Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

HostDzire Hit by Ransomware Attack

11011121315

Comments

  • @jsg said:
    where is the community for those expensive or even super-expensive providers, where can I get reliable information?

    https://repost.aws/

  • deqideqi Member
    edited August 9

    @default said:
    @HostDZire — it is enough for me that you offer and keep really cheap servers to this community; I don't need any compensation. Accidents can happen, especially in an age when AI evolves so much and so fast (for good people, but also for evil ones). For me it is enough that you're here, that you're with us in this community, with great passion for computers and servers. Thank you.

    couldn't agree more, i make a living off these servers i got with you, for me the downtime was a good way to actually prove my drp was working (lab tested it a few times on several occasions) and thus my downtime was like roughly 10 mins.

    nothing lost, even dns failed over automatically

  • jsgjsg Member, Resident Benchmarker

    @CloudHopper said:

    @jsg said:
    where is the community for those expensive or even super-expensive providers, where can I get reliable information?

    https://repost.aws/

    Thanks, but I meant 3rd party fora (as opposed to a provider's), neutral, with concrete and credible experience by actual users (as opposed to support, KB, etc.) or in other words, a "HET", i.e. like LET but for "high-end" products.

  • QuenFeaQuenFea Member
    edited 1:10AM

    @CloudHopper said:

    @QuenFea said:

    @CloudHopper said:

    @QuenFea said:

    @CloudHopper said:

    @QuenFea said:
    As this was all an unforeseen circumstance, who could have imagined that, following a data loss, they would now be implementing a policy of randomly changing IP addresses?

    This will be my 3rd IP renumbering of one of my VMs so far this year. It's the first data loss I've had in a while, but that also happens a lot with LET hosts. In fact, Hostdzire's NL offer explicitly said that the host server didn't have RAID configured so data loss was a very foreseeable outcome.

    If you read through all my previous replies, you’ll see I stated from the start that data loss resulting from a security breach is entirely acceptable; as consumers, we should always maintain our own backups rather than relying on the provider.
    My main issue has always been Hostdzire’s decision to simply reassign random IPs in order to speed up recovery. Keep in mind that the context here was a server reconfiguration necessitated by a breach—not a data center migration or an IP re-addressing scheme.
    To expedite recovery, they could have easily assigned random IPs from a pool of unallocated subnets that existed prior to the breach, allowing customers to manually switch back to their original IPs later if needed. Unfortunately, that isn't the path they chose. Perhaps it was a cost consideration, a lack of sufficient unallocated subnets to support that approach, or some other factor.
    1. The affected service was located in India, not the Netherlands.
    2. I don't care about the data loss; my only concern is the original IP address.
    3. They have decades of experience, yet the emergency response plan implemented following this breach struck me as chaotic—more like a series of ad-hoc decisions.

    Regardless, what they need to do now is promptly analyze and fully disclose the cause of the incident and the current remediation steps, while also preparing contingency plans for various scenarios. If possible, they should also adjust pricing to reflect current hardware market rates—doubling, tripling, or even quadrupling prices. Only with sufficient profit margins can they realistically aim for stability, security, and efficiency.

    I think your just shopping in the wrong window. This is "Low End Talk" and things are supposed to be cheap, with providers cutting corners to keep prices down. Servers here are cheap, but you have to accept occasional IP renumbering, noisy neighbours, inconvenient maintenance windows, less than perfect uptime and possible data loss as part of the package.

    If you want to pay double, triple or even quadruple the price then there's established providers that serve that market, but they don't advertise here. The truth is you should be angry at yourself for putting a production workload on a Low End server without a proper disaster and recovery plan because there servers are cheap for a reason.

    You simply don’t understand.
    These servers come with 16H/32GB/240GB, yet the annual fee is only $32. Do you see any problem with raising the price?

    No, you don't understand. People here want cheap servers and are willing to accept the trade-offs. There's plenty of providers that will charge you more, and some of them will offer you better reliability and security etc. But this is Low End Talk and here you buy Low End servers at rock bottom prices. So if you ran a production workload on a server you're paying less than $3/month without a disaster and recovery plan that's on you.

