Budget: 4000 UAH Deadline: 5 days
Good day! I have experience in server administration. I would be happy to collaborate with you :)
A specialist is needed for a comprehensive check and adjustment of the server infrastructure in the office. Currently, several virtual machines on Ubuntu are running through Proxmox, with the main database and virtual machines for Laravel websites. There were previous issues with the server because an old version of Laravel was running a miner that overloaded the entire server. Therefore, we need someone who specializes in this segment and can ensure a long-term and secure operation from A to Z.
Regarding the router, mainly we need to configure the firewall, as important documents are stored online on the NAS server in the office, and additionally, we want to switch from rented email to our own.
We tested Mail on Mailcow and quite like it, but I am open to suggestions.
What we have now:
1. Dell R640 NVME Server
2. UniFi Router UDM SE
3. Connection via UniFi Teleport
What needs to be done:
Complete server and network check
Security analysis of the server
Check open ports, access, users
Check network settings
Check the operation of UniFi / Teleport
Identify potential or existing backdoors
Check and configure backups
Check and adjust possible bugs in Proxmox
Configure full autonomy of the server
2. Fixing and configuration
Resolving identified issues
Server protection
Recommendations and implementation of secure settings
3. Email configuration and protection
Complete Mail setup
Protect email from hacking and spam
Configure SPF / DKIM / DMARC
Check account security
Recommendations for safe usage
4. Documentation and instructions
After the work is completed, a checklist is needed:
How to properly manage email
What to pay attention to
Basic security rules
Recommendations for the server and maintenance
Important:
A specialist with experience in UniFi is needed
Possible ongoing collaboration
In your proposal, please indicate immediately:
the price
the completion time
a brief overview of your experience
Payment is negotiable.
Budget: 4000 UAH Deadline: 5 days
Good day! I have experience in server administration. I would be happy to collaborate with you :)
Budget: 10000 UAH Deadline: 5 days
Ready to take on the job, write to me, I will do everything with quality. I have over 14 years of work experience!
Budget: 4000 UAH Deadline: 5 days
Hello. I understand the task: a complete audit and protection of the office's server infrastructure is needed, specifically Proxmox with virtual machines on Ubuntu, the main database and websites on Laravel, and NAS with documents, following the incident where an old Laravel was exploited to deploy a miner. Additionally, I need to configure the firewall, backups, and migrate email to our own Mailcow setup with SPF, DKIM, DMARC, and provide a checklist.
For security, I would approach it systematically: inventory what is running on each virtual machine, check open ports, users and access, search for traces of the miner and possible backdoors, such as suspicious cron jobs, systemd units, autostarts, connections, updates, and hardening of Ubuntu and Proxmox, segregating the network through the firewall to isolate the websites and internal database. I will also separately configure and verify backups, as any protection is incomplete without a working backup.
For email, I would set up Mailcow with correct DNS and SPF, DKIM, DMARC policies to prevent emails from going to spam, plus account protection and basic rules. In the end, I will provide documentation and a checklist for managing email and the server, as requested.
I have experience in auditing and hardening Ubuntu servers, configuring email and DNS policies, working with Docker, and security in production. To better assess the scope: how many virtual machines are currently on Proxmox and is there already a backup we can work from, or are we starting from scratch? I am ready to begin with an audit of the current state of the server and network, followed by addressing the findings and migrating the email.
Budget: 10000 UAH Deadline: 14 days
Good day! I have experience with Proxmos and the technology stack described by you, feel free to reach out - I will help you.
Budget: 10000 UAH Deadline: 20 days
Hello Lyubomyr!
Regarding the websites: If the infection occurs due to an old version of Laravel, it will be very difficult to close the gap to prevent further infections.
The optimal option I would recommend is to update Laravel to the latest version. Because infections can constantly arise from other vulnerabilities, and it turns out that the programmer will be patching holes after the fact.
It is possible to configure a firewall. You can cover the ports that are not in use. Although your server is behind a router, unnecessary ports are not exposed on the internet - the router simply does not allow them through. That's already a plus.
Regarding the infection of the virtual machines themselves - you need to check if there is a backdoor installed on the servers. If the servers are clean, then it will be easier. If the virtual servers are also infected, then the only correct option is to completely reinstall the virtual server. Because fighting a backdoor on an infected server makes no sense. It is unknown what has been changed on the server, which programs have been modified to work with the backdoor, and searching for a needle in a haystack will simply be a waste of time and finances.
What is meant by: checking network settings?
To use your server for mail:
- you need to find out if your dedicated external IP is not on any blacklists
- you need to ask your provider if they can change the PTR record on their server for your mail domain. The domain for mail should already be registered/purchased. For example: mail.example.com
- find out from the provider if they can open mail ports on the edge firewall for you: 25, 110, 143, 465, 587, 993, 995.
