{"id":22475,"date":"2026-08-28T10:24:03","date_gmt":"2026-08-28T08:24:03","guid":{"rendered":"https:\/\/www.curiaweb.ch\/?post_type=docs&#038;p=22475"},"modified":"2026-08-28T10:28:20","modified_gmt":"2026-08-28T08:28:20","password":"","slug":"cpanel-security-features","status":"publish","type":"docs","link":"https:\/\/www.curiaweb.ch\/en\/hilfe\/webhosting-cpanel\/cpanel-sicherheit-funktionen\/","title":{"rendered":"cPanel Security: SSL, SSH, ModSecurity, 2FA and Imunify360 Explained"},"content":{"rendered":"<p class=\"wp-block-paragraph\">In the field of <strong>Safety<\/strong> of your CURIAWEB cPanel you will find tools to protect your hosting account, your websites, and encrypted communication. Here you can, among other things, manage SSL certificates, enable two-factor authentication, block IP addresses, and access security-related features such as ModSecurity and Imunify360.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At CURIAWEB you will find the functions in this area <strong>SSH access<\/strong>, <strong>IP blocking<\/strong>, <strong>SSL\/TLS Certificates<\/strong>, <strong>Manage API tokens<\/strong>, <strong>Hotlink protection<\/strong>, <strong>Protection against password sharing<\/strong>, <strong>ModSecurity<\/strong>, <strong>Two-factor authentication<\/strong> and <strong>Imunify360<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we explain what these security features are intended for and which settings require special caution.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Briefly explained:<\/strong> Security in web hosting does not consist of a single feature. For example, SSL protects data transmission, two-factor authentication secures your cPanel access, and Imunify360 helps protect the hosting environment and your websites from various threats.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Where can you find the security features?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Log in to your CURIAWEB cPanel and open the section on the home page <strong>Safety<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\" style=\"margin-top:50px;margin-bottom:50px\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"571\" src=\"https:\/\/www.curiaweb.ch\/wp-content\/uploads\/2026\/08\/cpanel-sicherheit-funktionen-1024x571.png\" alt=\"cPanel Security: SSL, SSH, ModSecurity, 2FA and Imunify360 Explained\" class=\"wp-image-22477\" srcset=\"https:\/\/www.curiaweb.ch\/wp-content\/uploads\/2026\/08\/cpanel-sicherheit-funktionen-1024x571.png 1024w, https:\/\/www.curiaweb.ch\/wp-content\/uploads\/2026\/08\/cpanel-sicherheit-funktionen-300x167.png 300w, https:\/\/www.curiaweb.ch\/wp-content\/uploads\/2026\/08\/cpanel-sicherheit-funktionen-768x428.png 768w, https:\/\/www.curiaweb.ch\/wp-content\/uploads\/2026\/08\/cpanel-sicherheit-funktionen-360x201.png 360w, https:\/\/www.curiaweb.ch\/wp-content\/uploads\/2026\/08\/cpanel-sicherheit-funktionen.png 1400w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">There you will find the following features:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SSH access<\/li>\n\n\n\n<li>IP blocking<\/li>\n\n\n\n<li>SSL\/TLS Certificates<\/li>\n\n\n\n<li>Manage API tokens<\/li>\n\n\n\n<li>Hotlink protection<\/li>\n\n\n\n<li>Protection against password sharing<\/li>\n\n\n\n<li>ModSecurity<\/li>\n\n\n\n<li>Two-factor authentication<\/li>\n\n\n\n<li>Imunify360<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">An overview of all areas of your cPanel can be found under <a href=\"\/en\/help\/web-hosting-cpanel\/cpanel-funktionen-ueberblick\/\">cPanel at CURIAWEB explained: All areas and functions at a glance<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">SSH access<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SSH<\/strong> stands for <strong>Secure Shell<\/strong> and provides encrypted access to the command line of a server or hosting account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead of managing files and settings exclusively through graphical interfaces, technically experienced users can perform certain tasks via terminal commands.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SSH is used, for example, by developers and administrators for command-line tools, file management, development workflows, or other technical tasks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You don't necessarily need SSH for the normal administration of a website.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Important:<\/strong> SSH provides direct access to the technical features of your hosting account. Do not run commands from someone else&#x27;s guide if you do not understand what those commands will change or delete.<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">SSH keys<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SSH can be used with cryptographic key pairs. Here, a key pair consists of a <strong>private<\/strong> and a <strong>public<\/strong> Key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The public key can be stored on the target system. The private key remains with the user and must not be disclosed to third parties.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Safety:<\/strong> Treat a private SSH key like a highly sensitive access credential. Do not publish it, do not transmit it unencrypted, and do not store it in publicly accessible locations.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">IP blocking<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With the <strong>IP blocking<\/strong> can you block access from certain IP addresses or correspondingly defined address ranges to your website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This can be useful, for example, if unwanted or malicious requests are repeatedly sent from a specific address.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, IP blocking should be used selectively. IP addresses can be assigned dynamically or shared among multiple users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Blocking a single IP address is therefore not a general solution to spam, bots, or attacks.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Attention:<\/strong> Before blocking large IP ranges, check carefully which addresses are affected. A rule that is too broad may also block legitimate visitors.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">SSL\/TLS Certificates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Under <strong>SSL\/TLS Certificates<\/strong> You manage certificates and the associated cryptographic information for encrypted connections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SSL, or\u2014from a technical standpoint today\u2014primarily <strong>TLS<\/strong> enables the encrypted transmission of data between a client and the server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On a website, you can usually tell that a connection has been set up this way by an address that starts with <code>https:\/\/<\/code> begins.