VPS WordPress Security Cleanup
Budget: $10 – $30 USD
My Server4You VPS has triggered an abuse report and I need a one-time, decisive intervention. The first order of business is malware removal—locating and eradicating any malicious code sitting inside the WordPress installs. While doing so, I also need you to pinpoint which site is behind the current XML-RPC and brute-force login traffic, disable XML-RPC wherever it isn’t explicitly required, and verify no backdoor scripts are left behind.
You will receive root (or sudo) SSH access. Once inside, please:
• Scan every WordPress instance and the underlying file system, remove malware, and patch obvious vulnerabilities.
• Trace the origin of the XML-RPC abuse and stop it without breaking legitimate functionality.
• Review cron jobs, tighten file and directory permissions, check web-server configs (Apache/Nginx) and key services, and apply proven WordPress-hardening steps—fail2ban, mod_security rules, wp-config tweaks, etc.
Deliverables that must be met for the job to be considered complete:
1. A clean, functioning server free of malicious code and rogue processes.
2. XML-RPC disabled site-wide unless explicitly required.
3. A brief remediation report I can forward to Server4You that explains root cause and corrective actions.
This is strictly a single cleanup session; no ongoing maintenance is expected. Only apply if you have demonstrable experience securing VPS environments and hardening WordPress under SSH.
You will receive root (or sudo) SSH access. Once inside, please:
• Scan every WordPress instance and the underlying file system, remove malware, and patch obvious vulnerabilities.
• Trace the origin of the XML-RPC abuse and stop it without breaking legitimate functionality.
• Review cron jobs, tighten file and directory permissions, check web-server configs (Apache/Nginx) and key services, and apply proven WordPress-hardening steps—fail2ban, mod_security rules, wp-config tweaks, etc.
Deliverables that must be met for the job to be considered complete:
1. A clean, functioning server free of malicious code and rogue processes.
2. XML-RPC disabled site-wide unless explicitly required.
3. A brief remediation report I can forward to Server4You that explains root cause and corrective actions.
This is strictly a single cleanup session; no ongoing maintenance is expected. Only apply if you have demonstrable experience securing VPS environments and hardening WordPress under SSH.
Related categories:
Linux
Web Security
WordPress
Apache
Nginx
VPS
Network Security
System Administration