Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


[ ASK ] Refund Experience Delimiter Services - Page 2
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

[ ASK ] Refund Experience Delimiter Services

2»

Comments

  • MarkTurner said: You were alerted to the problem, you choose to do nothing on ANY of the 5 notifications, even now you still have taken no action to fix the problem.

    5 notification ? NONE in email or client
    i create ticket to know what is the problem, but no respon after 3 days and i PM you

  • Rather than bleating, just fix the problem. You've had more than ample chance to do that.

    Come back here when you have fixed the problem. Your server is not going to be considered for unsuspension whilst you have these sites hosted.

  • I can't even understand what the hell op is talking about half the time. From what I see he had everything he needed to fix the problem and had ample time to complete the task.

  • @TheLinuxBug i just use free controlpanel, i use free webuzo to decrease the cost.
    with $100 i can rent 5 vps and its i can host +- 250 freenom domain

  • vanjava said: 5 notification ? NONE in email or client i create ticket to know what is the problem, but no respon after 3 days and i PM you

    If you used a valid email when signing up, you would have gotten a email when the ticket got created and replied.

    vanjava said: Linode always give probabily suspect site

    If you like Linode so much why don't you just go back and use them for everything and be done with it.

  • MarkTurner said: Rather than bleating, just fix the problem. You've had more than ample chance to do that.

    Come back here when you have fixed the problem. Your server is not going to be considered for unsuspension whilst you have these sites hosted.

    i want list of webite hosted
    and reinstall OS, but no control panel to reinstal OS, because i want try VPSSIM control panel with ngix

    any link to reinstall OS tutorial on delimiter server

  • CFarence said: If you used a valid email when signing up, you would have gotten a email when the ticket got created and replied.

    i use valid email, and every i open ticket always send to my email, but none notification before suspend

    CFarence said: If you like Linode so much why don't you just go back and use them for everything and be done with it.

    i still use linode, but i want try dedicated server and delimiter is my fist DS, want compare and calculating the cost, feature, performance and others

    something can not say it's better if there is no comparison :D

  • AnthonySmithAnthonySmith Member, Patron Provider

    tl;dr

    image

  • FlamesRunnerFlamesRunner Member
    edited August 2015

    @vanjava said:
    something can not say it's better if there is no comparison :D

    They did give you a list of websites.

    @MarkTurner said:
    vanjava - we provide this information as the reports come in. You will have had them in realtime.

    Stop going on about resources, its not related. What you do with your resources is YOUR business, we don't care. What we care about is that customers don't use their server to break the law.

    Here's some examples of the reports:


    Dear Yomura abuse team, BFK edv-consulting GmbH is an anti-fraud and security company and acts
    on behalf of the German private banking industry, cooperative banks as
    well as savings banks. BFK combats spam, phishing, and identity theft
    malware. The following server seems to have been hacked and is being used as a
    jumphost redirecting to phishing sites: "vpstutorial.tk" (= 199.204.186.46) The fraudulent content can be found at http://vpstutorial.tk/wp-includes/js/imgareaselect/jquery.imgareaselect.js.php In order to prevent further losses and evade liability issues we urge
    you to disconnect/shut down the hacked server and clean up the web space. We
    kindly ask you to assist our investigation by providing us with a copy of the
    fraudulent content on the server, especially any PHP scripts and log files
    found. You can do so by replying to this mail and including a zip archive of
    the content. We are happy to assist you in case of further questions. Thank you for your cooperation. Best Regards, BFK Cert-Team BFK edv-consulting GmbH http://www.bfk.de
    Kriegsstrasse 100 D-76133 Karlsruhe
    tel: +49 721 96201-1 fax: +49 721 96201-99
    Geschäftsführer: Christoph Fischer HRB105469 Mannheim


    We have detected a phishing page on 199.X.X.X. Our client, SunTrust, requests that the page be disabled immediately. URL on 199.204.186.46: hxxp://chelseawalpaper[.]cf/wp-includes/SimplePie/SunTrust-Online Banking[.]htm Please reply to this message to confirm receipt and update us on the status of shutting down the fraudulent site. Please let us know if you can provide any files associated with this attack, so that we can perform analysis. Thank you in advance,
    Ray Powell | Incident Response Analyst | 905-271-3725 x314
    [16979606]

    It's literally right there.

