Online store on OpenCart 3. An automated attack is underway: bots are placing fake orders with random data (names, phone numbers, addresses). They operate in a real browser, bypass Cloudflare and CAPTCHA, constantly changing IPs of Ukrainian mobile operators, with a pool of about 2000 IPs. The difficulty is that blocking by IP is not possible, as real clients are using the same addresses. It is necessary to filter out bots without affecting live customers (real orders ~10-20/day, an error in blocking a client is critical). It is also necessary to protect advertising using our API key to block impressions from particularly aggressive IPs. Blocking at the account level. What I expect in the response: How would you approach the task? What detection methods do you see as effective in this case? Do you have experience with similar (anti-fraud, anti-bot, form protection)? Estimation of timelines and costs. Stack: OpenCart, PHP 7.3. Ready to discuss. The budget is arbitrary; I have no idea of the real cost.
Proposals are currently absent
Proposals are currently absent
-
Yuliya Dubina
25 November 2022
https://drive.google.com/drive/folders/1avuppH5bNKO_rTBOgzRH-78litZVwJuv?usp=share_link
Current freelance projects in the category Cybersecurity & Data Protection
Good day. There is a website from 2019. An old website. It's a business card type website + some sections with job vacancies. It's clear that everything there is outdated and so on. We need to understand if we can access the database and whether it's possible to make changes or if it's better to write a new one from scratch. Please write in private messages - we will discuss everything. As for the price - we will agree.
Good day! Our Joomla website has been hacked. Initially, the attackers defaced it (wrote "Hacked by Antonkill"). After attempts to clean it ourselves, the hackers returned and installed a malicious script: now, when accessing the site, a foreign blurry screen with a fake captcha (phishing/redirect) is displayed. The hosting provider constantly sends notifications about infected files.What needs to be done: A complete audit and cleaning of all website files and the database from viruses, shells, phishing scripts, and backdoors. Finding and eliminating the vulnerability that led to the hack (updating Joomla, plugins, closing holes). Checking the database for hidden administrators created by hackers. Setting up basic website protection (configuring .htaccess, restricting folder permissions, installing security components like RSFirewall or equivalents). Removing the site from antivirus/search engine blacklists, if it has been listed.Please contact specialists who have real experience with Joomla security. A guarantee for the work will be required (that the viruses will not return within a few days). Access will be provided via temporary FTP/SSH.