Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

VPS 8gb 4vcpu EU/US for cyber security activities

Hi all,

Buying 5 KVM VPS over the next few months (3 EU + 2 US), staggered ~1 month apart. Repeat buyer if it goes well.
Per-VPS specs:

RAM: 8 GB
vCPU: 4 - low steal / not heavily oversold (a YABS for the exact plan is appreciated)
Storage: 45–70 GB SSD/NVMe
Bandwidth: ~2 TB/mo on a real, unthrottled uplink (no hidden speed caps)
OS: Linux, full KVM
1× clean/unblocklisted IPv4 (extra IPv4s optional)

Usage - please read before offering:
Authorized, legal, ethical security work: outbound vulnerability/port scanning of in-scope bug-bounty / pentest targets.

Nice to have: stable nodes / few unscheduled reboots (jobs run long), self-serve reinstall + snapshot, and a benchmark score
Budget: ~$70/yr per VPS (flexible for the right network).
PMs welcome.

Comments

  • rpqurpqu Member

    Might as well BYOIP+ASN. @Shakib

    Thanked by 2Shakib forest
  • @rpqu said:
    Might as well BYOIP+ASN. @Shakib

    Know any providers?

  • ShakibShakib Member, Patron Provider

    @somethingsomething said:

    @rpqu said:
    Might as well BYOIP+ASN. @Shakib

    Know any providers?

    The budget is too low, and I don't want to deal with abuse reports.

  • rpqurpqu Member

    @Shakib said:

    @somethingsomething said:

    @rpqu said:
    Might as well BYOIP+ASN. @Shakib

    Know any providers?

    The budget is too low, and I don't want to deal with abuse reports.

    I mean. Maybe he consider purchasing IP block and 6 digit AS (or rent). Then, he could purchase vps from you or anyone else that has BYOAS. It will only blow his budget by $6-7k

    Thanked by 1Shakib
  • ShakibShakib Member, Patron Provider

    @rpqu said:

    @Shakib said:

    @somethingsomething said:

    @rpqu said:
    Might as well BYOIP+ASN. @Shakib

    Know any providers?

    The budget is too low, and I don't want to deal with abuse reports.

    I mean. Maybe he consider purchasing IP block and 6 digit AS (or rent). Then, he could purchase vps from you or anyone else that has BYOAS. It will only blow his budget by $6-7k

    I support almost anything legal and white hat.

    OP can buy a VPS from HostCram and keep using it as long as it doesn't generate abuse reports.

  • forestforest Member

    @somethingsomething said: pentest targets.

    Will you be sharing the Permission to Attack documents with the host?

    Thanked by 1rpqu
  • @forest said:

    @somethingsomething said: pentest targets.

    Will you be sharing the Permission to Attack documents with the host?

    I don't mind sharing that, and the companies won't either if I redact things correctly.
    But sharing every Authorisation doc would be insane for both since I run automation. The proper pentest contracts are less so; no problem on that side.

  • forestforest Member

    @somethingsomething said:

    @forest said:

    @somethingsomething said: pentest targets.

    Will you be sharing the Permission to Attack documents with the host?

    I don't mind sharing that, and the companies won't either if I redact things correctly.
    But sharing every Authorisation doc would be insane for both since I run automation. The proper pentest contracts are less so; no problem on that side.

    Even sharing the first few would go a long way in proving your legitimacy. You have no idea how many people come here claiming to be pentesters and asking for a lenient provider that allows scanning but just end up using the service for abuse, so even the truly lenient providers will need some convincing.

  • HostSlickHostSlick 🚩 Host Rep Tag Suspended

    Even there was one willing to do it, it wouldnt be a good idea to write it here.

    Because in no time the Provider will be overrun by such people
    Trust me, its crazy. And more and more will come.

  • conceptconcept Member

    If its for legitimate cyber security work, you would have your IPs and ASN

    Thanked by 1forest
  • @concept said:
    If its for legitimate cyber security work, you would have your IPs and ASN

    Sure, but being a solo, I cannot afford an ASN.

  • rpqurpqu Member

    @somethingsomething said:

    @concept said:
    If its for legitimate cyber security work, you would have your IPs and ASN

    Sure, but being a solo, I cannot afford an ASN.

    How about renting an ASN?

  • iriskairiska Member

    If it's for legitimate (authorized) pentesting, then any VPS could do, people use AWS for that; you could always ask before-hand with an LOA to be safe.

    If it's bug bounty, just use Censys or Shodan for port enumeration, no need to burn clean IP reputations from good providers.

    Any DNS enumeration can simply be done behind VPNs or proxies, they're IPs are usually cooked charred from people abusing them, but doesn't really matter for DNS (typically).

    Thanked by 2forest rpqu
  • @rpqu said:

    @somethingsomething said:

    @concept said:
    If its for legitimate cyber security work, you would have your IPs and ASN

    Sure, but being a solo, I cannot afford an ASN.

    How about renting an ASN?

    How much does it cost generally?

  • rpqurpqu Member

    @somethingsomething said:

    @rpqu said:

    @somethingsomething said:

    @concept said:
    If its for legitimate cyber security work, you would have your IPs and ASN

    Sure, but being a solo, I cannot afford an ASN.

    How about renting an ASN?

    How much does it cost generally?

    I forgot, but I think there was a thread about it. Can't find it. Otherwise, ask people at https://lowendtalk.com/discussion/160162/aio-ip-related-ipv4-ipv6-asn-thread-only-providers-lirs-are-allowed-to-post-offers

  • tentortentor Member, Host Rep

    @rpqu said:

    @somethingsomething said:

    @concept said:
    If its for legitimate cyber security work, you would have your IPs and ASN

    Sure, but being a solo, I cannot afford an ASN.

    How about renting an ASN?

    You don't need to "rent" it, RIPE charges €50/year and LIR sponsorship ends up €75-100/year, no need to go unofficial shady path.

    The most expensive part is IPv4 address space actually.

    Thanked by 2forest rpqu
  • bbn12bbn12 Member

    ..asn is cheap..... you will need your own IPv4 range

Sign In or Register to comment.