    You seem to insist things must stay exactly as they are—just because this is LET? Providers like Hetzner, OVH, Netcup, and Host-c can raise prices. Yet you think Hostdzire isn’t allowed to do the same.

    Global storage hardware prices are skyrocketing. The situation has gone far beyond expectations. So what’s wrong with a provider reassessing risks and costs—and adjusting prices to match reality? Or do you want them to become unsustainable and go under—the next “Deadpool” (not a curse)? Besides, I’m just an ordinary user sharing my thoughts. Hostdzire hasn’t even said they will raise prices. Their Terms of Service already cover this. So what’s there to argue about?

    “The amount you pay for your service will not increase from the date of purchase in the current billing cycle. However, prices may be increased from the next billing cycle. We reserve the right to change prices listed on our websites, and the right to increase/decrease the amount of resources given to plans at any time.”

    As for the ransomware incident or data loss—I don’t care. It didn’t affect me. The only thing I cared about was the original IP. When I learned two days ago it couldn’t be recovered, I executed my contingency plan. I updated all services manually. Everything runs fine now. I also understand why they assigned random IPs.

    All misunderstandings are cleared up. If you still insist on your view, fine—you’re right. That’s all I’ll say. I won’t reply further. Have a pleasant weekend, everyone.

  • ART994ART994 Member

    Where does everyone store cheap backups? Has anyone thought about sending them to Telegram?

  • akaemuakaemu Veteran

    Is this host desirable or not?

  • SayantanSayantan Member

    @HostDZire want to change ip please help.

    Ticket #884062

    Thank you.

  • This thread made my Monday morning.

    Why are so many people hosting 'critical services' on dirt-cheap servers without any backups? You should always keep at least one backup under your own control.

  • vpsricvpsric Member

    @ART994 said:
    It’s a very strange decision to use the exact same thing that got hacked. I probably won’t renew my server in the future; I’ve switched to another provider.

    any other alternative?

  • mhpteammhpteam Member

    they do offer me a pro-rated refund if I want to, even though its a LET Special plan ;)

  • mhpteammhpteam Member

    @akaemu said:
    Is this host desirable or not?

    They are trying to fix everything, listening to customers, not like ericlewisboloxmedia

  • @ART994 said:
    Where does everyone store cheap backups? Has anyone thought about sending them to Telegram?

    most of my backup are small enough, so they goes to borgbase.com (free 10gb). the bigger one aren't on free service. as long as it's encrypted by default it shouldn't be an issue. if you really emphasis on free then use rclone + rclone crypt, it has more coverage on the free cloud accounts.

    don't forget to setup a notification system on the backup action, so you knew if a backup was failing for whatever reason. i personally uses self-hosted ntfysh for this one since i'm not comfortable putting those message in telegram/discord .etc

    for telegram i couldn't recommend, my account got whacked after storing around 2TB of encrypted data (which is deserved).

    @akaemu said:
    Is this host desirable or not?

    looking forward for dealz. especially on india location (alaready have sg with them)

    Thanked by 1rpqu
  • rpqurpqu Member

    @ScreenReader said:
    for telegram i couldn't recommend, my account got whacked after storing around 2TB of encrypted data (which is deserved).

    You probably send it too fast

  • VoidVoid Member

    [@ScreenReader said]
    for telegram i couldn't recommend, my account got whacked after storing around 2TB of encrypted data (which is deserved).

    Did you have telegram premium by any chance?

  • @rpqu said:

    @ScreenReader said:
    for telegram i couldn't recommend, my account got whacked after storing around 2TB of encrypted data (which is deserved).

    You probably send it too fast

    nope, 2TB is accumulation in around 1 year timeframe. i have a track on it on google sheet (for every timestamp when a backup event is made). i did this with reasoning "is there a limit on this chat app?" and find out. i probably could do better if i managed to script to keep last n backup only (as it's not an incrimental backup), not just perpetually sending more files on daily basis.

