E-commerce Security Audit & Hardening
Budget: $30 – $250 CAD
My online store has recently been flagged for hidden back-door files, and I need a seasoned security professional to give the entire site a clean bill of health. Please perform a full vulnerability assessment, locate and remove every malicious script or file you discover, then harden the platform so the same exploit cannot reappear.
The most business-critical areas are the payment gateway, customer database, and admin panel. I expect each of those surfaces to be stress-tested, patched, and monitored against common threat vectors (SQL injection, XSS, CSRF, file-upload exploits, brute-force logins, etc.).
You are free to use industry-standard tools—from OWASP testing utilities to server-side malware scanners—so long as nothing disrupts live transactions. I can supply temporary admin credentials and schedule maintenance windows to minimise customer impact.
Deliverables
• Detailed security report outlining every vulnerability found and the method used to verify it
• Clean removal (not quarantine) of all back-door or malicious files with a changelog of affected paths
• Implementation and configuration of preventive controls (firewall rules, permission hardening, real-time monitoring, alerting) focused on the payment gateway, customer database and admin panel
• Post-remediation penetration test demonstrating the site is free of the reported issues
• Recommendations for ongoing security best practices and update policies
Once the final penetration test shows zero critical findings and the site runs smoothly for 24 hours, I will consider the project complete.
The most business-critical areas are the payment gateway, customer database, and admin panel. I expect each of those surfaces to be stress-tested, patched, and monitored against common threat vectors (SQL injection, XSS, CSRF, file-upload exploits, brute-force logins, etc.).
You are free to use industry-standard tools—from OWASP testing utilities to server-side malware scanners—so long as nothing disrupts live transactions. I can supply temporary admin credentials and schedule maintenance windows to minimise customer impact.
Deliverables
• Detailed security report outlining every vulnerability found and the method used to verify it
• Clean removal (not quarantine) of all back-door or malicious files with a changelog of affected paths
• Implementation and configuration of preventive controls (firewall rules, permission hardening, real-time monitoring, alerting) focused on the payment gateway, customer database and admin panel
• Post-remediation penetration test demonstrating the site is free of the reported issues
• Recommendations for ongoing security best practices and update policies
Once the final penetration test shows zero critical findings and the site runs smoothly for 24 hours, I will consider the project complete.
Related categories:
PHP
Web Security
MySQL
Internet Security
Penetration Testing
Alerting
Security
Risk Assessment