Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

weird shit with my hostcram kvm

SmokeySmokey Member

I've had a monster 8G from back a while ago. Been through the changes at hostcram over these last few years and never much to complain about..

My KVM is IP whitelist only via custom nftables. Last access by me was around 8 hrs ago before some R&R time.

So I get back to work and can't connect. I find that the KVM is shut down. Startup and check on the VNC, nothing abnormal looking so fire up the ssh session and find a cert mismatch. I didn't continue to auth on SSH and went to the VNC at the VPS CP and can't use my root password. Normal user fine.

Primary activity on this server is working with incus. The couple container instances running Alpine I keep active also had alerts about the host certs not matching.

At this point I just shut the hostcram KVM down and sent off a ticket to see WTF they can tell me..

What does this smell like?

Seems like these conditions are result of root password reset by support/dc people to me.

Thanked by 1Shakib

Comments

  • forestforest Member

    Boot the server into a rescue ISO, mount your root drive, and check your logs for anything suspicious.

    Thanked by 3Smokey mans_xd Shakib
  • SmokeySmokey Member

    Unfortunantly ISO booting not available on this via the device manager.

    It has netboot.xyz via rebuild but in the past that's been kind of a pain in the ass for me to uncouple from vps and get back to where I was before using rebuild + netboot.xyz -- forget exactly the issue but in the end IIRC I just used it to install a newer debian than was available from the normal debian rebuild templates.

  • forestforest Member

    @Smokey said: Unfortunantly ISO booting not available on this via the device manager.

    iPXE?

    Thanked by 1Smokey
  • SmokeySmokey Member

    I know little about iPXE, got a prompt via the proxmox boot menu but eth0 closed and can't get an IP @ iPXE>dhcp

    Hehe, 100% of my XP with this is right, here: https://ipxe.org/ --> quickstart

  • ShakibShakib Member, Patron Provider

    Sorry for the inconvenience.

    We never log in to our customers' VM/Server without their permission.

    The host node "eris" has been online and has not gone down since the last reboot, which occurred 150 days ago.

    It's more like your OS/VM crashed and went offline, though I have seen two instability cases recently where the VM dropped offline for no reason, and upgrading Proxmox OS and Kernel might have resolved that issue on the other node.

    I will plan and upgrade all nodes soon.

    Thanked by 2Smokey sbenchid
  • SmokeySmokey Member

    I don't recall ever having the vm crash or go offline spontaneously, but there is always a first time I suppose.

    The only recent significant change to this was trixie 13.5 to 13.6 which seemed to go fine.

    Can you point me in the right direction to being able to approach the system from the VNC w/o having to provide creds or waking up the OS so I can snag the logs?

    ..or can you/support do it? as it stands, root PW and certs are not mine/expected and I don't want to volunteer anymore data if this is a breach.

    I realize the cause could be a rabbit hole and apologize for suspecting a support PW reset, but I have never had a breach AFAIK or seen odd changes like this.

    While I don't mind wiping the VPS and redoing it, I would like to put some effort into finding some reasonable explanation if possible. Crashing in normal circumstances I'd imagine that the specific changes noticed so far would not be..

    ..welcome anyone's input here, just directing it a bit towards Shakib since HostCram is postured best to investigate unless I can approach the vps from a different way than I see available.

    Thanked by 1Shakib
  • ShakibShakib Member, Patron Provider

    @Smokey said:
    I don't recall ever having the vm crash or go offline spontaneously, but there is always a first time I suppose.

    The only recent significant change to this was trixie 13.5 to 13.6 which seemed to go fine.

    Can you point me in the right direction to being able to approach the system from the VNC w/o having to provide creds or waking up the OS so I can snag the logs?

    ..or can you/support do it? as it stands, root PW and certs are not mine/expected and I don't want to volunteer anymore data if this is a breach.

    I realize the cause could be a rabbit hole and apologize for suspecting a support PW reset, but I have never had a breach AFAIK or seen odd changes like this.

    While I don't mind wiping the VPS and redoing it, I would like to put some effort into finding some reasonable explanation if possible. Crashing in normal circumstances I'd imagine that the specific changes noticed so far would not be..

    ..welcome anyone's input here, just directing it a bit towards Shakib since HostCram is postured best to investigate unless I can approach the vps from a different way than I see available.

    My team doesn't have access to any of our VPS nodes. I kept all access to myself and I didn't change your password or login to your account.

    We operate a few other businesses and our team is working on those.

    You have nothing to worry about.

    Thanked by 1Smokey
  • SmokeySmokey Member
    edited August 6

    I wanted to add some closure to the OP...

    @forest, after @Shikib hooked up a live debian ISO I could boot, I paged through the jounal, syslog & kern logs... Thank you both for taking the time to respond here!

    I didn't see anything looking like a crash, but then I'm not sure I that includes neon lights and big arrows pointing to it for me to see! :#

    After using the bootable ISO Shakib graciously hooked me up with, I changed the root pw eventually just dove in and looked around. My XP is nothing compared to Shakib with this sort of thing, and given the lack of obvious things I'd expect to find if hacked, I'm convinced Shakib nailed it on the head from the start.

    I put the monster back to work a few days ago and wanted to post a new yabs and comment a bit on HostCram and Skakib..

