Audit and Cleanup of Linux Server (IP blacklisted, suspected compromise)
Budget: €8 – €30 EUR
Details:
https://docs.google.com/document/d/1vmFu3sTakd8QWrXlxclu9SCfO3IFNWj8pG6UOPtFILI/edit?usp=sharing
We urgently need an experienced Linux system administrator / security specialist to investigate and fix issues with one of our servers.
We need a professional to:
Audit the server
Check for compromise (malware, trojans, rootkits, backdoors).
Analyze system and web logs for abnormal activity.
Identify the source of suspicious wp-login.php scanning activity.
Cleanup and fix
Remove any malicious files, processes, or cron jobs.
Update OS and all services to the latest secure versions.
Close/disable unnecessary ports and services.
Reconfigure firewall (iptables / ufw / CSF).
Harden security
Implement fail2ban (or equivalent) to block brute-force attacks.
Secure SSH (disable root login, use key-based authentication, non-standard port).
Reset all system and service passwords.
Set up basic monitoring of logs and system activity.
Report
Provide a short report of findings (evidence of compromise, actions taken).
Recommend best practices for preventing similar incidents in the future.
Draft a short summary for our Abuse Department to confirm remediation steps.
https://docs.google.com/document/d/1vmFu3sTakd8QWrXlxclu9SCfO3IFNWj8pG6UOPtFILI/edit?usp=sharing
We urgently need an experienced Linux system administrator / security specialist to investigate and fix issues with one of our servers.
We need a professional to:
Audit the server
Check for compromise (malware, trojans, rootkits, backdoors).
Analyze system and web logs for abnormal activity.
Identify the source of suspicious wp-login.php scanning activity.
Cleanup and fix
Remove any malicious files, processes, or cron jobs.
Update OS and all services to the latest secure versions.
Close/disable unnecessary ports and services.
Reconfigure firewall (iptables / ufw / CSF).
Harden security
Implement fail2ban (or equivalent) to block brute-force attacks.
Secure SSH (disable root login, use key-based authentication, non-standard port).
Reset all system and service passwords.
Set up basic monitoring of logs and system activity.
Report
Provide a short report of findings (evidence of compromise, actions taken).
Recommend best practices for preventing similar incidents in the future.
Draft a short summary for our Abuse Department to confirm remediation steps.