  • FlamesRunner said: They did give you a list of websites.

    its just arrive, but not on my ticket reply, if its give asap, i don't think because resource

  • FlamesRunnerFlamesRunner Member
    edited August 2015

    By the looks of it, you should just hire someone to manage your server. Honestly, you aren't cut out for the job right now.

    And no, it IS NOT your resource usage. You're on a dedicated server, so resources are dedicated to you.

    Thanked by 1KwiceroLTD
  • KwiceroLTDKwiceroLTD Member
    edited August 2015

    By the looks of it, you need to take your ass back to shared hosting or, PAY FOR MANAGED HOSTING. @OP you pretty much just said "I want a refund because delimiter is following the law which it's governed by, and because I broke their terms of service/aup"

    Thanked by 1timnboys
  • Next time. Disable root login locally and remote. Disable password login and use keys only and allow only one or two ip to even ssh in on a random port. Setup the iptables to ban any ip or subnet that even looks at port 22.

    This will be after you do a first time install of course. Oh and

    This won't affect your clients and I'm wondering how you are in the industry without knowing this?

    Thanked by 1timnboys
  • I think the op wasn't given the list of sites before Mark Turner posted it here. Could the op or Mark turner confirm otherwise.

  • Better yet, port knocking/different SSH port/key authentication on a proxy VPS that serves as the only server with access to the dedicated server.

  • Maybe you should try reading? It's not really that difficult.

    @ez2uk said:
    I think the op wasn't given the list of sites before Mark Turner posted it here. Could the op or Mark turner confirm otherwise.

  • " i just use server for AGC, Linode always give probabily suspect site because i don't memorize all of my domain (i use hundreds of freenom), just create and forget +- 150 site on Dedicated and +- 50 on VPS"

    Create and forget??? Used to Linode sending lists of "suspected" sites? Folks it sounds like this is a common occurrence with this person.

    Thanked by 1netomx
  • I did and needed a clarification. whats wrong?

  • Fine, here is a brief summary:

    The issue is the client is not removing phishing sites that he is hosting on his dedicated server. Delimiter proceeded to shut down the server, so the client could remove the files via KVM over IP. He didn't, and complained about it here. What's worse is he says "resource usage" may have been an issue on a dedicated server.

    Thanked by 1netomx
  • Dumb question but what is "AGC"? I know I'll probably kick myself but it's not computing.

  • Well, I just found it difficult to believe how post #8 by @MarkTurner would need any clarification. It clearly says OP was provided with the necessary information so as to deal with the issue at hand: his post even goes on to list a couple of example reports which Mr. Turner sent out to OP.

    @ez2uk said:
    I did and needed a clarification. whats wrong?

  • @ez2uk said:
    I think the op wasn't given the list of sites before Mark Turner posted it here. Could the op or Mark turner confirm otherwise.

    Mark said they sent phishing sites list, OP claimed otherwise. I'd trust Mark's words so either OP just ignored the mails (some clients simply don't care about any message from the host until their service got interrupted/suspended), or the mails ended up in Spam/Bulk/Junk folder.

    @lazyt said:
    Dumb question but what is "AGC"? I know I'll probably kick myself but it's not computing.

    Auto Generated Content, a.k.a. search engine spam.

  • Thanks I thought it might be something like that but I couldn't for the life of me connect the words to the letters.

  • Op - in my opinion, I'd suggest that you perform the steps as Mark had specified to you and it is true that, you could spend the time to remove the sites accordingly and get your server re-activated, than posting your claims here.

  • Language barrier is a b..ch.
    But in such cases you shouldn't act like you understood all.

    Clearly you have been reported of these.
    If not, please share the tickets/mails you recieved.

  • ClouviderClouvider Member, Patron Provider
    edited August 2015

    @cmsjr123 said:
    Next time. Disable root login locally and remote. Disable password login and use keys only and allow only one or two ip to even ssh in on a random port. Setup the iptables to ban any ip or subnet that even looks at port 22.

    Hiding gives you zero added security. How this is going to solve breach done via PHP script, or how it will prevent this? You are talking about a completely different thing here.

  • FlamesRunnerFlamesRunner Member
    edited August 2015

    Forgot to mention: Have monthly security audits performed by a professional. I've done it on some of my scripts before, and they'd tell me there was a billion injection possibilities even with stripslashes + htmlspecialchars + mysql_real_escape_string. Although sometimes I am lazy, and don't have them checked :)

Sign In or Register to comment.