Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

AvaHosting suspended my vps

24

Comments

  • AvaHostingAvaHosting Member, Patron Provider

    Hi, dear @kv1108

    First of all how dramatically you represent the issue, in the ticket it was specified that this was an DoS attempt, not DDoS, you better know the difference

    1. Your VPS is not a installed with Windows

    2. there were 10-12 req/seconds whith higher peaks, no windows 10 will determine whether the computer is connected to the Internet. in such a manner

    a small snippet

    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:15 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:44 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:46 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:15 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:16 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:16 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:46 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:47 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:47 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:48 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:48 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:49 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:11 +0200] "POST /v2/track HTTP/1.0" 404 233703 "-" "-"
    217.xxx.xx.x - - [13/Dec/2024:08:08:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:18 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:18 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:19 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:19 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:20 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:48 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:49 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:49 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:50 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:51 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:52 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:19 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:20 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:21 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:21 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:22 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:23 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:51 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:52 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:52 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:53 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:53 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:54 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:23 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:23 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:24 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:24 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:25 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:25 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:54 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:55 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:55 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:56 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:56 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    
    1. according to https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/internet-explorer-edge-open-connect-corporate-public-network

    Windows 10 or later versions:

    NCSI sends a DNS request to resolve the address of the www.msftconnecttest.com FQDN.

    If NCSI receives a valid response from a DNS server, NCSI sends a plain HTTP GET request to http://www.msftconnecttest.com/connecttest.txt.

    nslookup for the www.msftconnecttest.com on your VPS return completly different addresses but no 176.xxx.x.xxx and it will never will return this address
    https://i.imgur.com/o9ZBIFt.png

    Also the monthly service was suspended, it wasn't VPS Nano. Also you are "old" customer. You didn't used any BF Promotion.

    Kind Regards,
    Ava.Hosting

  • @AvaHosting said:
    1. Your VPS is not a installed with Windows

    He said he uses it as a VPN. What makes you think that there aren't any Windows machines connected to this VPN?

    1. there were 10-12 req/seconds whith higher peaks, no windows 10 will determine whether the computer is connected to the Internet. in such a manner

    You concluded that this is a dos attack based on 10-12 requests in a second.

  • Microsoft.com really sent a DoS abuse report for 10 req per second to that URL?

  • @AvaHosting said:
    @kv1108 @ILLKX Hello, can you share your tickets IDs?

    tid=459106

    @AvaHosting said:
    Hi, dear @kv1108

    First of all how dramatically you represent the issue, in the ticket it was specified that this was an DoS attempt, not DDoS, you better know the difference

    1. Your VPS is not a installed with Windows

    2. there were 10-12 req/seconds whith higher peaks, no windows 10 will determine whether the computer is connected to the Internet. in such a manner

    a small snippet

    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:14 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:15 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:44 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:45 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:06:46 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:15 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:16 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:16 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:46 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:47 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:47 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:48 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:48 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:07:49 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:11 +0200] "POST /v2/track HTTP/1.0" 404 233703 "-" "-"
    217.xxx.xx.x - - [13/Dec/2024:08:08:17 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:18 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:18 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:19 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:19 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:20 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:48 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:49 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:49 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:50 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:51 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:08:52 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:19 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:20 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:21 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:21 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:22 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:23 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:51 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:52 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:52 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:53 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:53 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:09:54 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:23 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:23 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:24 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:24 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:25 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:25 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:54 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:55 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:55 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:56 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    217.xxx.xx.x - - [13/Dec/2024:08:10:56 +0200] "GET /connecttest.txt HTTP/1.1" 301 189 "-" "Microsoft NCSI"
    
    1. according to https://learn.microsoft.com/en-us/troubleshoot/windows-client/networking/internet-explorer-edge-open-connect-corporate-public-network

    Windows 10 or later versions:

    NCSI sends a DNS request to resolve the address of the www.msftconnecttest.com FQDN.

    If NCSI receives a valid response from a DNS server, NCSI sends a plain HTTP GET request to http://www.msftconnecttest.com/connecttest.txt.

    nslookup for the www.msftconnecttest.com on your VPS return completly different addresses but no 176.xxx.x.xxx and it will never will return this address
    https://i.imgur.com/o9ZBIFt.png

    Also the monthly service was suspended, it wasn't VPS Nano. Also you are "old" customer. You didn't used any BF Promotion.