    @Void said:

    [@ScreenReader said]
    for telegram i couldn't recommend, my account got whacked after storing around 2TB of encrypted data (which is deserved).

    Did you have telegram premium by any chance?

    i don't think telegram premium is a thing yet back then, it's around 2021-2022 ish. it's also before i knew telegram-as-filesystem too but nowadays i don't bother with it anymore.

    if you're willing to pay i think it's better to pay some LET host instead, cheap storage like hostbrr as one of your mirror makes life easier. telegram premium cost $4.99 a month, boy that's a lot of money if the usage is only for storage.

  • edited 5:27AM

    I hope providers will offer VPS storage for backups. We’re entering uncharted territory with no limits; in other words, deep penetration attacks using AI are coming...

  • dev127dev127 Member
    edited 5:34AM

    @HostDZire said:

    @mehargags said:
    @HostDZire I requested Debian 13 Template for OS Reinstall via ticket #179938.

    @dev127 said:

    @mehargags said:
    @HostDZire I requested Debian 13 Template for OS Reinstall via ticket #179938.

    @HostDZire Debian 13 Template for OS Reinstall

    Hopefully tomorrow, we had debian 13 already but it has some issue.
    We will fix it and enable it.

    @HostDZire any update on this. i think debian 13 templete has issue with /boot/efi partion in /etc/fstab. incorrect uuid

  • edited 5:46AM

    @CloudHopper said:

    @QuenFea said:

    @CloudHopper said:

    @QuenFea said:
    As this was all an unforeseen circumstance, who could have imagined that, following a data loss, they would now be implementing a policy of randomly changing IP addresses?

    This will be my 3rd IP renumbering of one of my VMs so far this year. It's the first data loss I've had in a while, but that also happens a lot with LET hosts. In fact, Hostdzire's NL offer explicitly said that the host server didn't have RAID configured so data loss was a very foreseeable outcome.

    If you read through all my previous replies, you’ll see I stated from the start that data loss resulting from a security breach is entirely acceptable; as consumers, we should always maintain our own backups rather than relying on the provider.
    My main issue has always been Hostdzire’s decision to simply reassign random IPs in order to speed up recovery. Keep in mind that the context here was a server reconfiguration necessitated by a breach—not a data center migration or an IP re-addressing scheme.
    To expedite recovery, they could have easily assigned random IPs from a pool of unallocated subnets that existed prior to the breach, allowing customers to manually switch back to their original IPs later if needed. Unfortunately, that isn't the path they chose. Perhaps it was a cost consideration, a lack of sufficient unallocated subnets to support that approach, or some other factor.
    1. The affected service was located in India, not the Netherlands.
    2. I don't care about the data loss; my only concern is the original IP address.
    3. They have decades of experience, yet the emergency response plan implemented following this breach struck me as chaotic—more like a series of ad-hoc decisions.

    Regardless, what they need to do now is promptly analyze and fully disclose the cause of the incident and the current remediation steps, while also preparing contingency plans for various scenarios. If possible, they should also adjust pricing to reflect current hardware market rates—doubling, tripling, or even quadrupling prices. Only with sufficient profit margins can they realistically aim for stability, security, and efficiency.

    I think your just shopping in the wrong window. This is "Low End Talk" and things are supposed to be cheap, with providers cutting corners to keep prices down. Servers here are cheap, but you have to accept occasional IP renumbering, noisy neighbours, inconvenient maintenance windows, less than perfect uptime and possible data loss as part of the package.

    If you want to pay double, triple or even quadruple the price then there's established providers that serve that market, but they don't advertise here. The truth is you should be angry at yourself for putting a production workload on a Low End server without a proper disaster and recovery plan because there servers are cheap for a reason.

    No system is secure. The age of AI has made that easy; I think VPS servers will fall out of favour if these vulnerabilities keep cropping up – even a dedicated server isn’t safe if they manage to breach the router.

