Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Home β€Ί Offers
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

πŸ‡ΊπŸ‡Έ USA KVM VPS β€” Kansas & Texas | Starting at $5/mo Unmetered BW

AK_KWHAK_KWH Member, Patron Provider

KhanWebHost offers affordable KVM VPS Servers in the USA, with locations in Kansas and Texas. Our VPS plans are designed for developers, websites, applications, VPNs, game servers, and other workloads requiring full KVM virtualization.

We've been providing hosting services since 2016, offering VPS, dedicated servers, web hosting, and related infrastructure services.

For the LowEndTalk community, we're offering special recurring pricing on selected USA KVM VPS plans.

☁ 2 GB USA KVM VPS β€” $5/mo or $60/year

  • 40 GB SSD Storage
  • Unlimited Bandwidth
  • 2 GB RAM
  • 2 CPU Cores
  • 1 IPv4
  • IPv6 Included
  • KVM Virtualization
  • Location: Kansas or Texas, USA
  • Instant VPS Deployment
  • DDoS Protection
  • 24/7 Support

Order: Order USA VPS


☁ 3 GB USA KVM VPS β€” $7.50/mo or $90/year

  • 60 GB SSD Storage
  • Unlimited Bandwidth
  • 3 GB RAM
  • 2 CPU Cores
  • 1 IPv4
  • IPv6 Included
  • KVM Virtualization
  • Location: Kansas or Texas, USA
  • Instant VPS Deployment
  • DDoS Protection
  • 24/7 Support

Order: Order USA VPS


☁ 4 GB USA KVM VPS β€” $10/mo or $120/year

  • 80 GB SSD Storage
  • Unlimited Bandwidth
  • 4 GB RAM
  • 4 CPU Cores
  • 1 IPv4
  • IPv6 Included
  • KVM Virtualization
  • Location: Kansas or Texas, USA
  • Instant VPS Deployment
  • DDoS Protection
  • 24/7 Support

Order: Order USA VPS


🎁 LowEndTalk Special Offer

The prices listed above are recurring prices and apply to eligible VPS plans.

Locations: Kansas, USA & Texas, USA


βš™οΈ VPS Features

  • KVM Virtualization
  • SSD Storage
  • Unlimited Bandwidth
  • IPv4 Included
  • IPv6 Included
  • DDoS Protection
  • Custom ISO Support
  • OS Reinstallation
  • Instant Provisioning
  • Multiple Linux Distributions
  • Windows Server available where supported
  • 24/7 Support
  • Additional IPv4 available
  • RDNS/PTR Support

πŸ’» Available Operating Systems

Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS and other supported Linux distributions.

Custom ISO installation is also supported where applicable.


❓ Frequently Asked Questions

1. Do you support RDNS/PTR?
Yes.

2. Can I install a custom ISO?
Yes, custom ISO installation is supported.

3. Can I reinstall my VPS?
Yes, VPS reinstallations are supported.

4. Is IPv6 included?
Yes, IPv6 is included with the VPS.

5. Are additional IPv4 addresses available?
Yes, subject to availability and applicable requirements.

6. Where are the VPS servers located?
We currently offer Kansas and Texas, USA locations.

7. Is DDoS protection included?
Yes, DDoS protection is included.

8. Do you provide support?
Yes, support is available 24/7.


πŸ’³ Payment Methods

We accept multiple payment methods, including:

  • PayPal
  • Credit/Debit Cards
  • Cryptocurrency
  • Local payment methods where available

🏒 About KhanWebHost

KhanWebHost has been providing hosting services since 2016. We provide VPS, dedicated servers, web hosting, and infrastructure services to customers worldwide.

Our goal is to provide affordable infrastructure while maintaining reliable service and responsive customer support.

If you have any questions about the offer, feel free to reply to this thread or contact our support team.

Discord Channel: https://discord.gg/hfMuNwv

Thanked by 1IonutNM

Comments

  • First. GLWS!

    Thanked by 1AK_KWH
  • GLWS!

    Thanked by 1AK_KWH
  • You mention "Unlimited Bandwidth," but when I check the control panel, the bandwidth is 1TB?

  • AK_KWHAK_KWH Member, Patron Provider

    @tnc6666 said:

    You mention "Unlimited Bandwidth," but when I check the control panel, the bandwidth is 1TB?

    it will not be suspended on over usage dont worry or raise tikcet will increase it

  • AK_KWHAK_KWH Member, Patron Provider
    ⚠️ BETA TESTING β€” NAT VPS Platform Migration
    This service is currently part of our BETA testing program for our NAT VPS infrastructure. We are migrating our existing NAT VPS platform from OpenVZ 7 to our in-house built LXC-based virtualization platform and management panel.

    During this testing phase, the service may experience changes, interruptions, resets, or other issues as we continue testing and improving the new platform. The service may also be terminated at any time without prior notice or announcement.

    Please do not use this service for production or critical workloads.
    • 1 CPU Core β€” Fair Usage
    • 256 MB RAM
    • 5 GB NVMe Disk Space
    • 500 GB Bandwidth @ 10 Gbps
    • 1 NAT IPv4
    • 1 Dedicated IPv6
    • 20 Pre-Allowed Ports

    Order Now 0.00$

  • itzsenuitzsenu Member
    edited September 2

    @AK_KWH said: ⚠️ BETA TESTING β€” NAT VPS Platform Migration
    This service is currently part of our BETA testing program for our NAT VPS infrastructure. We are migrating our existing NAT VPS platform from OpenVZ 7 to our in-house built LXC-based virtualization platform and management panel.

    there's an issue with the email template.

