Rebuild Wordpress Site and SuiteCRM Site
Budget / Salary$750–1,500
TypeFreelance project
LocationRemote
Posted1 hour ago
Rebuild hacked Wordpress site using latest versions.
The site is wordpress with a custom portal that connect to ~4 custom SuiteCRM modules for rendering a film archive, festival program etc. from the CRM.
This is a complete rebuild, not trying to fix the existing site.
Brand new wordpress and Suitecrm install on a new ubuntu VM we will supply. Install Wordpress, SuiteCrm, custom modules, copy and clean data etc.
Then I will install the portal/bridge between WordPress and the CRM myself. The csite is silwerskermfees.com
Here is an extract from the AI analysis of the hack.
-----
New machine. Fresh OS image. New SSH keys, new users, new database user and
password, new WordPress salts, new SuiteCRM encryption key. Do not reuse
crontabs, authorized_keys, PHP auto-prepend settings, or the old home directory
from the current host. Treat the current server as untrusted until someone checks
those outside this web root.
WordPress. Install a current WordPress core. Install Avada, Fusion, Slider Revolution,
WooCommerce, ACF Pro, and the other plugins from vendor packages, then update
them. Copy media out of wp-content/uploads only after deleting every .php,
.phtml, .phar, and dot-file .ico. The Avada demo files under uploads/fusion-
builder-avada-pages/ look like real theme demos, but PHP should not be
executable anywhere under uploads. Re-import demos from the theme if you need
them.
Database. Dump it, then audit it before import. Check wp_users and wp_usermeta
for unknown administrators, wp_options for rogue cron and active_plugins,
and post content for injected script. Rotate every password. The database was not
queried in this review, so this part is still open and it matters as much as the files.
SuiteCRM. Reinstall 7.8 from a clean package only as a bridge, then plan an upgrade.
Do not copy include/, modules/, Zend/, cache/, or jssource/ from this tree.
Wipe cache. The business customizations (film_argief, oe_session, faq_faq,
ssfp_people, the tran_* modules) live in custom/, and the shells were dropped
in the same custom/Extension and custom/history trees. Those have to be
diffed against a clean SuiteCRM and reviewed file by file. A wholesale copy of
custom/ will bring the shells along.
The site is wordpress with a custom portal that connect to ~4 custom SuiteCRM modules for rendering a film archive, festival program etc. from the CRM.
This is a complete rebuild, not trying to fix the existing site.
Brand new wordpress and Suitecrm install on a new ubuntu VM we will supply. Install Wordpress, SuiteCrm, custom modules, copy and clean data etc.
Then I will install the portal/bridge between WordPress and the CRM myself. The csite is silwerskermfees.com
Here is an extract from the AI analysis of the hack.
-----
New machine. Fresh OS image. New SSH keys, new users, new database user and
password, new WordPress salts, new SuiteCRM encryption key. Do not reuse
crontabs, authorized_keys, PHP auto-prepend settings, or the old home directory
from the current host. Treat the current server as untrusted until someone checks
those outside this web root.
WordPress. Install a current WordPress core. Install Avada, Fusion, Slider Revolution,
WooCommerce, ACF Pro, and the other plugins from vendor packages, then update
them. Copy media out of wp-content/uploads only after deleting every .php,
.phtml, .phar, and dot-file .ico. The Avada demo files under uploads/fusion-
builder-avada-pages/ look like real theme demos, but PHP should not be
executable anywhere under uploads. Re-import demos from the theme if you need
them.
Database. Dump it, then audit it before import. Check wp_users and wp_usermeta
for unknown administrators, wp_options for rogue cron and active_plugins,
and post content for injected script. Rotate every password. The database was not
queried in this review, so this part is still open and it matters as much as the files.
SuiteCRM. Reinstall 7.8 from a clean package only as a bridge, then plan an upgrade.
Do not copy include/, modules/, Zend/, cache/, or jssource/ from this tree.
Wipe cache. The business customizations (film_argief, oe_session, faq_faq,
ssfp_people, the tran_* modules) live in custom/, and the shells were dropped
in the same custom/Extension and custom/history trees. Those have to be
diffed against a clean SuiteCRM and reviewed file by file. A wholesale copy of
custom/ will bring the shells along.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.