Web & Server Security Expert (PHP/Yii2/Nginx/Ubuntu)
Budget: $500 – $1,000 USD
Web & Server Security Expert (PHP/Yii2/Nginx/Ubuntu)
We are urgently seeking an experienced Web & Server Security Expert to help us investigate and resolve a recent security breach. Our project is currently under attack and we need immediate support for analysis, mitigation, and hardening.
Current Situation:
* The project is built using the Yii2 (PHP) framework.
* The website is behind Cloudflare, but the real server IP seems to have been exposed.
* Even after changing servers and getting a new IP, the attacker managed to identify the new IP and resumed the attacks.
* The attacks involve POST-based DDoS requests to random and fake paths (likely fuzzing or brute-force path enumeration).
* The attacker gained access to the admin panel.
* Some internal APIs were identified and have been targeted with massive and repeated requests.
* There may be a backdoor, shell access, or injected code present on the server.
Expected Tasks:
* Deep log analysis (NGINX and PHP) to trace the attack and intrusion paths.
* Full audit of Yii2/PHP codebase to detect and eliminate potential backdoors or malicious scripts.
* Hardening NGINX and completely blocking direct access to the server's IP.
* Implementing methods to hide the real IP behind Cloudflare (advanced techniques).
* Securing APIs with proper authentication, rate limiting, and IP whitelisting.
* Prevent future IP leakage and propose long-term network security solutions.
* Providing a detailed report outlining the vulnerabilities, intrusion path, and all steps taken.
Required Skills:
* Strong expertise in Linux server security (Ubuntu / Debian)
* Advanced knowledge of NGINX configuration and firewall tools (UFW, Fail2Ban, iptables)
* Experience in analyzing NGINX and PHP logs
* Proficient with Yii2 framework and securing PHP applications
* Familiarity with IP leakage techniques behind Cloudflare and how to mitigate them
* Ability to identify and clean malicious or modified scripts
* Knowledge of implementing WAFs, rate limiting, and DDoS mitigation techniques
Work Terms:
* Remote work only
* Project-based engagement with payment negotiable depending on experience and skill
* We will provide:
* Access to logs and source code
* Limited SSH and server access
* Domain and Cloudflare details
If you have hands-on experience dealing with real-world breaches, DDoS attacks, and securing PHP/Yii2 projects — and you're ready to step into a high-priority challenge — we want to hear from you.
Please send your resume or relevant project samples for consideration.
We are urgently seeking an experienced Web & Server Security Expert to help us investigate and resolve a recent security breach. Our project is currently under attack and we need immediate support for analysis, mitigation, and hardening.
Current Situation:
* The project is built using the Yii2 (PHP) framework.
* The website is behind Cloudflare, but the real server IP seems to have been exposed.
* Even after changing servers and getting a new IP, the attacker managed to identify the new IP and resumed the attacks.
* The attacks involve POST-based DDoS requests to random and fake paths (likely fuzzing or brute-force path enumeration).
* The attacker gained access to the admin panel.
* Some internal APIs were identified and have been targeted with massive and repeated requests.
* There may be a backdoor, shell access, or injected code present on the server.
Expected Tasks:
* Deep log analysis (NGINX and PHP) to trace the attack and intrusion paths.
* Full audit of Yii2/PHP codebase to detect and eliminate potential backdoors or malicious scripts.
* Hardening NGINX and completely blocking direct access to the server's IP.
* Implementing methods to hide the real IP behind Cloudflare (advanced techniques).
* Securing APIs with proper authentication, rate limiting, and IP whitelisting.
* Prevent future IP leakage and propose long-term network security solutions.
* Providing a detailed report outlining the vulnerabilities, intrusion path, and all steps taken.
Required Skills:
* Strong expertise in Linux server security (Ubuntu / Debian)
* Advanced knowledge of NGINX configuration and firewall tools (UFW, Fail2Ban, iptables)
* Experience in analyzing NGINX and PHP logs
* Proficient with Yii2 framework and securing PHP applications
* Familiarity with IP leakage techniques behind Cloudflare and how to mitigate them
* Ability to identify and clean malicious or modified scripts
* Knowledge of implementing WAFs, rate limiting, and DDoS mitigation techniques
Work Terms:
* Remote work only
* Project-based engagement with payment negotiable depending on experience and skill
* We will provide:
* Access to logs and source code
* Limited SSH and server access
* Domain and Cloudflare details
If you have hands-on experience dealing with real-world breaches, DDoS attacks, and securing PHP/Yii2 projects — and you're ready to step into a high-priority challenge — we want to hear from you.
Please send your resume or relevant project samples for consideration.
Related categories:
PHP
Linux
Web Security
Nginx
Ubuntu
Internet Security
Penetration Testing
Yii2
Network Security
Cloudflare