Expert Magento 2 Developer & AWS server specialist needed to find and resolve security loopholes and vulnerabilities for ongoing attacks

Job ID: 38788890

Budget: $30 – $250 AUD

Hi

I need someone who is an expert in security for Magento 2 and AWS. My sites have been hacked numerous times in last 18 months and is getting worse, almost daily! I have had two previous developers continuously remove the malicious code and then literally hours or days later the attackers find another way to get in. At the moment the code is being put into the footer of the sites but it has been on the checkout page previously. The attacks either cause my site/s to go down, run slower or get blocked etc and the cost to remove the code each time and loss of orders as sites recover is becoming crazy and not sustainable. I need to get to the bottom of why it is continuing to happen.

The two developers I have used previously have told me all security patches are up to date (need this confirmed) as I believe there is one recent one which needs installing but don’t believe this is the sole issue of the way the attackers are getting in as it was happening prior to this.

I’m looking for an expert Magento 2 Developer who understands multistore set up (two different front ends and one shared database) and the intricacies which comes with it i.e. one change can impact other store and have huge implications/break the sites. In summary, I have two urls impacted every time the malicious code is added.

We thought eWay (my credit card transaction module) may have been compromised but they (eWay) have confirmed there has been no breaches with their extension and it is safe and believe it could be an issue with Porto theme being compromised? I have been told upgrades to both my Magento 2 and Porto theme would help with the above but I have had these both updated (approx. 4 months ago) and the issues are still happening. The last two weeks they are at the worst they have ever been. I need to know for sure the sites are secure and no more loopholes.

My current version of Magento 2 is 2.4.6
My current version of Porto theme is 4.0.8

My understanding is all modules/extensions have been updated with the upgrades above.

I get notified of the malicious code by Sansec or Netcraft (I can forward some of the emails I have received if need be). As soon as I get the notification from Sansec/Netcraft I have had a developer remove the code as any delay in removing, results in Cloudflare blocking my site or the code brings the site down, makes them slow and then my site rankings are negatively impacted which has a negative impact on sales orders. There has been two malicious codes installed in last 24hrs!!!

The theme for sites is Porto so must have a good understanding of this theme. I have extensions/ modules so developer must understand how these work with theme and how changes can impact multistore set up.

Sites are hosted on AWS so must have a good understanding of AWS and I also use free version of Cloudflare. CSF Firewall has been added to AWS server in last week but malicious code has still been injected since.

I need to find the backdoor used and vulnerabilities found and fixed so I can get back to business and resolve these attacks once and for all.

Important: Please start your reply with the code word 'CHICKEN' so that I know you took the time to read the complete posting instead of just replying to all new submissions as some people do.

Please only bid or make contact if you are 100% confident with Magento 2 and AWS and have experience with the above security issues.

Thank you
Related categories: PHP Linux Web Security Magento Internet Security