  • VoidVoid Member

    @ScreenReader said:

    @rpqu said:

    @ScreenReader said:
    for telegram i couldn't recommend, my account got whacked after storing around 2TB of encrypted data (which is deserved).

    You probably send it too fast

    nope, 2TB is accumulation in around 1 year timeframe. i have a track on it on google sheet (for every timestamp when a backup event is made). i did this with reasoning "is there a limit on this chat app?" and find out. i probably could do better if i managed to script to keep last n backup only (as it's not an incrimental backup), not just perpetually sending more files on daily basis.

    @Void said:

    [@ScreenReader said]
    for telegram i couldn't recommend, my account got whacked after storing around 2TB of encrypted data (which is deserved).

    Did you have telegram premium by any chance?

    i don't think telegram premium is a thing yet back then, it's around 2021-2022 ish. it's also before i knew telegram-as-filesystem too but nowadays i don't bother with it anymore.

    if you're willing to pay i think it's better to pay some LET host instead, cheap storage like hostbrr as one of your mirror makes life easier. telegram premium cost $4.99 a month, boy that's a lot of money if the usage is only for storage.

    TG premium is like $20/yr in my country (IN) and while it doesn’t guarantee account bans, it offers some resilience and also increases the maximum individual file size to 4GB and better transfer speeds too. I have a few TBs of stuff stored that way and couldn’t complain.

  • tzulitzuli Member

    @freelanceonline said: No system is secure. The age of AI has made that easy; I think VPS servers will fall out of favour if these vulnerabilities keep cropping up – even a dedicated server isn’t safe if they manage to breach the router.

    Where do you think everything will move to? The cloud? I've heard clouds are safe

    Perhaps carrier pigeons will make a comeback

  • LEmeINalrLEmeINalr Member

    @Void said: TG premium is like $20/yr in my country (IN) and while it doesn’t guarantee account bans, it offers some resilience and also increases the maximum individual file size to 4GB and better transfer speeds too. I have a few TBs of stuff stored that way and couldn’t complain.

    While I can attest to this having stored lots of ahem encrypted linux ISOs ahem, there is no evidence to support the fact that it makes our account more resilient to being limited. Then again Telegram wasn't supposed to be a filehost alternative in the first place.

    If the backups are crucial to our work then I would honestly suggest its better to stick to a verified host and follow 3-2-1 policy or 2-2-1.

  • @QuenFea said:
    You seem to insist things must stay exactly as they are—just because this is LET? Providers like Hetzner, OVH, Netcup, and Host-c can raise prices. Yet you think Hostdzire isn’t allowed to do the same.

    Anyone can raise their prices, but maybe look at the reaction from LET users to some of those price rises. Especially with Host-C, who raised their prices by 200%+ like you recommend. Providers can charge whatever they want, and consumers can choose whether or not to pay the new prices. But none of the providers you mentioned their introduced any qualitative improvements with their service, which you also seem to expect from Hostdzire if/when they raise their prices so those aren't great examples.

  • @jsg said:

    @CloudHopper said:

    @jsg said:
    where is the community for those expensive or even super-expensive providers, where can I get reliable information?

    https://repost.aws/

    Thanks, but I meant 3rd party fora (as opposed to a provider's), neutral, with concrete and credible experience by actual users (as opposed to support, KB, etc.) or in other words, a "HET", i.e. like LET but for "high-end" products.

    The word "forum" has been absorbed into the English language, so please spare us your cheap attempts to look cultured and educated by using the Latin plural "fora" rather than the grammatically correct "forums". 🙄

    But as web "forums" are effectively dead in 2026, the closest you'll find that matches your criteria is probably Web Hosting Talk, (unless you accept that Reddit is a collection of "forums" because then you have all sorts of communities dedicated to high-end hosting).

  • @freelanceonline said: freelanceonline Miembro

    @tzuli said:

    @freelanceonline said: No system is secure. The age of AI has made that easy; I think VPS servers will fall out of favour if these vulnerabilities keep cropping up – even a dedicated server isn’t safe if they manage to breach the router.

