BashEdge for DirectAdmin

DirectAdmin DDoS protection that keeps every hosted website online.

Stop application-layer request floods before they consume the Web server. BashEdge combines Layer 7 DDoS protection, a DirectAdmin WAF, server firewall controls and login defence across every user and domain.

One-command install No reboot Monitor before blocking
BashEdge stopping a large DirectAdmin DDoS attack before clean traffic reaches the Web server and its hosted websites
Every user and domain coveredLayer 7 floods containedExisting firewall rules preservedTraffic changes only when approved
DirectAdmin server security

A shared hosting server has one pool of capacity.

DirectAdmin separates administrators, resellers, users and domains neatly. The Web server underneath still shares CPU, memory, PHP workers and network capacity. A request flood aimed at one application can therefore affect websites belonging to people who were never attacked.

BashEdge evaluates traffic before that shared capacity is spent. It connects request behaviour, attack rules, source identity and the targeted domain so the response protects the whole server without treating every visitor as hostile.

ONE TARGETA single hosted domain

Attackers repeatedly request expensive application paths.

SHARED PRESSUREWorkers and CPU fill up

Valid-looking requests bypass simple port controls.

WIDER IMPACTOther users slow down

Unrelated sites compete for the same remaining capacity.

BASHEDGEImpact stops at the edge

Hostile traffic is contained before application processing.

How BashEdge protects DirectAdmin

Inspect each request before the hosting stack does the expensive work.

The Web stack may use nginx, Apache, LiteSpeed or a combination. BashEdge makes the attack decision before hostile traffic reaches hosted applications.

INTERNET TRAFFICVisitors, bots and attacks
→
BASHEDGEInspect · verify · contain Hostile traffic stops here
→
01
Web servernginx, Apache or LiteSpeed
02
PHP + applicationDynamic requests and database work
→
DIRECTADMIN USERS
Every hosted domain
Inspect the request

Evaluate path, method, headers, parameters, source, network and behaviour.

Choose the response

Watch uncertain activity, verify suspicious visitors and block confirmed attacks.

Keep the evidence

Record the rule, reason, source and targeted domain for investigation.

Server-wide protection

Contain the attack before it crosses reseller and user boundaries.

A control panel can separate ownership, but it cannot create separate Web server capacity for each account. BashEdge protects at the shared request path, then preserves the target context needed to understand which user and domain were involved.

Protect one targeted domainLimit incident controls to the site under pressure.Protect every hosted websitePut the complete server behind visitor verification.Keep healthy traffic movingVerified visitors and trusted services continue normally.
A BashEdge security layer containing hostile request volume before clean traffic reaches separate DirectAdmin users and hosted websites
DIRECTADMIN REQUEST PRESSURE Protection active
Hostile requests21,840/minVerified traffic734/min
Attack traffic contained Verified requests passedAll hosted users remain available
DirectAdmin DDoS protection

Stop Layer 7 floods that look like ordinary Web traffic.

A DirectAdmin firewall can control whether a source reaches a port. An application-layer DDoS attack already uses an allowed port and may send technically valid HTTP requests. The danger comes from rate, coordination and the cost of the requested path.

BashEdge detects high-rate clients, distributed campaigns, rotating identities, repeated expensive URLs and automation that shifts across domains. During an active incident, Lockdown Mode verifies new visitors before they reach the Web server.

  • Respond at server speed. Activate protection for one site or every DirectAdmin user.
  • Recognise coordinated activity. Connect sources that behave like one campaign.
  • Preserve legitimate access. Trusted services, allowlisted clients and verified crawlers continue.
DirectAdmin firewall, ModSecurity and BashEdge

Give every security layer a clear responsibility.

DirectAdmin servers often use a network firewall and ModSecurity. Both remain useful. BashEdge works alongside the controls already present and adds the behavioural, server-wide view needed for request floods and coordinated attacks.

No destructive replacement

Existing firewall rules remain in place. You can observe BashEdge decisions before enabling any traffic-changing action.

Security layerPrimary roleWhat it sees best
DirectAdmin firewallNetwork accessSources, ports, protocols and connection rules
DirectAdmin ModSecurityRule-based WAFPayload patterns inside individual Web requests
DirectAdmin server security in one place

Protect websites, server services and the capacity connecting them.

One BashEdge installation covers the DirectAdmin server while keeping each protection decision traceable to its source and target.

Contain request floods

Detect high-rate clients and distributed application-layer campaigns before PHP workers and databases absorb the load.

Stop application attacks

Inspect URLs, parameters, headers and uploads for injection, execution, traversal, credential probing and webshell activity.

Control network access

Manage inbound and outbound policy without wiping the firewall configuration already protecting the server.

Defend server logins

Stop brute force attempts with service-specific thresholds for DirectAdmin, SSH, FTP, mail, Webmail and database authentication.

Understand hosted applications

Recognise abuse aimed specifically at WordPress, Joomla and Drupal instead of treating every website identically.

Explain every action

See the source, network, country, rule, reason, target and response in one threat record.

Web Application Firewall for DirectAdmin

Protect every domain with rules that understand the request.

A DirectAdmin WAF needs visibility beyond addresses and ports. BashEdge examines the parts of HTTP traffic an application exposes, then adds source and behaviour context before deciding whether to watch, verify or block.

More than 50 maintained rules cover common exploit paths and emerging abuse. Updates arrive without restarting the Web server, and application-aware controls provide additional protection for the CMS platforms commonly hosted on DirectAdmin.

