CASE STUDIES

Problems Solved, Outages Avoided, Time Given Back

Real engagements from the last twelve months, anonymised at our clients’ request. Each one shows the value in the terms that matter: hours and days saved, incidents that never became outages, and attack surface that no longer exists.

6 Incidents

Written up in detail below

100k+ IPs

Largest bot flood defeated

Same Day

Typical time to full recovery

0 Rebuilds

Every recovery kept the data

E-COMMERCE · MAGENTO

Botnet Crawling a Retailer Off the Internet

Problem solved · Security improved

The problem

A UK online retailer on Magento was being hammered by more than 100,000 distinct IP addresses crawling every combination of its layered-navigation filters. Each request forced an expensive database query; the store slowed to a crawl and dropped offline at peak times. Blocking IPs one by one was hopeless.

What we did

We put the store behind a Cloudflare WAF rule that challenges suspicious traffic to faceted URLs, added nginx rate-limiting and cheap 429 responses for filter combinations, passed real visitor IPs through to the application, and locked the firewall so the origin server only accepts traffic from Cloudflare.

The outcome

  • Store stable the same day, with no application code changes
  • Bot traffic dropped to a trickle; real customers unaffected
  • Origin server no longer reachable directly from the internet — a permanent security gain
  • Same playbook since applied to two other client stores in under an hour each

MEMBERSHIP PLATFORM · WORDPRESS

Brute-Forced WordPress Site With Rogue Admins and a Webshell

Security improved · Problem solved

The problem

Attackers used the WordPress REST API batch endpoint to brute-force credentials at high speed, created hidden administrator accounts and installed a webshell disguised as a plugin. The site owner only noticed when strange admin users appeared.

What we did

We contained the site, identified and removed four separate backdoors, deleted the rogue accounts, rotated every authentication salt and key, blocked the batch endpoint and XML-RPC at the web server, and preserved a full evidence bundle. We also verified that cloud credentials stored on the server had not been exfiltrated.

The outcome

  • Compromise eradicated the same day with no data loss
  • The entry vector is closed permanently, not just cleaned up
  • Documented incident evidence available for the client’s insurers and records
  • Outstanding credential rotation tracked to completion rather than forgotten

MULTI-TENANT HOSTING · MARIADB

Disk-Full Corruption on a 20-Site Hosting Server

Time saved · Problem solved

The problem

A shared server hosting around twenty client websites ran out of disk space overnight. The database engine wrote a corrupt transaction log and refused to start. Every site on the box went down at once, and the previous provider’s advice was to rebuild from scratch.

What we did

We isolated the corrupt data directory, rebuilt the MariaDB instance cleanly, restored every database from the 01:00 nightly dumps, fixed two applications whose runaway tables had caused the disk fill, and added disk-usage alerting so the same condition pages an engineer at 80% instead of failing at 100%.

The outcome

  • All sites restored the same day — days of rebuild work avoided
  • Maximum data loss limited to that morning’s backup window
  • Root cause fixed, not just the symptom
  • Early-warning monitoring in place across the fleet

MANUFACTURING · MONITORING

Monitoring That Had Been Silently Dead for 40 Days

Problem avoided · Time saved

The problem

A client’s monitoring platform had stopped alerting weeks earlier and nobody noticed — the dashboard simply looked quiet. An automatic security update had left the monitoring service hung on shutdown, and the database start-up job was queued behind it forever.

What we did

We diagnosed the stuck systemd job in minutes, cleared it safely, brought the database and monitoring server back, then reviewed the unattended-upgrade configuration so service restarts cannot deadlock the same way again. We also added an external heartbeat check: something now monitors the monitoring.

The outcome

  • Monitoring restored the same afternoon
  • Six weeks of blind operation ended; no more silent gaps
  • Upgrade process changed so it cannot recur
  • Independent heartbeat means a dead monitor is now itself an alert

PROFESSIONAL SERVICES · NGINX / TLS

Expired SSL Certificate Caused by a Rogue Web Server Process

Problem solved · Problem avoided

The problem

An accounting firm’s website started showing browser security warnings after its certificate expired. Renewals had been failing quietly for three months. The real cause was a second nginx process, spawned by a certificate tool back in April, running outside the service manager and holding the ports.

What we did

We found the orphaned process, retired it, restored nginx under proper systemd control, renewed the certificate and verified the automatic renewal path end to end. Package upgrades that had been silently failing for the same reason were applied at the same time.

The outcome

  • Certificate renewed and warnings gone within the hour
  • Automatic renewals now genuinely automatic and verified
  • Three months of blocked security updates applied
  • Certificate-expiry monitoring added so a failure is caught 14 days early, not on the day

TECHNOLOGY · VIRTUALISATION

Provider Abuse Notice Threatening to Disconnect a Production Hypervisor

Problem avoided · Security improved

The problem

A data-centre provider issued an abuse notice for a production virtualisation host: virtual machines were leaking their own network addresses onto the provider’s uplink, which breaches the hosting terms. The provider gives a short deadline before the server is disconnected — taking a Kubernetes cluster and its workloads with it.

What we did

We redesigned the guest networking from bridged to routed, so only the host’s permitted address ever reaches the uplink, applied it live without rebooting the guests, and confirmed with the provider that the offending traffic had stopped.

The outcome

  • Abuse case closed well inside the deadline; no disconnection
  • Zero downtime for the cluster during the change
  • Network design is now compliant and documented for future hosts

HOW WE WORK

The Pattern Behind Every Case Study

Every one of these follows the same approach, and it is the approach you get as a managed client.

Find the Root Cause

We do not restart things and hope. Each fix above started with understanding exactly why it broke — the stuck job, the rogue process, the filter URLs.

Fix It Properly

Contain first, then eradicate, then close the door. A compromise is not “fixed” until the entry vector is gone and the secrets are rotated.

Make Sure It Cannot Recur

Every incident ends with monitoring, alerting or a process change so the same failure pages an engineer early next time — or never happens at all.

Have a Problem Like One of These?

Whether it is happening right now or you would rather it never does, talk to the engineers who fixed the ones above. Managed clients get us 24×7; everyone else gets a straight answer during business hours.

Phone

07487 759 091
24×7 for managed clients · Mon–Fri 9–6 for new enquiries

WhatsApp

Chat with an engineer on WhatsApp
Send a message, screenshot or error — we reply from the same number

Company

Ur-Sltn Ltd — Registered in England & Wales (07539499)
High Lees Farmhouse, Paddock Wood, Kent TN12 6PT

WhatsApp us