    Kind Regards,
    Ava.Hosting

    I guess you are looking at my ticket, not kv1108s'.

    1. Do you mind to share the abuse report from Microsoft?

    1. I don't think a DoS attempt would be less than 20 requests a second for just a static file.
    2. I'm using your VPS as a VPN gateway, which is allowed, according to your LET post and your website.
    3. I'm using 1.1.1.1 DNS. Do you mean that my VPS sent thousands of "GET /connecttest.txt" requests to your mail host (176.xxx.xxx.xxx) instead of Microsoft or Akamai CDN edge server? If so, is it possible that you are hijacking all your customers' UDP53 DNS request and wrongly configured your DNS server that it returned your mail host IP (176.xxx.xxx.xxx)? After all, you have some kind of DPI firewall, which makes it possible to hijack UDP53 traffic and you are logging your customers' plain HTTP requests.
    Thanked by 1tentor
  • @AvaHosting said:
    nslookup for the www.msftconnecttest.com on your VPS return completly different addresses but no 176.xxx.x.xxx and it will never will return this address
    https://i.imgur.com/o9ZBIFt.png

    www.msftconnecttest.com is GeoDNSed so resolved IP addresses will be defferent by region.

    BTW

    % host ava.hosting
    ava.hosting has address 176.123.0.130
    ava.hosting mail is handled by 10 mail.ava.hosting.
    
  • NebesNebes Member
    edited December 2024

    Let me guess, the cost of the problem is ten dollars - thankfully it wasn't thousands. Put them on your own blacklist. Thanks for sharing. I have a Nano and will not renew for sure.

  • BTW

    $ host www.msftconnecttest.com.ava.hosting
    www.msftconnecttest.com.ava.hosting has address 176.123.0.130
    

    (so probably the client just thinks it is now in the ava.hosting domain and automatically appends that to DNS queries, and then the web server there responds with a redirect and the client just follows that redirect a few times)

  • ping this.sucks.ava.hosting
    
    Pinging this.sucks.ava.hosting [176.123.0.130] with 32 bytes of data:
    Reply from 176.123.0.130: bytes=32 time=59ms TTL=56
    Reply from 176.123.0.130: bytes=32 time=60ms TTL=56
    Reply from 176.123.0.130: bytes=32 time=60ms TTL=56
    Reply from 176.123.0.130: bytes=32 time=61ms TTL=56
    
    Ping statistics for 176.123.0.130:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 59ms, Maximum = 61ms, Average = 60ms
    

    Wildcard DNS records rocks! :D

  • I just cannot believe Microsoft actually sent out an abuse report.
    What about my institute that has like thousands of windows pcs?

  • AvaHostingAvaHosting Member, Patron Provider

    @ILLKX @kv1108

    TL;DR: We have been reactivated the services.

    Hi,

    @TheOnlyDK
    "He said he uses it as a VPN. What makes you think that there aren't any Windows machines connected to this VPN?""

    -You're right, well, even though this isn't a normal request rate, which may suggest that the requests are artificial

    "You concluded that this is a dos attack based on 10-12 requests in a second.""
    It was said DoS attempt, there are cases than a few request per second on application vulnerability is enough to overload a server, in this case we can assume that is searching for such one, evenmore the resolver will not return 176.123.0.130 for the www.msftconnecttest.com, until the customer don't have a plausible explanation of such actions we reserve the right to suspend it.


    for @ILLKX
    "Do you mind to share the abuse report from Microsoft?"

    -It was a misunderstanding, the reply was intended to other ticket.

    "I don't think a DoS attempt would be less than 20 requests a second for just a static file."
    explained above about this

    "I'm using 1.1.1.1 DNS. Do you mean that my VPS sent thousands of "GET /connecttest.txt" requests to your mail host (176.xxx.xxx.xxx) instead of Microsoft or Akamai CDN edge server?"

    -As we have shown earlier, on your VPS is set on google DNS, nonetheless, on your local machine it can be Cloudflare and any other, doesn't matter, if you explicitly will set in hosts file the name for www.msftconnecttest.com to 176.123.0.130

    "If so, is it possible that you are hijacking all your customers' UDP53 DNS request and wrongly configured your DNS server that it returned your mail host IP (176.xxx.xxx.xxx)? After all, you have some kind of DPI firewall, which makes it possible to hijack UDP53 traffic and you are logging your customers' plain HTTP requests."

