Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Onidel Cloud's Thread - Announcements, Feedbacks and Discussions!

11314151618

Comments

  • @rpqu said: hopefully it's under $7/y

    Don't lose hope :lol:

    Thanked by 1rpqu
  • @onidel said:
    You can now order 250 GB and 500 GB S3 storage plans in Singapore and Sydney (annual billing only)

    Any Singapore vps deal?

  • Hitori0221Hitori0221 Member
    edited July 20

    Bring back the Singapore VPS deal and I'll grab an annual ONI-3 <3

    Thanked by 1waqid
  • GravelyGravely Member

    Anyone notice a new location pop up this evening?

    Basic System Information:
    ---------------------------------
    Uptime     : 0 days, 0 hours, 4 minutes
    Processor  : AMD EPYC 7513 32-Core Processor
    CPU cores  : 1 @ 2595.122 MHz
    AES-NI     : ✔ Enabled
    VM-x/AMD-V : ✔ Enabled
    RAM        : 1.9 GiB
    Swap       : 0.0 KiB
    Disk       : 19.3 GiB
    Distro     : Ubuntu 24.04.4 LTS
    Kernel     : 6.8.0-85-generic
    VM Type    : KVM
    IPv4/IPv6  : ✔ Online / ❌ Offline
    
    IPv4 Network Information:
    ---------------------------------
    ISP        : Onidel Pty Ltd
    ASN        : AS152900 Onidel Pty Ltd
    Host       : DigitalFyre Internet Solutions
    Location   : Melbourne, Victoria (VIC)
    Country    : Australia
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/vda1):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 191.14 MB/s  (46.6k) | 2.02 GB/s    (30.8k)
    Write      | 191.65 MB/s  (46.7k) | 2.03 GB/s    (30.9k)
    Total      | 382.79 MB/s  (93.4k) | 4.05 GB/s    (61.8k)
               |                      |                     
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ---- 
    Read       | 5.79 GB/s    (11.0k) | 6.00 GB/s     (5.7k)
    Write      | 6.10 GB/s    (11.6k) | 6.40 GB/s     (6.1k)
    Total      | 11.89 GB/s   (22.6k) | 12.41 GB/s   (11.8k)
    
    iperf3 Network Speed Tests (IPv4):
    ---------------------------------
    Provider        | Location (Link)           | Send Speed      | Recv Speed      | Ping           
    -----           | -----                     | ----            | ----            | ----           
    Clouvider       | London, UK (10G)          | 513 Mbits/sec   | 652 Mbits/sec   | 246 ms         
    Eranium         | Amsterdam, NL (100G)      | 555 Mbits/sec   | 822 Mbits/sec   | 250 ms         
    Uztelecom       | Tashkent, UZ (10G)        | 670 Mbits/sec   | 578 Mbits/sec   | 197 ms         
    Leaseweb        | Singapore, SG (10G)       | 909 Mbits/sec   | 894 Mbits/sec   | 83.7 ms        
    Clouvider       | Los Angeles, CA, US (10G) | 621 Mbits/sec   | 559 Mbits/sec   | 213 ms         
    Leaseweb        | NYC, NY, US (10G)         | 660 Mbits/sec   | 682 Mbits/sec   | 211 ms         
    Edgoo           | Sao Paulo, BR (1G)        | 382 Mbits/sec   | 350 Mbits/sec   | 323 ms         
    
    Geekbench 6 Benchmark Test:
    ---------------------------------
    Test            | Value                         
                    |                               
    Single Core     |                               
    Multi Core      |                               
    Full Test       | https://browser.geekbench.com/v6/cpu/18812172
    
    YABS completed in 12 min 22 sec
    
  • rpqurpqu Member

    Perth, Darwin when

    Thanked by 2Smigit onidel
  • SmigitSmigit Member
    edited July 24

    @Gravely said:
    Anyone notice a new location pop up this evening?

    Must have missed the turnoff to Canberra when going south on the highway. Easy mistake I guess.

    Thanked by 3oloke rpqu onidel
  • allthemtingsallthemtings Member, Megathread Squad

    Big thanks to @oloke for the continued support

  • sliixsliix Member

    Whoaaa. Melbourne???

  • Premium support from vampires.

    Support from the east

  • onidelonidel Member, Patron Provider, Top Host, Megathread Squad

    @rpqu said:
    Perth, Darwin when

    soon™️

  • rpqurpqu Member

    @onidel said:

    @rpqu said:
    Perth, Darwin when

    soon™️

    Crikey, must be the NBN mucking things up

    Thanked by 1onidel
  • drivexdrivex Member

    @onidel any plans to bring S3 to Amsterdam?

  • Hello I want to order 250GB of oloke.

    Thanked by 2oloke onidel
  • @nghialele said:
    Hello I want to order 250GB of oloke.

    Please continue. Payment in oscypek only.

    Thanked by 1nghialele
  • Whenever you hear someone talk about continuous improvement, pay attention to their project, because that concept can work wonders over time.

  • networknetwork Member

    @onidel said:

    @rpqu said:
    Perth, Darwin when

    soon™️

    Any plans for pay for actual usage (per gb) with prepaid credits like Bunny.net? Looking for a Bunny.net alternative for S3 storage but don't want to commit yearly for a fixed size.

    Thanked by 1rpqu
  • onidelonidel Member, Patron Provider, Top Host, Megathread Squad

    We've just released a new platform update, introducing SSO support with Google, GitHub, and passkeys, along with a range of UI/UX and security improvements.

  • ArirangArirang Member
    My idlers are waiting for Melbourne. Looking forward to a launch promotion.
    