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What does HTTPS protect?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">HTTPS protects data transmitted between the browser and the web server from being easily intercepted or tampered with during transmission and allows the browser to verify the identity for which the certificate was issued or is valid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is particularly important for registrations, forms, customer data, and other sensitive transmissions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, HTTPS does not mean that the website itself is automatically free of security vulnerabilities or malware.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Important:<\/strong> A valid SSL\/TLS certificate does not confirm that a website is trustworthy in terms of its content or completely secure from a technical standpoint. It primarily protects the encrypted connection and provides the authentication intended for it.<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">Certificate, private key and CSR<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When working manually with SSL\/TLS, you may encounter several terms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>Certificate<\/strong> contains, among other things, information about the secured identity or domain and is signed by a certificate authority.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The corresponding one <strong>private key<\/strong> It is secret and must not be published.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>CSR<\/strong> \u2013 Certificate Signing Request \u2013 is a certificate request used in certain procedures for issuing a certificate.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Safety:<\/strong> A private SSL\/TLS key must not be publicly accessible. Anyone who has the matching private key possesses a security-critical component of the certificate configuration.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">SSL certificate and HTTPS are closely connected, but not identical<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A certificate is a technical component of the HTTPS configuration. However, for a website to actually function correctly via HTTPS, the web server and the website must also be configured accordingly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a website can have a valid certificate and still load internal resources via unencrypted HTTP. In that case, so-called mixed content issues can occur.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HTTP to HTTPS redirects and the configuration of the respective web application can also play a role.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Manage API tokens<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With <strong>API Tokens<\/strong> Applications or automated processes can access authorized cPanel functions without having to use the normal cPanel password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is relevant, for example, in automations or external management systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An API token is an access key and must be protected accordingly.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Important:<\/strong> API tokens do not belong in publicly accessible files, screenshots, support forums, or source code repositories. Treat them like credentials.<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\">Why are separate tokens useful?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A dedicated token can be created for a specific purpose and later revoked without having to change your actual cPanel password.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When an integration is no longer in use, a token created for it should not remain active unnecessarily.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Hotlink protection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With the <strong>Hotlink protection<\/strong> Can you prevent or restrict other websites from embedding certain files directly from your domain?.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A typical example is images.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an external website does not copy an image to its own server, but instead embeds it directly via a URL from your domain, the file continues to be served from your hosting with every corresponding request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This generates data traffic on your hosting, even though the content is displayed on a third-party website.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Configure hotlink protection wisely<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Not every external use of a file is automatically unwanted. Certain applications, CDNs, or other legitimate services may also access resources on your domain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An overly restrictive configuration can therefore lead to images or other files no longer being displayed in places where you actually need them.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Practical Tip:<\/strong> Do not enable hotlink protection simply on principle. First, check whether unwanted hotlinking is actually occurring and which external services your website uses.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Protection against password sharing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The function <strong>Protection against password sharing<\/strong> is related to protected web directories and is intended to prevent access credentials for such areas from being improperly reused or shared.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is therefore a special addition for certain access-protected areas and not a general password manager for cPanel, WordPress, or email accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For most normal websites, this function does not need to be changed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">ModSecurity<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ModSecurity<\/strong> is a Web Application Firewall, or WAF for short <strong>WAF<\/strong>, which can inspect HTTP requests based on defined security rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Such rules can detect suspicious or known attack patterns and block corresponding requests before they are processed by a web application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This can help, for example, with protection against certain web-based attack methods.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why can ModSecurity block a legitimate request?