cPanel mod_evasive & mod_reqtimeout: Mitigating HTTP DoS (2026)

Defend cPanel Apache web servers against Slowloris, Slow POST (R-U-Dead-Yet), and HTTP application Layer-7 DoS attacks. Learn how to configure mod_reqtimeout, tune mod_evasive thresholds, and automate CSF firewall IP blocking in Pakistan.

cPanel mod_evasive & mod_reqtimeout: Mitigating HTTP DoS (2026)

In cybersecurity and web server administration, distributed denial-of-service (DDoS) attacks are often visualized as massive volumetric floods—hundreds of gigabits of UDP and SYN packets saturating physical datacenter uplinks.

However, the most lethal and covert attacks against web hosting servers in Pakistan require virtually zero bandwidth: Low-and-Slow Application Layer (Layer-7) DoS attacks.

Using techniques like Slowloris and Slow POST (R-U-Dead-Yet / RUDY), a single laptop tethered to a residential mobile connection can take an entire multi-core cPanel Apache server offline. The attacker opens hundreds of HTTP connections and deliberately trickles incomplete request headers at a glacial pace (e.g., 1 byte every 15 seconds).

Because the traffic volume is minuscule, standard network firewalls and router rate limits never trigger. Yet, inside Apache, every incoming trickle monopolizes an active worker thread (MaxRequestWorkers). In under 60 seconds, Apache exhausts its process pool, locking up and presenting legitimate visitors with 503 Service Unavailable errors.

To permanently neutralize slow exhaustion attacks and HTTP brute-force floods, system administrators must deploy a two-tier defense: mod_reqtimeout and mod_evasive. In this engineering masterclass, we configure both modules in cPanel/WHM and automate real-time IP blacklisting with CSF Firewall.


🔬 The Physics of Slowloris & Worker Starvation

To understand why Apache is uniquely susceptible to slow attacks, examine how connection handling operates:

STANDARD APACHE MPM (Prefork / Worker / Event):
MaxRequestWorkers = 150 (Total concurrent client slots)

ATTACKER WITH SLOWLORIS (Minimal Bandwidth, Maximum Damage):
Attacker opens 150 TCP connections:
  Connection #1: "GET / HTTP/1.1\r\n" ... (waits 15s) ... "X-Header: foo\r\n" ...
  Connection #2: "GET / HTTP/1.1\r\n" ... (waits 15s) ... "X-Header: bar\r\n" ...
  ...
  Connection #150: Holds last available Apache worker slot!

RESULT:
[ Total Apache Worker Slots: 150 / 150 USED ]
Genuine Pakistani Customer visits https://yourdomain.pk:
Apache cannot allocate a worker thread ──> Connection drops! [503 Service Unavailable]

By holding connection sockets in an incomplete state, the attacker keeps the TCP session alive without completing the HTTP request. Apache waits patiently, assuming the client is merely on a slow mobile connection.


🛡️ Tier 1 Defense: Hardening mod_reqtimeout

The first line of defense is mod_reqtimeout (included natively in Apache 2.4). It enforces a strict mathematical clock on how quickly clients must transmit request headers and bodies:

If a client does not send headers at a minimum transfer rate, Apache forcefully severs the TCP connection with an HTTP 408 Request Timeout, freeing the worker slot.

Step-by-Step WHM Configuration:

  1. Log into WHM (WebHost Manager) as root.
  2. Navigate to Service Configuration > Apache Configuration > Include Editor.
  3. Under Pre Main Include, select your active Apache version (e.g., All Versions).
  4. Paste the following production-hardened directives:
<IfModule mod_reqtimeout.c>
    # 1. Enforce Header Timeout:
    # Client has 20 seconds to begin. For every 500 bytes sent, add 1 second (up to max 40 seconds).
    RequestReadTimeout header=20-40,MinRate=500

    # 2. Enforce Request Body Timeout (Protects against Slow POST / RUDY):
    # Client has 20 seconds to begin sending POST payload; requires minimum 500 bytes/sec.
    RequestReadTimeout body=20,MinRate=500
</IfModule>
  1. Click Update and restart Apache.

With this rule active, Slowloris bots trickling 1 byte every 15 seconds violate MinRate=500 and are severed in under 20 seconds!