Injection and executionSQL injection, command injection, remote code execution and dangerous framework behaviour.Files and credentialsTraversal, environment files, cloud credentials, backups, database dumps and configuration exposure.Persistent accessWebshells and backdoors hidden inside media or other writable application directories.Modern application abuseXSS, SSRF, NoSQL injection, deserialization, GraphQL probing and parameter pollution.
REQUEST INSPECTIONBlocked
POST/api/report/export403
DETECTED ASRemote command executionformat=pdf&renderer=$(malicious-command)
Stopped before PHP processingMatched a maintained execution rule and hostile source behaviour.
Target reports.exampleMode Block

Synthetic demonstration data. No customer traffic is shown.

Simple pricing, per server.

Every plan runs the same Web Application Firewall, Layer 7 DDoS protection, server firewall and intrusion prevention. Pick a plan by how many hosting accounts you need to cover.

Basic

Up to 10 hosting accounts

$12per month
Start free trial
  • Web Application Firewall (WAF)
  • Layer 7 DDoS protection
  • Server firewall & intrusion prevention
  • Watch, verify or block per rule
  • Up to 10 hosting accounts
  • Unlimited domains
Most popular
Premium

Unlimited hosting accounts

$23per month
Start free trial
  • Everything in Basic
  • Unlimited hosting accounts
  • Unlimited domains

Priority support is available as an add-on on any plan.

Price per server, per month, excluding VAT. Cancel anytime. Talk to us.

INCIDENT RESPONSELockdown Mode ACTIVE
PROTECTION SCOPEAll hosted domainsVISITOR POLICYVerify before origin
184hostile sources contained→BashEdgeBrowser verification→100%hosting users covered
Web server capacity is stableVerified visitors continue while the request flood is held back.
Protection during an active attack

Put one domain or the complete DirectAdmin server behind verification.

Lockdown Mode gives the hosting team a fast response when an incident is already underway. New visitors prove they are real browsers before reaching hosted sites, while allowlisted services and previously verified traffic continue.

Choose a targeted domain or every user Set a fixed duration or leave protection active Preserve trusted crawlers and operational services
DirectAdmin-aware operations

Keep the server-wide view without losing the targeted domain.

BashEdge groups protection around the way a hosting server is operated. Administrators can see overall pressure and active rules, then trace an event to the reseller, user and domain involved.

Admin viewCoverage, request pressure and service protection across the server.User contextThreat activity tied to the account and domain that received it.Safe rolloutMonitor rule impact before enforcement changes customer traffic.
DirectAdminServer Manager / BashEdge Protected
OverviewThreat activityDomainsFirewall
REQUESTS INSPECTED428,610ATTACKS CONTAINED1,284HOSTED DOMAINS486
reseller-demo124 domainsProtected
hosting-user38 domainsProtected
site-owner6 domainsProtected

Synthetic interface and demonstration values only.

DirectAdmin rule impactMONITOR MODE
Distributed request rate246 matches in the last 24 hoursVerify
Credential file probing81 matches in the last 24 hoursBlock
WordPress login abuse39 matches in the last 24 hoursWatch
No hosted traffic changedReview impact →
Start with evidence

See how protection fits your DirectAdmin server before switching it on.

BashEdge begins in monitor mode. It records what each rule would have done against the server's own traffic without blocking visitors. Review the targets, allowlist trusted systems and choose the response for each rule when the evidence is clear.

Watch, verify or block per rule Preserve existing firewall policy Resource limits protect server stability
DirectAdmin security questions

What hosting teams ask about BashEdge.

What does DirectAdmin DDoS protection stop?

BashEdge focuses on application-layer or Layer 7 DDoS attacks that send large volumes of HTTP requests through allowed Web ports. It detects high-rate clients, distributed campaigns, rotating identities and repeated expensive paths, then watches, verifies or blocks the traffic before the Web server performs costly application work.

Does BashEdge replace my DirectAdmin firewall?

No. A network firewall remains responsible for connection policy using sources, ports and protocols. BashEdge preserves existing rules and works alongside the firewall while adding Web request inspection, server-wide rate intelligence and targeted incident controls.

Is BashEdge the same as DirectAdmin ModSecurity?

No. ModSecurity is a rule engine that identifies patterns inside individual Web requests. BashEdge provides its own maintained WAF rules and also connects source behaviour, request rate, visitor verification, firewall controls, login defence and evidence across hosted domains. The products can operate alongside one another.

Can I protect every reseller and user from one installation?

Yes. BashEdge protects the shared server request path, so one installation can cover every hosted user and domain. Threat records still identify the targeted domain so administrators can understand where an attack was directed.

Will BashEdge work with nginx, Apache or LiteSpeed?

BashEdge protects before application processing and is designed for the common Web stacks used on DirectAdmin servers, including nginx, Apache and LiteSpeed-based configurations. The installation detects the server environment and starts in monitor mode.

Will enabling the WAF break customer websites?

Protection does not begin by blocking traffic. Monitor mode records rule matches and the affected domain so the hosting team can review impact, allowlist trusted traffic and activate only the rules it is ready to enforce.

Can I protect only the domain currently under attack?

Yes. Lockdown Mode can verify new visitors for one targeted domain or for every hosted website on the server. It can run for a fixed incident window or remain active until an administrator disables it.

How is BashEdge installed on a DirectAdmin server?

Installation uses one command, requires no reboot and starts in monitor mode. Existing firewall policy remains in place while BashEdge learns from real server traffic.

Keep every DirectAdmin user online during the next request flood.

Install BashEdge in monitor mode, review the evidence from your own server and activate protection when you are ready.

Start free trial