Russian  English  All projects

Repair the site on Drupal, completely reconfigure security and clean up malware



There is a site on Drupal, which must be cleaned of malware, update the kernel according to the instructions
www.drupal.org/ru/docs/us...

and configure security.

RIGHT AWAY:
Drupal 7.69
PHP 5.4.16 (native)
mysql-5.7.27 1 database ~ 250 MB

Heres what you need to do:
– update the version of Drupal as much as possible, but so that neither the existing extensions, nor the design template, nor the admin panel for users fall off on the site (adding materials)
– remove obvious jambs such as a forgotten install file.php in the root
– change the page of the admin panel
– change of the standard admin login (done)
– adding admin partition protection via htaccess
– adding protection of potentially vulnerable partitions via htaccess
– find, describe and eliminate the cause of the appearance of "left" users (appear again, apparently due to the implemented malicious code)
- Removal of the "left" content of these users (now done, but will surely reappear)
– demolition of all "left" extensions and plugins that are not actually applied and do not affect the already placed target materials
– completely close the registration on the portal, especially from the internal pages
– closing from indexing all unnecessary files and directories (i.e. everything except the root of the site and directly published materials)

What else would you recommend.

Perform work that may lead to unavailability of the site,
it is possible only from 22:00 to 07:00 Moscow time, so that visitors to the portal do not stumble upon the technical kitchen.

For the duration of the work, turn on the built-in plug (maintenance mode).

There are also mailboxes on the linked domain, they cannot be "dropped".

I will be able to respond in detail to the responses in the evening.
09.02.2022 23:13



 Answers freelancers