Urgent Post-Hack Security Audit

Job ID: 40539218

Budget: $250 – $750 USD

My production servers were recently compromised and I need a thorough security audit carried out right away. The attack vectors appear to have included Denial of Service and Brute Force attempts, so I want those areas examined in depth first.

Scope
• Web application: review code, configuration, authentication flows, and any third-party dependencies for weaknesses a DOS or brute-force bot could exploit.
• Database layer: inspect access controls, query patterns, and any logging gaps that may have allowed the breach to spread beyond the app tier.

Deliverables
1. A clear, prioritised report of all discovered vulnerabilities with evidence (logs, PoC, screenshots) so I can reproduce each issue.
2. Action-oriented recommendations for preventive measures—patches, hardening steps, rate-limiting rules, WAF configurations, or tooling changes—mapped to the findings.
3. A brief follow-up call or document confirming the fixes once I implement them.

Acceptance Criteria
• Every high-severity item shows a repeatable exploit path.
• Recommendations are specific, actionable, and aligned with OWASP and industry best practices.
• All findings are validated against both my web application and the underlying database.

If you have hands-on experience mitigating large-scale DOS events, brute-force defenses (e.g., fail2ban, rate limiting, CAPTCHA), and conducting post-incident audits, I’d like to start immediately.