    • we are not doing any of this, you can implement DoT and DoH and check this

    We have to assure all you that the issue is not in bandwidth, and after all, despite the unusual requests to from these two hosts, we will reactivate it, and will monitor the situation further.

  • If /etc/resolv.conf is follows:

    search ava.hosting
    nameserver 8.8.8.8
    nameserver 8.8.4.4
    

    doing host www.msftconnecttest.com would resolve www.msftconnecttest.com.ava.hosting and could get 176.123.0.130 because wildcard A record.
    Now wildcard A record seems to be fixed.

  • until i see valid proof (like email headers) of the dos/ddos report -- I am inclined to think this report about the connect test being hammered is bull.

    @zGato said:
    I just cannot believe Microsoft actually sent out an abuse report.
    What about my institute that has like thousands of windows pcs?

  • yoursunnyyoursunny Member, IPv6 Advocate
    edited December 2024

    @amj said:
    If /etc/resolv.conf is follows:

    search ava.hosting
    nameserver 8.8.8.8
    nameserver 8.8.4.4

    If the customer installed from template and the template contains a resolvconf like this, it's entirely the provider's fault, for having such a template along with the wildcard DNS.
    Provider should unsuspend the server and grant SLA credits equivalent to a downtime.

    If the customer installed from ISO and accepted this search domain (discovered through RDNS) during installation, it's the customer's mistake, not an intentional abuse.
    Customer should be spanked but then given an opportunity to correct this mistake by deleting the search domain.

  • wadhahwadhah Member, Host Rep

    @AvaHosting can we please view the microsoft report that was sent because of one of the accounts suspended?

    Thanked by 1yoursunny
  • Customer has ava.hosting in resolv.conf, ava.hosting has wildcard dns for this domain.
    Customer installed VPN and their computers tries to ping Microsoft, but couldn't get to Microsoft due to incompetence of the network person from the hosting provider.
    Hosting provider sees lots of requests for "http://www.msftconnecttest.com/connecttest.txt" but due to their incompetence all of these requests hit their own server instead. They assume it's a DoS attack and suspend their customer.
    Host claims Microsoft sent the abuse report but so far has not provided proof, suggesting to me they have made up the fact about this abuse report and trying to blame their customers.
    Host realizes their mistake, addresses the mistake, but not admitting mistake.

    /s

  • This is embarrassing.

    Thanked by 1beermachine
  • So the wildcard DNS is indeed gone now

    $ host www.msftconnecttest.com.ava.hosting
    Host www.msftconnecttest.com.ava.hosting not found: 3(NXDOMAIN)
    
  • Step 1:
    Heeeeey, Microsoft send us abuse report because you spamming the network check for Windows.
    Step 2:
    Oh btw. you never reached Microsoft servers, you spamming our mail host.

    Profit:
    ????

  • Plot twist, OP and ava.hosting are the same person. LET was used as free tech support.

    /jk

  • admaxadmax Member, Megathread Squad

    @TheOnlyDK said:
    Plot twist, OP and ava.hosting are the same person. LET was used as free tech support.

    /jk

    LMAO

  • NeoonNeoon Community Contributor, Veteran

    @allthemtings said:
    regards

    reguards

    Thanked by 1beermachine
  • @Lu5ck said:
    This is embarrassing.

    and entertaining!

    Thanked by 1beermachine
  • totally embarrassing LOL

  • hello sir this is kind of emberrassing but what are we expecting of lowendproviders anyway, competence?

  • Dm me to get 99.9% sale off lol

    @TheOnlyDK said:
    Plot twist, OP and ava.hosting are the same person. LET was used as free tech support.

    /jk

  • Anyway thank guys, I have 350 days left, may be drama continue

  • kevindskevinds Member, LIR

    @AvaHosting said:
    TL;DR: We have been reactivated the services.

    Why?

    The ticket said reactivation was not negotiable.

    Thanked by 2Rubben sanvit
  • admaxadmax Member, Megathread Squad

    :D

  • kevindskevinds Member, LIR

    @kevinds said:

    But I think my favourite part of this drama is Microsoft sending abuse reports about abuse not directed at their IPs..

    Thanked by 3xvps equalz gks
Sign In or Register to comment.