Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Stop Cross-Site Scripting (XSS) With a WAF

This guide explains XSS in simple words and shows how a web application firewall helps block it.

Firewall2 min read6 steps

What is cross-site scripting?

Cross-site scripting is called XSS. An attacker sneaks a small piece of code into your web page, for example through a comment box or a search form. When another visitor opens the page, the code runs in their browser. It can steal their login or send them to a fake page.

Think of someone who leaves a booby-trapped note on your notice board. Anyone who reads it gets tricked.

The bad code is usually JavaScript. It often looks like this:

<script>alert('hacked')</script>

What does a WAF do?

A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads every request to your website. If it sees script tags or other XSS tricks in a form or address, it blocks the request. The bad code never reaches your page.

Most WAFs use ModSecurity with a rule set. The OWASP Core Rule Set has a group of rules just for XSS.

Steps

  1. Turn on your WAF. In cPanel, look in Security for ModSecurity. In Plesk, use Web Application Firewall in Tools & Settings. In WHM, search ModSecurity. Ask Hostvento support if you cannot find it.
  2. Set the engine to On, not just detection.
  3. Make sure a good rule set is installed, such as OWASP.
  4. Check that the XSS rule group is switched on.
  5. Test with your own site, using the example below.
  6. Read the log to see the block was recorded.

Test safely

Type this into your own site's address bar, changing the domain:

https://example.com/?q=<script>alert(1)</script>

A WAF should answer with "403 Forbidden". Test only on your own sites.

Do more than the WAF

A WAF helps, but good site habits matter too.

  • Keep your website software, themes and plugins updated.
  • Remove plugins you do not use.
  • Do not allow visitors to post raw HTML in comments.
  • If you build sites, escape output. This means turning characters like < into safe text so the browser shows them instead of running them.
Tip: A rich editor may post HTML on purpose. The WAF may block it. Add an exception for that one rule on that one page. Do not switch off all XSS rules.

Need help? Open a support ticket.

Quick recap

  • XSS sneaks bad code into pages that other visitors view.
  • A WAF blocks requests that contain such code.
  • Turn the engine On with a rule set like OWASP.
  • Test on your own site and check the log.
  • Keep your software updated.