New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
racknerd, why do you always permit 107.173.42.94 to abuse again and again
in General
https://linux.do/t/topic/2662508/20
https://linux.do/t/topic/2426372
Racknerd, why do you alwasy permit 107.173.42.94 to abuse again and again? There are already many victims reported this CPA abuse.

Comments
@dustinc
Sorry @markrao888, what is CPA?
Your abuse has been doubled.
https://www.abuseipdb.com/check/107.173.42.94
Hi @markrao888 -- happy to look into this, though I'd need an abuse ticket ID or reference to work from. Feel free to send me a message with that information, if you've submitted one.
To set expectations on how this works on our end: we don't monitor third party public forums such as the ones you linked for alleged abuse reports, and realistically no provider at our scale can. Abuse handling has to be systematic, otherwise nothing is properly tracked or actionable. The correct path is to email reportabuse[@]racknerd.com with the IP, and any relevant logs or evidence. Sending an email to that address will automatically generate a ticket ID (system should reply back to you via email with a ticket ID within a few minutes after emailing).
From there, the report is logged, forwarded to the end user in question, and they're given a reasonable window to respond and remediate. If there's no response, or the behavior continues, we escalate accordingly, up to and including suspension or termination of the service.
All services on our network are governed by our Terms of Service and Acceptable Use Policy, and we have defined processes and procedures behind enforcement of them. When you're managing hundreds of thousands of IPs across a network of our size, enforcement can't be "informal" or based on public forum's back and forth.
It's also worth mentioning that abuse handling isn't always as simple as it may appear from the outside. In some cases, the party behind an IP isn't a direct client of ours, as we have other hosting providers, resellers, and colocation customers who operate on our infrastructure/network, and maintain their own customer bases. When that's the case, that naturally adds a layer between us and the actual end user. It doesn't mean nothing is happening -- it just means the process involves more than one party.
There are also situations where an IP may not even be ours anymore. IPv4 space in this industry commonly gets released, reassigned, and reallocated over time, and outdated SWIP or stale WHOIS records can leave an IP appearing to be under one provider when it's since allocated elsewhere by upstream. That's just an example, I'd have to look at the specifics of this particular case to say either way, though I mention it because assumptions based on public records alone aren't always accurate. These situations aren't always as straightforward as you may think, when looking from the outside.
So if you (or anyone else in this thread) has previously submitted a report, send over the ticket ID and I'll personally pull it up and review where things stand. Feel free to reach out to me directly at dustin[@]racknerd.com as well.
Hi, @dustinc
My ticket number is Ticket #YX01810
I reported once, and it is suspended, and after some time 107.173.42.94 try to steal other people's gpt quota in cpa again. Then I reported again, and it is suspended again.
But now, other people said it stil steal other peoples' gpt quota again.
Why this happen and you do not block it?
MJJs are now fighting for tokens, how exciting.
CPA is clipproxyapi, that it is a proxy that can be use to access openai codex.
It steal other people's gpt quota via trying the CPA password or CPA vulnalities.
How is it stealing your GPT quota?
Any evidence for this?
CPA has logs to record who is using it, here are some from my cpa vsp log:
Format: [timestamp, local UTC+08:00] status | latency | client IP | method "path"
[2026-06-17 23:20:05] 400 | 2.086s | 107.173.42.94 | POST "/v1/responses"
[2026-06-17 23:20:30] 200 | 17.142s | 107.173.42.94 | POST "/v1/responses"
[2026-06-17 23:20:33] 200 | 14.743s | 107.173.42.94 | POST "/v1/responses"
[2026-06-18 00:16:00] 429 | 270ms | 107.173.42.94 | POST "/v1/responses"
[2026-06-18 00:16:01] 429 | 342ms | 107.173.42.94 | POST "/v1/responses"
[2026-06-18 08:22:29] 200 | 4.163s | 107.173.42.94 | POST "/v1/responses"
[2026-06-18 08:23:45] 200 | 3.936s | 107.173.42.94 | POST "/v1/responses"
(The complete 3,186-line log is available on request.)
I'm honestly amused. I wish the translate function would work better on that page but I'm laughing regardless
Ya it is kinda awkward to read that translation but well, this is life.
I don't see anything malicious here.
Maybe they should ask gpt to fix the issue?
No, it is CPA, that if somebody did not set the settings correctly or password is too weak, then somebody like 107.173.42.94 will steal the cpa owner's gpt quota.
the best part is that nobody could even be arsed to drop the ip if thats such an issue. Its gold, pure gold.
It means 107.173.42.94 are using this CPA owner's codex quota. CPA is a codex proxy that setup by who has gpt/codex account. And 107.173.42.94 steal codex quota when CPA is not set up correctly or has weak password
How about to set a good password then?
If you start to make threads about every IP that is doing this then LET will soon be filled with nothing else.
If this is your perception of evidence for stealing, then it's evidence for me that you have a security issue if it's that easy.
Doesn't take away that I'm annoyed with all the hammering of bots trying to do all kind of stuff on my services also, but that's where security measures are for... it's 2026, if it's not trying to do GPT stuff, then it's Wordpress, Joomla or whatever.
That is another topic, like a attcker always try to ssh to different vps using different password to try. And many people foud it, then I think we should report to the attacker's vps provider. I think this is a abuse behavior.
But this is not the vps provider.
This is LET.
Someone please TL;DR in English so I can join the fun, thanks.
As a service provider, seeing an IP address access this API without any actual abusive behavior looks to me like a normal user.
Furthermore, you didn't set up proper authentication mechanisms for the CPA service, which is why anyone could easily access and use it. This feels much more like your own issue.
Here is what you should do:
I hope this gets resolved quickly, and I hope this serves as a lesson to properly protect your services.
Bro had no password, and is now complaining to the provider and all of us that someone is accessing his service.
MJJ 101
Many people report the IP is stealing gpt quota, yes, we may take more actiosn to protect our vps. But this is a abuse behavior, like attacker ssh to differrent vps via trying different password. I think the vps provider shuould take actions to stop the attacker.
Why I complain here due to Racknerd suspend the vps for some time, and then the IP steal again. And then I report again, then suspend again, but now the IP continue to find the CPA vpses and steal other people's quota.
Do you really agree the VPS provider could permit such behavior?
Responsibility of veeeppps customer only to protect veeeppps
Set a password dude.