← Back to Services ⌂ Home

Server Access Setup

How to grant secure SSH access for malware investigation and cleanup

My SSH Public Key

To investigate and clean your server, I need SSH access. Add the following public key to the server. This only grants access to whoever holds the matching private key — which is only me.

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMupKArYDMiB/rLHswxMkJchL8NoJVFXf6qlc6KCXCuK kbourdakos@remediation

This key is rotated every six months for security. The key shown above is always the current one. If you have an older key on file, please replace it with this one.

How to Add the Key

Choose the method that matches your hosting environment:

cPanel / WHM

  1. Log in to cPanel
  2. Go to Security → SSH Access → Manage SSH Keys
  3. Click Import Key
  4. Leave the key name as default, paste the public key into the Public Key field
  5. Click Import, then go back and click Manage → Authorize

For root access (WHM): navigate to WHM → Security Center → Manage root's SSH Keys

Plesk

  1. Log in to Plesk as admin
  2. Go to Tools & Settings → SSH Keys (under Security)
  3. Click Add Key
  4. Paste the public key into the Key content field
  5. Click Add

For subscription-level access: Domains → [domain] → SSH Access

DirectAdmin

  1. Log in to DirectAdmin as admin
  2. Go to SSH Keys (under Account Manager or Admin Tools)
  3. Click Create Key or Paste Key
  4. Paste the public key and save

Manual (SSH Command Line)

If you have SSH access to the server, run the following command as the user I need to connect as (typically root):

mkdir -p ~/.ssh && chmod 700 ~/.ssh && echo "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMupKArYDMiB/rLHswxMkJchL8NoJVFXf6qlc6KCXCuK kbourdakos@remediation" >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys

Where I Connect From

All SSH connections originate exclusively from my dedicated jump server. You can whitelist this host in your firewall to restrict access to only my infrastructure:

Jump Server

Hostname: baremetal.kbourdakos.gr

IPv4: 147.135.213.177

IPv6: 2001:41d0:303:6fb1::1

This is a dedicated bare-metal server under my direct control — not shared hosting, not a cloud instance. All connections are logged and auditable.

Optional but recommended: Configure your firewall to allow SSH from 147.135.213.177 and 2001:41d0:303:6fb1::1 only during the engagement period. Security is my first priority.

Custom SSH Port?

If your server runs SSH on a port other than 22, please let me know the port number when granting access. If you've configured a firewall whitelist for my IP, make sure it covers your custom port, not just port 22.

What Access I Need

What I Will and Won't Do

Security Guarantees

After the Job

Once the cleanup is complete and you've received the report:

  1. Remove my SSH key from the server using the same panel where you added it
  2. I'll confirm removal is done on my end as well
  3. No persistent access is retained — the key only works while it's in your authorized_keys

If we work together regularly, you can keep the key in place and revoke it anytime. You're always in control.

Alternative: Share Credentials via Vault

If adding an SSH key isn't practical for your setup, you can securely share your server credentials through my self-hosted Vault instead:

How It Works

  1. I'll send you a secure link via vault.kbourdakos.gr
  2. You fill in your server details (IP, SSH port, username, password or key)
  3. The data is end-to-end encrypted and only accessible by me
  4. No credentials are sent over email or chat in plain text

Vault is hosted on my own dedicated infrastructure — no third-party services involved.

Questions?

If you're unsure about any step or want to discuss access scope before granting it, get in touch and we'll figure it out together.