⚡ Tier 2 Defense: Installing & Tuning mod_evasive

While mod_reqtimeout destroys slow attacks, mod_evasive defends against rapid HTTP application floods (brute-force page scraping, login flooding, and Layer-7 DDoS).

mod_evasive maintains an in-memory hash table of client IP addresses. If an IP requests the same URI or exceeds site-wide threshold limits within a 1-second window, mod_evasive returns HTTP 403 Forbidden and temporarily blacklists the IP.

Step 1: Install mod_evasive via EasyApache 4

In SSH as root (or via WHM EasyApache 4 GUI):

# On AlmaLinux / Rocky Linux / CloudLinux:
dnf install -y ea-apache24-mod_evasive

Step 2: Configure Production Thresholds

Edit the mod_evasive configuration file:

nano /etc/apache2/conf.d/300-mod_evasive.conf

Insert the battle-tested configuration:

<IfModule mod_evasive24.c>
    # Hash table size for IP tracking (prime number recommended)
    DOSHashTableSize    3097

    # Max requests for the SAME page per interval (1 second)
    DOSPageCount        5

    # Max total requests across the ENTIRE site per interval (1 second)
    DOSSiteCount        100

    # Time interval in seconds for page and site counts
    DOSPageInterval     1
    DOSSiteInterval     1

    # How long an offending IP remains blacklisted (in seconds)
    DOSBlockingPeriod   60

    # Directory where mod_evasive stores temporary IP lock files
    DOSLogDir           "/var/log/mod_evasive"

    # Automated CSF Firewall Ban Integration!
    DOSSystemCommand    "/usr/sbin/csf -d %s 'Blocked by mod_evasive Layer-7 DoS'"
</IfModule>

Ensure the lock directory exists with proper permissions:

mkdir -p /var/log/mod_evasive
chown -R nobody:nobody /var/log/mod_evasive
chmod 1777 /var/log/mod_evasive

Restart Apache:

systemctl restart httpd

🚀 The Power Move: Integrating with CSF Firewall

Notice the directive:

DOSSystemCommand "/usr/sbin/csf -d %s 'Blocked by mod_evasive Layer-7 DoS'"

When an attacking IP breaches DOSPageCount or DOSSiteCount, mod_evasive does not just return a 403 header—it immediately invokes ConfigServer Security & Firewall (CSF)!

CSF permanently inserts the attacking IP into the Linux kernel iptables / nftables drop list. The attacker’s packets are dropped at the network interface layer, consuming zero CPU cycles in Apache!


🧪 Testing Your Layer-7 Defense

Verify that mod_evasive is actively guarding your server using a quick bash loop from a remote terminal:

for i in {1..20}; do curl -s -o /dev/null -w "%{http_code}\n" https://yourdomain.pk/; done

Output:

200
200
200
200
200
403    <--- mod_evasive triggers!
403
403

Check the log to confirm the automated block:

tail -n 10 /var/log/messages | grep evasive

🏆 Enterprise DDoS Mitigation on Nextgen Cloud Infrastructure

While software-level Apache hardening protects against application layer exhaustion, large-scale volumetric attacks require multi-gigabit upstream scrubbing:

  • Deploy mission-critical portals on Nextgen Cloud VPS in Pakistan featuring dedicated KVM hypervisors, automated CSF firewall rules, and low-latency PkIX peering.
  • For financial institutions, e-commerce conglomerates, and organizations needing dedicated bare-metal server resources, automated hardware diagnostics, and 99.99% uptime SLAs, deploy on Nextgen bare-metal Dedicated Servers in Pakistan and international Dedicated Servers with carrier-grade Layer-3/4 and Layer-7 DDoS mitigation.


🛡️ Hardened Web Server Security · 99.99% SLA

Deploy on DDoS-Protected Cloud Infrastructure in Pakistan

Protect your web applications from Slowloris attacks, Layer-7 HTTP floods, and malicious scraping. Nextgen delivers developer-first Cloud VPS and Bare-Metal Dedicated Servers pre-hardened with advanced Apache, Nginx, and CSF firewall defenses.

Explore Pakistan Cloud VPS → View Dedicated Servers