CASE STUDIES
Problems Solved, Outages Avoided, Time Given Back
6 Incidents
Written up in detail below
100k+ IPs
Largest bot flood defeated
Same Day
Typical time to full recovery
0 Rebuilds
Every recovery kept the data
E-COMMERCE · MAGENTO
Botnet Crawling a Retailer Off the Internet
Problem solved · Security improved
The problem
A UK online retailer on Magento was being hammered by more than 100,000 distinct IP addresses crawling every combination of its layered-navigation filters. Each request forced an expensive database query; the store slowed to a crawl and dropped offline at peak times. Blocking IPs one by one was hopeless.
What we did
We put the store behind a Cloudflare WAF rule that challenges suspicious traffic to faceted URLs, added nginx rate-limiting and cheap 429 responses for filter combinations, passed real visitor IPs through to the application, and locked the firewall so the origin server only accepts traffic from Cloudflare.
The outcome
- Store stable the same day, with no application code changes
- Bot traffic dropped to a trickle; real customers unaffected
- Origin server no longer reachable directly from the internet — a permanent security gain
- Same playbook since applied to two other client stores in under an hour each
MEMBERSHIP PLATFORM · WORDPRESS
Brute-Forced WordPress Site With Rogue Admins and a Webshell
Security improved · Problem solved
The problem
Attackers used the WordPress REST API batch endpoint to brute-force credentials at high speed, created hidden administrator accounts and installed a webshell disguised as a plugin. The site owner only noticed when strange admin users appeared.
What we did
We contained the site, identified and removed four separate backdoors, deleted the rogue accounts, rotated every authentication salt and key, blocked the batch endpoint and XML-RPC at the web server, and preserved a full evidence bundle. We also verified that cloud credentials stored on the server had not been exfiltrated.
The outcome
- Compromise eradicated the same day with no data loss
- The entry vector is closed permanently, not just cleaned up
- Documented incident evidence available for the client’s insurers and records
- Outstanding credential rotation tracked to completion rather than forgotten
MULTI-TENANT HOSTING · MARIADB
Disk-Full Corruption on a 20-Site Hosting Server
Time saved · Problem solved
The problem
A shared server hosting around twenty client websites ran out of disk space overnight. The database engine wrote a corrupt transaction log and refused to start. Every site on the box went down at once, and the previous provider’s advice was to rebuild from scratch.
What we did
We isolated the corrupt data directory, rebuilt the MariaDB instance cleanly, restored every database from the 01:00 nightly dumps, fixed two applications whose runaway tables had caused the disk fill, and added disk-usage alerting so the same condition pages an engineer at 80% instead of failing at 100%.
The outcome
- All sites restored the same day — days of rebuild work avoided
- Maximum data loss limited to that morning’s backup window
- Root cause fixed, not just the symptom
- Early-warning monitoring in place across the fleet
MANUFACTURING · MONITORING
Monitoring That Had Been Silently Dead for 40 Days
Problem avoided · Time saved
The problem
A client’s monitoring platform had stopped alerting weeks earlier and nobody noticed — the dashboard simply looked quiet. An automatic security update had left the monitoring service hung on shutdown, and the database start-up job was queued behind it forever.
What we did
We diagnosed the stuck systemd job in minutes, cleared it safely, brought the database and monitoring server back, then reviewed the unattended-upgrade configuration so service restarts cannot deadlock the same way again. We also added an external heartbeat check: something now monitors the monitoring.
The outcome
- Monitoring restored the same afternoon
- Six weeks of blind operation ended; no more silent gaps
- Upgrade process changed so it cannot recur
- Independent heartbeat means a dead monitor is now itself an alert
PROFESSIONAL SERVICES · NGINX / TLS
Expired SSL Certificate Caused by a Rogue Web Server Process
Problem solved · Problem avoided
The problem
An accounting firm’s website started showing browser security warnings after its certificate expired. Renewals had been failing quietly for three months. The real cause was a second nginx process, spawned by a certificate tool back in April, running outside the service manager and holding the ports.
What we did
We found the orphaned process, retired it, restored nginx under proper systemd control, renewed the certificate and verified the automatic renewal path end to end. Package upgrades that had been silently failing for the same reason were applied at the same time.
The outcome
- Certificate renewed and warnings gone within the hour
- Automatic renewals now genuinely automatic and verified
- Three months of blocked security updates applied
- Certificate-expiry monitoring added so a failure is caught 14 days early, not on the day
TECHNOLOGY · VIRTUALISATION
Provider Abuse Notice Threatening to Disconnect a Production Hypervisor
Problem avoided · Security improved
The problem
A data-centre provider issued an abuse notice for a production virtualisation host: virtual machines were leaking their own network addresses onto the provider’s uplink, which breaches the hosting terms. The provider gives a short deadline before the server is disconnected — taking a Kubernetes cluster and its workloads with it.
What we did
We redesigned the guest networking from bridged to routed, so only the host’s permitted address ever reaches the uplink, applied it live without rebooting the guests, and confirmed with the provider that the offending traffic had stopped.
The outcome
- Abuse case closed well inside the deadline; no disconnection
- Zero downtime for the cluster during the change
- Network design is now compliant and documented for future hosts
HOW WE WORK
The Pattern Behind Every Case Study
Find the Root Cause
We do not restart things and hope. Each fix above started with understanding exactly why it broke — the stuck job, the rogue process, the filter URLs.
Fix It Properly
Contain first, then eradicate, then close the door. A compromise is not “fixed” until the entry vector is gone and the secrets are rotated.
Make Sure It Cannot Recur
Every incident ends with monitoring, alerting or a process change so the same failure pages an engineer early next time — or never happens at all.
Have a Problem Like One of These?
Phone
07487 759 091
24×7 for managed clients · Mon–Fri 9–6 for new enquiries
Chat with an engineer on WhatsApp
Send a message, screenshot or error — we reply from the same number
Company
Ur-Sltn Ltd — Registered in England & Wales (07539499)
High Lees Farmhouse, Paddock Wood, Kent TN12 6PT