    Thanked by 1oloke
  • Hi @onidel

    Very lovely the new touring function on the Cloud Dashboard, but can we have a skip button for it, it's 34 steps and I don't think I can skip any of those T_T

  • onidelonidel Member, Patron Provider, Top Host, Megathread Squad

    @nghialele said:
    Hi @onidel

    Very lovely the new touring function on the Cloud Dashboard, but can we have a skip button for it, it's 34 steps and I don't think I can skip any of those T_T

    done :D

    Thanked by 1Hitori0221
  • @nghialele said:
    Hi @onidel

    Very lovely the new touring function on the Cloud Dashboard, but can we have a skip button for it, it's 34 steps and I don't think I can skip any of those T_T

    yep I spent ~90 seconds going through all the touring yesterday :D

    Thanked by 1nghialele
  • @Hitori0221 said:

    @nghialele said:
    Hi @onidel

    Very lovely the new touring function on the Cloud Dashboard, but can we have a skip button for it, it's 34 steps and I don't think I can skip any of those T_T

    yep I spent ~90 seconds going through all the touring yesterday :D

    CHAMP 🫡

  • onidelonidel Member, Patron Provider, Top Host, Megathread Squad

    @Hitori0221 said:

    @nghialele said:
    Hi @onidel

    Very lovely the new touring function on the Cloud Dashboard, but can we have a skip button for it, it's 34 steps and I don't think I can skip any of those T_T

    yep I spent ~90 seconds going through all the touring yesterday :D

    we should reward you with Onidel expert badge B)

  • olokeoloke Member, Host Rep

    We launched a public Bug Bounty Program for security researchers and ethical hackers to help us keep our platform secure through responsible disclosure.
    We offer rewards up to $500.

    You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program

    Once your submission gets accepted, you will also be listed on our Hall of Fame page :)

  • forestforest Member
    edited July 29

    @oloke said: You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program

    According to the rules:

    Any vulnerability found must be reported no later than 48 hours after discovery.

    Often, a potentially exploitable bug may be found but determining whether it really is exploitable can take a while. So does this 48 hour period start from the time the bug was discovered or from the time its exploitability was determined?

    Any AI generated reports will be rejected outright without bounty eligibility.

    Even if it was succinct and came with a trivial reproducer? It might be better to just say that it'll be ineligible for the bounty rather than saying it'll be rejected (i.e. not fixed) outright. After all, surely you wouldn't refuse to fix a reported and trivially reproducible vulnerability just because an AI generated the report, right? You'd just not consider it eligible for the bounty?

    Also, what would RCE leading to non-elevated privileges be classified as? For example, what would compromising a QEMU process and gaining full code execution on the node, but still confined to the QEMU user and not root (you do run QEMU as an unprivileged user with sandboxing enabled I hope!) count as?

    A bug bounty program is an awesome idea btw! Congrats on setting one up!

    Thanked by 2onidel buggedout
  • olokeoloke Member, Host Rep

    @forest said: So does this 48 hour period start from the time the bug was discovered or from the time its exploitability was determined?

    Right, here we meant from the time it was confirmed to be exploitable.
    I'll add a clarification to the rules as well.

    Thanked by 1forest
  • onidelonidel Member, Patron Provider, Top Host, Megathread Squad

    Also, what would RCE leading to non-elevated privileges be classified as? For example, what would compromising a QEMU process and gaining full code execution on the node, but still confined to the QEMU user and not root (you do run QEMU as an unprivileged user with sandboxing enabled I hope!) count as?

    that is just an example of what we consider a critical issue. Compromising QEMU and achieving code execution within the QEMU process context would generally fall somewhere between High and Critical. If the compromise does not result in root privileges, the severity ultimately depends on what can actually be achieved and the real-world impact (there are other defense-in-depth layers)

    that said, if the vulnerability is in QEMU itself rather than in our own services or infrastructure, it would not be eligible for a reward as it is considered a third-party issue. If there is a patch and we are still vulnerable after 90 days then it will be eligible (not saying we would wait that long to patch such a critical issue)

    Thanked by 1forest
  • forestforest Member

    @onidel said: If there is a patch and we are still vulnerable after 90 days

    Might want to mention that the 90 day countdown starts from when a patch is created, since the current text only mentions the disclosure of the vulnerability in public. Anyway QEMU was just an example, I was just curious. :P

  • rpqurpqu Member

    @forest said:

    @oloke said: You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program
    Any AI generated reports will be rejected outright without bounty eligibility.

    Even if it was succinct and came with a trivial reproducer? It might be better to just say that it'll be ineligible for the bounty rather than saying it'll be rejected (i.e. not fixed) outright. After all, surely you wouldn't refuse to fix a reported and trivially reproducible vulnerability just because an AI generated the report, right? You'd just not consider it eligible for the bounty?

    :(

  • forestforest Member
    edited July 29

    @rpqu said:

    @forest said:

    @oloke said: You can read more about the rules and scope of the program here:
    https://kb.onidel.com/hc/kb/articles/1775831946-bug-bounty-program
    Any AI generated reports will be rejected outright without bounty eligibility.

    Even if it was succinct and came with a trivial reproducer? It might be better to just say that it'll be ineligible for the bounty rather than saying it'll be rejected (i.e. not fixed) outright. After all, surely you wouldn't refuse to fix a reported and trivially reproducible vulnerability just because an AI generated the report, right? You'd just not consider it eligible for the bounty?

    :(

    I figure the intent is to avoid AI slop reports. I'm just a nitpicker for language so the phrase "rejected outright" caught my attention. I doubt they'd actually refuse to fix a severe reported vulnerability in any situation, even if the reporter made themselves ineligible for the bounty.

Sign In or Register to comment.