a ban after 10 attempts.
  • USOM malicious address list: USOM is Türkiye's national cyber incident response center. The list is updated from this official source every 6 hours.
  • NetSSL shared threat list: an address that attacks one organization is stopped at the other organizations too.

Automatic attack protection, scan protection and the USOM list


Additional rules

You turn on each rule separately. The eye icon previews the page that the rule will show to visitors.

  • Country access, IP address lists (allow, exempt, block)
  • AI bots (content scrapers such as ChatGPT, Claude and Perplexity)
  • Tor and VPN and data center and cloud IPs (block or require verification)
  • Login page protection: verification after 5 failed attempts, a ban after 20 attempts
  • Form and file upload protection: dangerous files such as .php and .exe, and rapid repeated submissions
  • Request limit and automatic ban, working hours rule (for example weekdays 08:00–18:00)
  • Admin panel lock: admin pages of WordPress, Joomla and similar software open only from your organization's network or with an email code
  • File theft (hotlinking): other sites cannot use your images, videos and documents
  • Custom rules: block, verify or allow by address, country, IP, browser and method

Additional rules: the status and preview next to each rule


Test mode

Before you turn on a new rule, tick the Test box. The rule blocks no one and only counts. The panel gives you a summary like this: “This rule would have blocked 412 requests in the last 24 hours, 12 of them from Türkiye, from 85 different IPs.” If the result looks right, click the Switch to blocking button.


Virtual patching and other protections

  • Virtual patching: requests aimed at known vulnerabilities are stopped until your software is updated. The PHPUnit, Laravel Ignition, Log4Shell and ThinkPHP patches are on for every site. You turn on patches such as Exchange ProxyShell and jQuery File Upload as needed.
  • Cookie security: missing Secure, HttpOnly and SameSite flags are added to the session cookies your server sends. You can exclude cookies used by virtual POS payments or e-Devlet login.
  • Bot management: real Google and Bing bots are verified by their IP address and let through. Fake ones are blocked. Automation tools such as curl and Python are limited to 120 requests per minute.
  • External script monitoring and CSP: you are notified when new external code is added to your pages. The content security policy first runs in Report only mode. It can be switched to Enforce mode after at least 3 days.
  • Exposed file and secret key scan: once a week, the scan looks for exposed backups, configuration files and SQL dumps, and for passwords visible in page code. The values it finds are not stored.
  • Software versions: once a day, old and vulnerable versions of software such as WordPress, Joomla, jQuery and PHP are checked passively. No penetration testing is done.

Virtual patch list and cookie security


Target server protection

If an attacker can bypass NetSSL and connect to your server directly, the protection is incomplete. The panel regularly checks whether your server is directly open to the internet. To help you allow only NetSSL addresses in your firewall, guides are ready for FortiGate, Sophos, Palo Alto, Check Point, WatchGuard, pfSense, MikroTik, Labris, Windows Server, Linux and Plesk/cPanel.

💡
Test first, then block

Run rules with a broad effect, such as country access and request limits, in test mode for a few days. Switch to blocking once you see that they do not affect real visitors.


Frequently asked questions

With smart protection, are visitors from Türkiye asked for verification?

No. Visitors from your trusted countries enter directly. Only visitors from other countries and from suspicious sources are asked for verification.

What does verification show the visitor?

A “Verifying your browser” page for a few seconds. The visitor does not need to click anything or pick images.

Will our mobile app or integrations be affected?

You define API and integration paths separately. Requests on these paths are not asked for verification.