Classic ASP Spam Injection Cleanup
Budget: ₹1,500 – ₹12,500 INR
My Classic ASP site was recently overrun by a black-hat SEO attack that injected gambling-related links into pages crawled by Google. Since then I’ve noticed a dip in performance, repeated security warnings, and spam URLs appearing in Search Console. I can give you full server access, including IIS and database credentials, plus the security logs and scans already generated by our endpoint software.
What I need from you is a thorough forensic sweep to pinpoint every entry point—whether that’s a compromised .asp file, a rogue include, or a polluted database field—and then clean it without breaking the legitimate codebase or content.
Deliverables
• Complete scan of site files, MSSQL/Access tables and IIS logs
• Written report listing each malicious snippet or payload and the path/table where it lived
• Safe removal of the spam content and any back-doors, followed by a second scan proving it’s been eradicated
• Hardening advice (file permissions, patch levels, input-sanitisation, Web.Config/IIS tweaks) so the site remains secure after we sign off
Acceptance criteria
1. Google Search Console fetch renders clean pages with no gambling links.
2. No suspicious outbound requests in a 48-hour monitoring window.
3. Your report documents both the root cause and every change made.
If you have solid Classic ASP experience, comfort with manual code review, and know your way around security tools like Sucuri, VirusTotal, or custom PowerShell scripts, let’s get this fixed quickly.
What I need from you is a thorough forensic sweep to pinpoint every entry point—whether that’s a compromised .asp file, a rogue include, or a polluted database field—and then clean it without breaking the legitimate codebase or content.
Deliverables
• Complete scan of site files, MSSQL/Access tables and IIS logs
• Written report listing each malicious snippet or payload and the path/table where it lived
• Safe removal of the spam content and any back-doors, followed by a second scan proving it’s been eradicated
• Hardening advice (file permissions, patch levels, input-sanitisation, Web.Config/IIS tweaks) so the site remains secure after we sign off
Acceptance criteria
1. Google Search Console fetch renders clean pages with no gambling links.
2. No suspicious outbound requests in a 48-hour monitoring window.
3. Your report documents both the root cause and every change made.
If you have solid Classic ASP experience, comfort with manual code review, and know your way around security tools like Sucuri, VirusTotal, or custom PowerShell scripts, let’s get this fixed quickly.