Magento 2 upgrade and resolve security loopholes and vulnerabilities for ongoing attacks (Expert Magento 2 Developer & AWS server specialist needed)
Budget: $30 – $250 AUD
This is a reposting of an existing open project with more detail added so this is now a new project as more involved so please bid on this if you are capable to do the works.
I’m looking for an expert Magento 2 developer who understands multistore set up (two different front ends and one shared database) and the intricacies which comes with it i.e. one change can impact other store and have huge implications/break the sites.
The theme for sites is Porto so must have an understanding of this theme. I have extensions/ modules so developer must understand how these work with theme and how updates can impact multistore set up. Porto version 4.08
Current Magento version 2.4.6, needs upgrading to latest stable Magento 2 version which I believe is 2.4.7 p3 or 2.4.8 (currently beta)
Porto theme I believe is already at latest stable version so shouldn’t need updating
The reason for upgrades is because of ongoing security issues.
I need someone who is an expert in security for Magento 2 and AWS. My sites have been hacked numerous times in last 18 months and is getting worse, almost daily! I have had two previous developers continuously remove the malicious code and then literally hours or days later the attackers find another way to get in. At the moment the code is being put into the footer of the sites but it has been on the checkout page previously. The attacks either cause my site/s to go down, run slower or get blocked etc and the cost to remove the code each time and loss of orders as sites recover is becoming crazy and not sustainable. I need to get to the bottom of why it is continuing to happen.
The two developers I have used previously have told me all security patches are up to date (need this confirmed) as I believe there is one recent one which needs installing but don’t believe this is the sole issue of the way the attackers are getting in as it was happening prior to this. My understanding is upgrading to latest version should solve any patch issues.
Due to multistore set up (one shared database, two front ends) I have two URLs impacted every time the malicious code is added.
We thought eWay (my credit card transaction module) may have been compromised but they (eWay) have confirmed there has been no breaches with their extension and it is safe and believe it could be an issue with Porto theme being compromised? I have been told upgrades to both my Magento 2 and Porto theme would help with the above but I have had these both updated (approx. 6 months ago) and the issues are still happening. The last two weeks they are at the worst they have ever been. I need to know for sure the sites are secure and no more loopholes.
My current version of Magento 2 is 2.4.6
My current version of Porto theme is 4.0.8
My understanding is all modules/extensions have been updated with the upgrades above.
I get notified of the malicious code by Sansec or Netcraft (I can forward some of the emails I have received if need be). As soon as I get the notification from Sansec/Netcraft I have had a developer remove the code as any delay in removing, results in Cloudflare blocking my site or the code brings the site down, makes them slow and then my site rankings are negatively impacted which has a negative impact on sales orders. There has been four malicious codes injected in last 24hrs!!!
Sites are hosted on AWS so must have a good understanding of AWS and I also use free version of Cloudflare. CSF Firewall has been added to AWS server in last week but malicious code has still been injected since.
I need to find the backdoor used and vulnerabilities found and fixed so I can get back to business and resolve these attacks once and for all.
Important: Please start your reply with the code word 'FROG' so that I know you took the time to read the complete posting instead of just replying to all new submissions as some people do.
Please only bid or make contact if you are 100% confident with Magento 2 and AWS and have experience with upgrades and the above security issues.
Thank you
I’m looking for an expert Magento 2 developer who understands multistore set up (two different front ends and one shared database) and the intricacies which comes with it i.e. one change can impact other store and have huge implications/break the sites.
The theme for sites is Porto so must have an understanding of this theme. I have extensions/ modules so developer must understand how these work with theme and how updates can impact multistore set up. Porto version 4.08
Current Magento version 2.4.6, needs upgrading to latest stable Magento 2 version which I believe is 2.4.7 p3 or 2.4.8 (currently beta)
Porto theme I believe is already at latest stable version so shouldn’t need updating
The reason for upgrades is because of ongoing security issues.
I need someone who is an expert in security for Magento 2 and AWS. My sites have been hacked numerous times in last 18 months and is getting worse, almost daily! I have had two previous developers continuously remove the malicious code and then literally hours or days later the attackers find another way to get in. At the moment the code is being put into the footer of the sites but it has been on the checkout page previously. The attacks either cause my site/s to go down, run slower or get blocked etc and the cost to remove the code each time and loss of orders as sites recover is becoming crazy and not sustainable. I need to get to the bottom of why it is continuing to happen.
The two developers I have used previously have told me all security patches are up to date (need this confirmed) as I believe there is one recent one which needs installing but don’t believe this is the sole issue of the way the attackers are getting in as it was happening prior to this. My understanding is upgrading to latest version should solve any patch issues.
Due to multistore set up (one shared database, two front ends) I have two URLs impacted every time the malicious code is added.
We thought eWay (my credit card transaction module) may have been compromised but they (eWay) have confirmed there has been no breaches with their extension and it is safe and believe it could be an issue with Porto theme being compromised? I have been told upgrades to both my Magento 2 and Porto theme would help with the above but I have had these both updated (approx. 6 months ago) and the issues are still happening. The last two weeks they are at the worst they have ever been. I need to know for sure the sites are secure and no more loopholes.
My current version of Magento 2 is 2.4.6
My current version of Porto theme is 4.0.8
My understanding is all modules/extensions have been updated with the upgrades above.
I get notified of the malicious code by Sansec or Netcraft (I can forward some of the emails I have received if need be). As soon as I get the notification from Sansec/Netcraft I have had a developer remove the code as any delay in removing, results in Cloudflare blocking my site or the code brings the site down, makes them slow and then my site rankings are negatively impacted which has a negative impact on sales orders. There has been four malicious codes injected in last 24hrs!!!
Sites are hosted on AWS so must have a good understanding of AWS and I also use free version of Cloudflare. CSF Firewall has been added to AWS server in last week but malicious code has still been injected since.
I need to find the backdoor used and vulnerabilities found and fixed so I can get back to business and resolve these attacks once and for all.
Important: Please start your reply with the code word 'FROG' so that I know you took the time to read the complete posting instead of just replying to all new submissions as some people do.
Please only bid or make contact if you are 100% confident with Magento 2 and AWS and have experience with upgrades and the above security issues.
Thank you