    Where do you think everything will move to? The cloud? I've heard clouds are safe

    Perhaps carrier pigeons will make a comeback

    Cloud services are expensive, and you are subject to whatever pricing algorithm they decide to use. If they make a mistake—which has happened before—you still get charged based on whatever they calculate. What’s more, if you’re hit by a DDoS attack designed to drain your wallet, that bill could rise without your consent.

    For me, the best option will continue to be using my own computer for backups. I have nearly 2 TB of storage available (unfortunately, it’s NVMe M.2 storage; fortunately, my backup is less than 200 GB), and I don’t store that much data anyway. On top of that, my computer runs 24 hours a day, 7 days a week.

    I plan to configure the backup system so that it will update automatically only when both the new data and the previous backup can be read correctly, and when there isn’t a significant percentage difference in size between them. Otherwise, a password will be required before the backup can be updated.

    This should help protect me from ransomware or anything else that might wipe my drive and then cause the backup process to automatically wipe the backup as well.

  • dev127dev127 Member

    @HostDZire said:

    @mehargags said:
    @HostDZire I requested Debian 13 Template for OS Reinstall via ticket #179938.

    @dev127 said:

    @mehargags said:
    @HostDZire I requested Debian 13 Template for OS Reinstall via ticket #179938.

    @HostDZire Debian 13 Template for OS Reinstall

    Hopefully tomorrow, we had debian 13 already but it has some issue.
    We will fix it and enable it.

    @HostDZire any update sir

  • tzulitzuli Member

    @freelanceonline said: I plan to configure the backup system so that it will update automatically only when both the new data and the previous backup can be read correctly, and when there isn’t a significant percentage difference in size between them. Otherwise, a password will be required before the backup can be updated.

    A lot of this seems bizarre... But I just want to point out that if an attacker could infect/encrypt the "new data", then they could also infect/encrypt the previous backup. Unless you have some sort of gap that you didn't mention. Encrypted data can be re-encrypted (think: matryoshka dolls)

  • @dev127 just use reinstall script, faster and safer.

    Thanked by 1JohnnySac
  • @tzuli said:

    @freelanceonline said: I plan to configure the backup system so that it will update automatically only when both the new data and the previous backup can be read correctly, and when there isn’t a significant percentage difference in size between them. Otherwise, a password will be required before the backup can be updated.

    A lot of this seems bizarre... But I just want to point out that if an attacker could infect/encrypt the "new data", then they could also infect/encrypt the previous backup. Unless you have some sort of gap that you didn't mention. Encrypted data can be re-encrypted (think: matryoshka dolls)

    It depends on the storage system you use. If it supports versioning similar to GitHub, you could restore a specific file to almost any previous point in time.

    The backup could also keep a record of the permissions each file originally had, while the backup copies themselves would be stored as read-only, with no write or execution permissions. The data could then be sent directly to cold storage and heavily compressed.

    This could be combined with an AI-based monitoring system that only alerts you when it detects something suspicious, such as a Trojan hiding a remote exploit payload among the files so it can be executed later.

  • arab28arab28 Member

    My server is up and running again. Thank you @HostDZire

  • HostDZireHostDZire Patron Provider, Veteran

    @dev127 said:

    @HostDZire said:

    @mehargags said:
    @HostDZire I requested Debian 13 Template for OS Reinstall via ticket #179938.

    @dev127 said:

    @mehargags said:
    @HostDZire I requested Debian 13 Template for OS Reinstall via ticket #179938.

    @HostDZire Debian 13 Template for OS Reinstall

    Hopefully tomorrow, we had debian 13 already but it has some issue.
    We will fix it and enable it.

    @HostDZire any update sir

    Sorry but Debian 13 will take time, if you want you can open ticket for manual ISO mount.
    Or you can use this for now.
    https://github.com/bin456789/reinstall/blob/main/README.en.md

Sign In or Register to comment.