- If all points are fulfilled, then you can proceed to the installation and configuration of mail on the server.
In principle, you can also set up Mailcow.
I usually set up Postfix+Dovecot+Rspamd+ClamAV+MariaDB+Roundcube.
Support and monitoring of the email server will be needed constantly. If spam starts being sent from the server, there is a high probability that it will immediately end up on blacklists, and mail will stop reaching some users. Excluding your IP from blacklists is usually possible, but it is not always simple and not always a free procedure.
If you have any questions or if the offer interests you, feel free to reach out.
Budget: 3998 UAH Deadline: 5 days
Good day. I am ready to discuss the details of your task. Write to me. Thank you.
Budget: 15000 UAH Deadline: 3 days
Good day!
I have extensive experience and can conduct a server audit, and I have also worked with UniFi.
Budget: 10000 UAH Deadline: 7 days
Good evening, I will conduct a full audit, create documentation, set up email, I have experience, for discussion please write in private.
Для використання свого сервера для пошти:
- ви повинні з"ясувати, чи ваша виділена зовнішня IP не в блеклистах
- ви повинні дізнатись у провайдера, чи він може змінити PTR-запис у себе на сервері під ваш поштовий домен. Домен для пошти повинен вже бути зареєстрований/куплений. Наприклад: mail.example.com
- дізнатись у провайдера, чи зможе він відкрити поштові порти на граничному фаєрволі для вас 25, 110, 143, 465, 587, 993, 995.
- Якщо всі пункти виконані, тоді можна перейти до встановлення та налаштування пошти на сервері
Впринципі поставити Mailcow можна.
Я зазвичай ставлю Postfix+Dovecot+Rspamd+ClamAV+MariaDB+Roundcube
We are looking for a programmer (IT specialist) for long-term cooperation for a new grocery store. We need assistance with: setting up the cash register program (PRRO/RRO); installing and servicing equipment (computer, receipt printer, barcode scanner, etc.); configuring the accounting program for products and inventory; connecting the terminal (if needed); technical support and assistance in case of problems. We will consider both one-time cooperation at the opening stage and further support for the store. If you provide such services, please write in private messages: what services you offer; work experience; city (preferably the outskirts of Stryi); estimated cost of your services.
It is necessary to transition from the old program 1C "Pharmacy for Ukraine" to BAS with a complete data transfer and launch of the new system into operation. Tasks — analyze the current database of 1C "Pharmacy for Ukraine"; — select and justify the BAS configuration suitable for retail trade, warehouse, procurement, sales, mutual settlements, and financial accounting; — install BAS on work computers or server; — configure users, access rights, stores, warehouses, cash registers, and organizations; — transfer data from the old 1C to BAS; — check the correctness of the transferred data; — configure trading equipment and external services; — conduct a test launch; — eliminate errors identified during testing; — prepare the system for full operation. Data to be transferred — product nomenclature; — categories and groups of products; — barcodes; — purchase and retail prices; — stock balances by warehouses and stores; — contractors; — suppliers; — mutual settlements; — debts and overpayments; — procurement and sales documents; — if possible — the history of product movements and sales. Before starting the transfer, the executor must check the database and inform in writing which data can be transferred completely, partially, or cannot be transferred. Necessary settings — loading bank statements; — working with client-bank; — integration with Checkbox; — configuring cash registers and fiscal receipts; — barcode scanners; — receipt printers; — printing price tags and labels; — product returns; — transfers between stores and warehouses; — inventory; — purchases, sales, and write-offs; — operation of multiple users. Updates and modifications The configuration must have the capability for further updates. All modifications must be made so that they do not disappear after updating BAS. Before making changes, the executor must agree on the implementation method: configuration extension, external processing, or another safe method. Unilateral removal of the configuration from support without agreement is not allowed. Work results — BAS installed and activated; — data from the old 1C transferred; — balances and mutual settlements reconciled; — Checkbox, bank, and trading equipment operational; — procurement, sales, returns, transfers, and inventory can be processed; — receipts, price tags, and labels can be printed; — a backup of the working database created; — a brief instruction on backup and updates provided; — training for responsible employees conducted. The response must indicate — recommended BAS configuration; — experience in transitioning from 1C to BAS; — experience in data transfer from industry configurations; — experience in integration with Checkbox; — method of preserving modifications after updates; — cost of each stage; — execution time; — cost of further support. Payment is preferably staged: database audit, installation, transfer, configuration, testing, and launch.
There is already a KeyCrm system It is necessary To be able to change receipts, editing the document itself To create a reconciliation act with the buyer and supplier To create receipts and invoices from the supplier To make sales And more