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A Web Application Firewall must decide based on technical characteristics whether a request appears suspicious. In certain cases, legitimate requests can also trigger a security rule.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is considered as <strong>False Positive<\/strong> referred to as.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One possible symptom can be, for example, that a specific action within a website is blocked, even though other areas function normally.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Attention:<\/strong> Do not disable ModSecurity permanently just because a single action is blocked. First, you should check which security rule was triggered and why.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">ModSecurity is not a replacement for a secure website<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A Web Application Firewall provides an additional layer of protection. However, it does not replace updates, secure passwords, or the securing of the actual web application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An outdated WordPress installation or a plugin with a security vulnerability does not become more secure software just because a firewall operates in front of it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Several protective mechanisms therefore complement each other.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Two-factor authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With the <strong>Two-factor authentication<\/strong> \u2013 short <strong>2FA<\/strong> \u2013 you can additionally secure access to your cPanel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For a normal login, a username or account and the corresponding password are sufficient. If two-factor authentication is enabled, a second factor is also required.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In cPanel, a time-based one-time code generated by a compatible authenticator app is typically used for this.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why is 2FA useful?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If your password is stolen or otherwise exposed, with two-factor authentication enabled, it alone is no longer enough for a normal login. An attacker would additionally need the second factor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This significantly increases the security of administrative access with 2FA.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Recommendation:<\/strong> If two-factor authentication is available for your cPanel access, activating it is a sensible additional security measure.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">What happens if you lose the second factor?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If the device with your authenticator app is lost or no longer available, signing in can be made correspondingly more difficult.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, when setting up two-factor authentication, you should also consider how you will regain access in an emergency or what recovery options are provided for the respective account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not remove a working 2FA configuration lightly just for convenience.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Imunify360<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Imunify360<\/strong> is an additional security platform for web hosting environments and is integrated into the CURIAWEB hosting infrastructure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The solution complements the classic cPanel functions with additional security mechanisms. Depending on the server-side configuration, this can include malware detection and further protection and analysis functions, among other things.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although Imunify360 is displayed within cPanel, it is <strong>a security module not developed by cPanel itself<\/strong>. It is a standalone security solution that integrates into the hosting interface.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Briefly explained:<\/strong> cPanel provides the management interface. Imunify360 is an additional security solution within the CURIAWEB hosting environment. The fact that you access Imunify360 via cPanel does not make it a cPanel-native feature.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Malware Detection with Imunify360<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An important task of Imunify360 is the detection of suspicious or malicious files within the hosting environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a file is identified as suspicious, it first means that it should be examined for security relevance or treated in accordance with the server-side security configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, in the case of a compromised website, it is not always sufficient to look at just a single file that was found.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, an attacker may have modified several files, created new user accounts, stolen credentials, or exploited a vulnerability in a web application.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Important:<\/strong> If malware is found on a website, the cause of the compromise must also be addressed. Otherwise, a cleaned website can be attacked again via the same vulnerability.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Imunify360 does not replace updates<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Even a comprehensive security platform cannot turn an outdated web application into a permanently secure application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, WordPress, plugins, themes, and other installed applications should continue to be kept up to date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Software that is no longer in use should be removed, especially if it remains publicly accessible or executable.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Multiple security layers work together<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The various security features of your hosting fulfill different tasks and should not be considered interchangeable alternatives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SSL\/TLS<\/strong> secures the data transmission. <strong>2FA<\/strong> makes the abuse of administrative access more difficult. <strong>ModSecurity<\/strong> inspects web requests based on security rules. <strong>Imunify360<\/strong> adds further security mechanisms to the hosting environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Added to this are secure passwords, up-to-date web applications, correct file permissions, and other server-side protection measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The principle of multiple independent layers of protection is frequently referred to in IT security as <strong>Defense in Depth<\/strong> referred to as.