Patch Compromised Ubuntu VPS Security
Budget: $30 – $250 USD
My provider has suspended my Ubuntu VPS after flagging a hack on the web-server layer (Apache/Nginx, exact stack is in the incident report I will share once we start). At the moment I have zero hardening in place—no firewall rules, no SSL, nothing—so the attacker clearly found an easy way in.
I do have a recent full backup, so you can work safely and roll back if needed. Your mission is to identify the entry point, remove any malicious code or files, close the vulnerability, and leave the server in a state that convinces the host to lift the ban. You are welcome to use tools such as fail2ban, UFW/iptables, ClamAV, rkhunter, ModSecurity, or any other utilities you normally rely on.
Deliverables
• Clean, uncompromised web root and services reinstated
• Detailed hardening steps applied (firewall, SSL/TLS, updated packages, secure SSH settings, etc.)
• Post-cleanup security report I can forward to the hosting abuse team
• Short set of prevention recommendations for me to follow
i have attached the provider abuse report
I will provide root access and the backup archive as soon as we agree to proceed. The job is complete when the host confirms the VPS is safe and re-enables it.
I do have a recent full backup, so you can work safely and roll back if needed. Your mission is to identify the entry point, remove any malicious code or files, close the vulnerability, and leave the server in a state that convinces the host to lift the ban. You are welcome to use tools such as fail2ban, UFW/iptables, ClamAV, rkhunter, ModSecurity, or any other utilities you normally rely on.
Deliverables
• Clean, uncompromised web root and services reinstated
• Detailed hardening steps applied (firewall, SSL/TLS, updated packages, secure SSH settings, etc.)
• Post-cleanup security report I can forward to the hosting abuse team
• Short set of prevention recommendations for me to follow
i have attached the provider abuse report
I will provide root access and the backup archive as soon as we agree to proceed. The job is complete when the host confirms the VPS is safe and re-enables it.