WordPress & Linux Security Expert Needed
Budget: $100.0
FIXED /
⭐ 4.97 (38)
Canada
network-security, linux-system-administration, internet-security, php
Gewenste kwalificaties
- Ervaring: Gevorderd
Important: Automated malware scanners alone are not sufficient. We are looking for a manual forensic investigation to identify the original attack vector and all persistence mechanisms, ensuring the compromise cannot return. This is the highest priority.
We are looking for an experienced **Linux server security and WordPress malware removal expert** to investigate and completely clean a compromised VPS hosting multiple WordPress websites.
The server has already had passwords changed and basic cleanup performed, however the compromise persists. Malicious code continues to be injected into website files (including `.htaccess`), indicating that the attacker still has a method of regaining access.
We are looking for someone who can identify the root cause, completely eliminate the compromise, and secure the server to prevent future reinfections.
## Environment
* VPS hosted with Namecheap
* Linux server
* Multiple WordPress websites
* SSH access available
* Root access available
## Scope of Work
### 1. Full Security Investigation
* Determine how the server was compromised
* Identify every persistence mechanism used by the attacker
* Review system logs
* Review SSH access
* Review cron jobs
* Check startup scripts and scheduled tasks
* Inspect all websites for backdoors
* Identify vulnerable plugins, themes or outdated software
* Verify there are no malicious Linux users, SSH keys or hidden services
### 2. Website Cleanup
* Remove all malware and malicious code
* Remove web shells and hidden PHP files
* Clean infected `.htaccess` files
* Verify WordPress core integrity
* Verify plugins and themes
* Remove injected JavaScript or redirects
* Ensure every hosted website is clean
### 3. Server Hardening
* Close the security hole that allowed the compromise
* Harden the VPS against future attacks
* Secure SSH
* Review file permissions
* Configure firewall if necessary
* Disable unnecessary services
* Apply security best practices
### 4. Password & Credential Review
Review and advise on any credentials that should be rotated, including:
* Root password
* SSH credentials
* WordPress admin accounts
* Database credentials
* FTP/SFTP accounts
* API keys (if applicable)
### 5. Clean Backup
After confirming the server is completely clean:
* Create a verified clean backup of the entire hosting environment
* Ensure the backup can be restored if needed
### 6. Documentation
Provide a short report including:
* How the compromise occurred
* Files that were infected
* What was removed
* What security improvements were made
* Recommendations to prevent future compromises
## Required Experience
Please apply only if you have experience with:
* Linux server administration
* VPS security
* WordPress malware removal
* WordPress forensics
* Apache/Nginx
* SSH
* Malware persistence
* Root cause analysis
## When Applying
Please include:
* Similar compromised VPS recoveries you have completed
* Your approach to identifying persistent infections
* Your estimated timeline
* Your fixed price or hourly rate
This project requires finding the **root cause** of the compromise—not simply deleting infected files. The work will be considered complete only when the server is fully cleaned, hardened, verified, and a clean backup has been created.
Funds will be released after 7 days of job completion to make sure that the issue does not reoccur
Openen op Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Inloggen