Linux & WHMCS Security Audit
Budget: $30 – $250 USD
I need a seasoned penetration tester who knows Linux inside-out and understands WHMCS whmcs.com system at the source-code level to carry out a full security audit on my production server. The sole aim of this engagement is to uncover security vulnerabilities—network-level weaknesses, application flaws, and user-access control issues—before anyone else does.
During the engagement I expect you to combine automated scanning (Nmap, Nessus, OpenVAS, Burp Suite or similar) with manual exploitation techniques so nothing slips through the cracks. That includes probing open ports and firewall rules, reviewing WHMCS hooks and custom modules for common web-app bugs such as SQL injection, XSS and CSRF, and testing privilege-escalation paths that could let an attacker pivot to root or other service accounts. If you spot bad crypto practices or misconfigured file permissions, highlight them too.
Deliverables:
• A concise executive summary plus a detailed technical report that maps every finding to a severity rating (CVSS preferred).
• Proof-of-concept evidence for each critical or high-risk issue.
• Clear, step-by-step remediation guidance for all identified weaknesses.
• One round of re-testing after fixes to confirm the environment is clean.
Acceptance criteria: the report must be reproducible, reference the tools, versions and commands you used, and leave no critical or high-risk items unaddressed after re-test.
If this sounds like your wheelhouse, let’s lock in the scope and timeline so you can get started.
During the engagement I expect you to combine automated scanning (Nmap, Nessus, OpenVAS, Burp Suite or similar) with manual exploitation techniques so nothing slips through the cracks. That includes probing open ports and firewall rules, reviewing WHMCS hooks and custom modules for common web-app bugs such as SQL injection, XSS and CSRF, and testing privilege-escalation paths that could let an attacker pivot to root or other service accounts. If you spot bad crypto practices or misconfigured file permissions, highlight them too.
Deliverables:
• A concise executive summary plus a detailed technical report that maps every finding to a severity rating (CVSS preferred).
• Proof-of-concept evidence for each critical or high-risk issue.
• Clear, step-by-step remediation guidance for all identified weaknesses.
• One round of re-testing after fixes to confirm the environment is clean.
Acceptance criteria: the report must be reproducible, reference the tools, versions and commands you used, and leave no critical or high-risk items unaddressed after re-test.
If this sounds like your wheelhouse, let’s lock in the scope and timeline so you can get started.