    A few years back I asked about something and got ~this: "that's for people who have brains.." LOL nuf said. I used to have one. Forgot it at an after party some years ago, and rot has since set in with age.. :'(

    However, I have noticed Shakib -has- adjusted some over the time I first hooked up with HostCram. Honestly, he's been a nice guy all along.. I know about the busy life and the value of time.. It's a slippery slope for me I know... PR has never been my strong point.

    Anyhow, great products and I aim to continue using what I have at HostCram and perhaps expand on that if I ever figure out what to do with my collection of servers as a tinkerer. ;)

    # bash yabs.sh -9 -6
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    #              Yet-Another-Bench-Script              #
    #                     v2026-07-03                    #
    # https://github.com/masonr/yet-another-bench-script #
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    
    Thu Aug  6 06:36:56 AM UTC 2026
    
    Basic System Information:
    ---------------------------------
    Uptime     : 9 days, 0 hours, 55 minutes
    Processor  : AMD Ryzen 9 7900 12-Core Processor
    CPU cores  : 4 @ 3693.062 MHz
    AES-NI     : ✔ Enabled
    VM-x/AMD-V : ✔ Enabled
    RAM        : 7.8 GiB
    Swap       : 0.0 KiB
    Disk       : 78.6 GiB
    Distro     : Debian GNU/Linux 13 (trixie)
    Kernel     : 6.12.96+deb13-amd64
    VM Type    : KVM
    IPv4/IPv6  : ✔ Online / ✔ Online
    
    IPv6 Network Information:
    ---------------------------------
    ISP        : HostCram LLC
    ASN        : AS39618 HostCram LLC
    Host       : Fiberstate
    Location   : Buffalo, Wyoming (WY)
    Country    : United States
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/sda1):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 449.42 MB/s (109.7k) | 5.11 GB/s    (78.0k)
    Write      | 450.61 MB/s (110.0k) | 5.13 GB/s    (78.4k)
    Total      | 900.03 MB/s (219.7k) | 10.25 GB/s  (156.4k)
               |                      |
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 5.59 GB/s    (10.6k) | 5.45 GB/s     (5.2k)
    Write      | 5.89 GB/s    (11.2k) | 5.81 GB/s     (5.5k)
    Total      | 11.48 GB/s   (21.9k) | 11.27 GB/s   (10.7k)
    
    iperf3 Network Speed Tests (IPv4):
    ---------------------------------
    Provider        | Location (Link)           | Send Speed      | Recv Speed      | Ping
    -----           | -----                     | ----            | ----            | ----
    Clouvider       | London, UK (10G)          | 239 Mbits/sec   | 847 Mbits/sec   | 114 ms
    Eranium         | Amsterdam, NL (100G)      | 336 Mbits/sec   | 1.85 Gbits/sec  | 120 ms
    Uztelecom       | Tashkent, UZ (10G)        | 715 Mbits/sec   | 780 Mbits/sec   | 211 ms
    Leaseweb        | Singapore, SG (10G)       | 223 Mbits/sec   | 871 Mbits/sec   | 227 ms
    Clouvider       | Los Angeles, CA, US (10G) | 5.21 Gbits/sec  | 4.45 Gbits/sec  | 23.2 ms
    Leaseweb        | NYC, NY, US (10G)         | 3.15 Gbits/sec  | 3.55 Gbits/sec  | 47.2 ms
    Edgoo           | Sao Paulo, BR (1G)        | 1.54 Mbits/sec  | 671 Mbits/sec   | 159 ms
    
    iperf3 Network Speed Tests (IPv6):
    ---------------------------------
    Provider        | Location (Link)           | Send Speed      | Recv Speed      | Ping
    -----           | -----                     | ----            | ----            | ----
    Clouvider       | London, UK (10G)          | 1.36 Gbits/sec  | 1.22 Gbits/sec  | 128 ms
    Eranium         | Amsterdam, NL (100G)      | 1.43 Gbits/sec  | 1.95 Gbits/sec  | 122 ms
    Uztelecom       | Tashkent, UZ (10G)        | 700 Mbits/sec   | 1.12 Gbits/sec  | 203 ms
    Leaseweb        | Singapore, SG (10G)       | 453 Mbits/sec   | 905 Mbits/sec   | 262 ms
    Clouvider       | Los Angeles, CA, US (10G) | 6.04 Gbits/sec  | 2.94 Gbits/sec  | 13.8 ms
    Leaseweb        | NYC, NY, US (10G)         | 1.52 Gbits/sec  | 3.33 Gbits/sec  | 47.1 ms
    Edgoo           | Sao Paulo, BR (1G)        | 961 Mbits/sec   | 1.18 Gbits/sec  | 157 ms
    
    Geekbench 4 Benchmark Test:
    ---------------------------------
    Test            | Value
                    |
    Single Core     |
    Multi Core      |
    Full Test       | https://browser.geekbench.com/v4/cpu/19830909
    
    Geekbench 5 Benchmark Test:
    ---------------------------------
    Test            | Value
                    |
    Single Core     |
    Multi Core      |
    Full Test       | https://browser.geekbench.com/v5/cpu/24510448
    
    Geekbench 6 Benchmark Test:
    ---------------------------------
    Test            | Value
                    |
    Single Core     |
    Multi Core      |
    Full Test       | https://browser.geekbench.com/v6/cpu/18924709
    
    YABS completed in 16 min 29 sec
    
    Thanked by 1forest
Sign In or Register to comment.