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What should you do if a security feature blocks something?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When a legitimate action suddenly stops working, you should not immediately disable all security mechanisms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">First, try to narrow down the problem as precisely as possible. Note down the affected URL, the action performed, the exact time, and the error message displayed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In case of website issues, the cPanel error logs can also provide important clues.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">How we will show you how to evaluate these is below at <a href=\"\/en\/help\/web-hosting-cpanel\/read-cpanel-error-log\/\">Read cPanel Error Log and find website errors<\/a>.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Practical Tip:<\/strong> Disabling a security feature may seemingly fix an error without explaining the actual cause. For a clean solution, it is crucial to find out which mechanism was triggered and why.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">403 Forbidden and security features<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An HTTP error <code>403 Forbidden<\/code> basically means that access to the requested resource was denied.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Various causes are possible for this. In addition to security rules, file permissions, configuration rules, or access restrictions, for example, can play a role.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, a 403 error does not automatically prove that ModSecurity or Imunify360 blocked the request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We will cover systematic troubleshooting later under <a href=\"\/en\/help\/web-hosting-cpanel\/fehler-403-forbidden-beheben\/\">Fix 403 Forbidden<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What shouldn't you change on suspicion?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Special caution is advised regarding security functions whose effects you do not fully understand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Disabling ModSecurity completely, blocking extensive IP ranges, deleting certificate components, or simply ignoring security alerts can cause new problems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Changes should therefore always have a concrete technical reason.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Basic rule:<\/strong> In the event of a security issue, diagnose first, then make targeted changes. Do not disable multiple security mechanisms at the same time just to check if a website works again afterward.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Security warning or technical error?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Not every technical problem is a security incident. At the same time, an unusual change to a website should not be hastily dismissed as an ordinary software bug.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A PHP error after an update can, for example, be a normal compatibility problem. Unknown files, unexpected redirects, tampered content, or newly created unknown administrators, on the other hand, can indicate a compromise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Therefore, the overall context is decisive in the assessment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Summary<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The area <strong>Safety<\/strong> Your CURIAWEB cPanel contains various tools that protect different levels of your hosting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SSH<\/strong> enables encrypted technical access. Via the <strong>IP blocking<\/strong> certain accesses can be blocked. <strong>SSL\/TLS<\/strong> protects data transmission while <strong>API Tokens<\/strong> Enable controlled access for applications and automations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ModSecurity<\/strong> works as a web application firewall, and the <strong>Two-factor authentication<\/strong> offers additional protection for your cPanel access. With <strong>Imunify360<\/strong> is also an independent security platform integrated into the CURIAWEB hosting environment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not a single one of these features can cover all security risks. The key is the interplay of multiple layers of protection as well as a well-maintained and up-to-date website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a security feature blocks an action or a website displays an error, you should systematically investigate the cause first before disabling protective mechanisms.<\/p>","protected":false},"excerpt":{"rendered":"<p>Im Bereich Sicherheit deines CURIAWEB-cPanels findest du Werkzeuge zum Schutz deines Hosting-Accounts, deiner Websites und der verschl\u00fcsselten Kommunikation. Hier kannst du unter anderem SSL-Zertifikate verwalten, die Zwei-Faktor-Authentifizierung aktivieren, IP-Adressen blockieren und sicherheitsrelevante Funktionen wie ModSecurity und Imunify360 aufrufen. Bei CURIAWEB findest du in diesem Bereich die Funktionen SSH-Zugriff, IP-Blockierung, SSL\/TLS Certificates, API-Token verwalten, Schutz vor [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_joinchat":[],"footnotes":""},"doc_category":[78],"doc_tag":[],"class_list":["post-22475","docs","type-docs","status-publish","hentry","doc_category-webhosting-cpanel"],"year_month":"2026-09","word_count":2321,"total_views":"5","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"Silvio Mazenauer","author_nicename":"admin-curia","author_url":"https:\/\/www.curiaweb.ch\/en\/author\/admin-curia\/"},"doc_category_info":[{"term_name":"Webhosting &amp; cPanel","term_url":"https:\/\/www.curiaweb.ch\/en\/hilfe-kategorie\/webhosting-cpanel\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs\/22475","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/comments?post=22475"}],"version-history":[{"count":1,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs\/22475\/revisions"}],"predecessor-version":[{"id":22478,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/docs\/22475\/revisions\/22478"}],"wp:attachment":[{"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/media?parent=22475"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/doc_category?post=22475"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.curiaweb.ch\/en\/wp-json\/wp\/v2\/doc_tag?post=22475"}],"curies":[{"name":"WP","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}