    YABS:

    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    #              Yet-Another-Bench-Script              #
    #                     v2026-07-24                    #
    # https://github.com/masonr/yet-another-bench-script #
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    
    Wed Sep  2 01:25:50 PM UTC 2026
    
    Basic System Information:
    ---------------------------------
    Uptime     : 0 days, 0 hours, 2 minutes
    Processor  : AMD EPYC 7543 32-Core Processor
    CPU cores  : 1 @ 2799.998 MHz
    AES-NI     : βœ” Enabled
    VM-x/AMD-V : βœ” Enabled
    RAM        : 244.1 MiB
    Swap       : 0.0 KiB
    Disk       : 4.8 GiB
    Distro     : Debian GNU/Linux 12 (bookworm)
    Kernel     : 5.15.0-190-generic
    VM Type    : LXC
    IPv4/IPv6  : βœ” Online / ❌ Offline
    
    IPv4 Network Information:
    ---------------------------------
    ISP        : Philip Fjaera trading as PFWeb Solutions
    ASN        : AS214902 Philip Fjaera trading as PFWeb Solutions
    Host       : GHOSTnet GmbH
    Location   : Bad Soden am Taunus, Hesse (HE)
    Country    : Germany
    Warning: Could not parse free space format for /: ''
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/lxc-lvm/containers_akmvl9ij--8mi1fsld):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 53.18 MB/s   (12.9k) | 601.64 MB/s   (9.1k)
    Write      | 53.26 MB/s   (13.0k) | 604.80 MB/s   (9.2k)
    Total      | 106.45 MB/s  (25.9k) | 1.20 GB/s    (18.4k)
               |                      |
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 1.36 GB/s     (2.5k) | 1.55 GB/s     (1.4k)
    Write      | 1.43 GB/s     (2.7k) | 1.65 GB/s     (1.5k)
    Total      | 2.79 GB/s     (5.3k) | 3.20 GB/s     (3.0k)
    
    iperf3 Network Speed Tests (IPv4):
    ---------------------------------
    Provider        | Location (Link)           | Send Speed      | Recv Speed      | Ping
    -----           | -----                     | ----            | ----            | ----
    Clouvider       | London, UK (10G)          | 4.59 Gbits/sec  | 2.94 Gbits/sec  | 14.0 ms
    Eranium         | Amsterdam, NL (100G)      | 5.27 Gbits/sec  | 6.96 Gbits/sec  | 7.79 ms
    Uztelecom       | Tashkent, UZ (10G)        | 1.71 Gbits/sec  | 1.28 Gbits/sec  | 89.2 ms
    Leaseweb        | Singapore, SG (10G)       | 1.07 Gbits/sec  | 844 Mbits/sec   | 158 ms
    Clouvider       | Los Angeles, CA, US (10G) | 1.25 Gbits/sec  | 925 Mbits/sec   | 141 ms
    Leaseweb        | NYC, NY, US (10G)         | 2.07 Gbits/sec  | 1.83 Gbits/sec  | 84.2 ms
    Edgoo           | Sao Paulo, BR (1G)        | 1.05 Gbits/sec  | busy            | 205 ms
    

    EDIT : My bad :smile:

  • AK_KWHAK_KWH Member, Patron Provider

    @itzsenu said:

    @AK_KWH said: ⚠️ BETA TESTING β€” NAT VPS Platform Migration
    This service is currently part of our BETA testing program for our NAT VPS infrastructure. We are migrating our existing NAT VPS platform from OpenVZ 7 to our in-house built LXC-based virtualization platform and management panel.

    there's an issue with the email template.

    YABS:

    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    #              Yet-Another-Bench-Script              #
    #                     v2026-07-24                    #
    # https://github.com/masonr/yet-another-bench-script #
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    
    Wed Sep  2 01:25:50 PM UTC 2026
    
    Basic System Information:
    ---------------------------------
    Uptime     : 0 days, 0 hours, 2 minutes
    Processor  : AMD EPYC 7543 32-Core Processor
    CPU cores  : 1 @ 2799.998 MHz
    AES-NI     : βœ” Enabled
    VM-x/AMD-V : βœ” Enabled
    RAM        : 244.1 MiB
    Swap       : 0.0 KiB
    Disk       : 4.8 GiB
    Distro     : Debian GNU/Linux 12 (bookworm)
    Kernel     : 5.15.0-190-generic
    VM Type    : LXC
    IPv4/IPv6  : βœ” Online / ❌ Offline
    
    IPv4 Network Information:
    ---------------------------------
    ISP        : Philip Fjaera trading as PFWeb Solutions
    ASN        : AS214902 Philip Fjaera trading as PFWeb Solutions
    Host       : GHOSTnet GmbH
    Location   : Bad Soden am Taunus, Hesse (HE)
    Country    : Germany
    Warning: Could not parse free space format for /: ''
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/lxc-lvm/containers_akmvl9ij--8mi1fsld):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 53.18 MB/s   (12.9k) | 601.64 MB/s   (9.1k)
    Write      | 53.26 MB/s   (13.0k) | 604.80 MB/s   (9.2k)
    Total      | 106.45 MB/s  (25.9k) | 1.20 GB/s    (18.4k)
               |                      |
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 1.36 GB/s     (2.5k) | 1.55 GB/s     (1.4k)
    Write      | 1.43 GB/s     (2.7k) | 1.65 GB/s     (1.5k)
    Total      | 2.79 GB/s     (5.3k) | 3.20 GB/s     (3.0k)
    
    iperf3 Network Speed Tests (IPv4):
    ---------------------------------
    Provider        | Location (Link)           | Send Speed      | Recv Speed      | Ping
    -----           | -----                     | ----            | ----            | ----
    Clouvider       | London, UK (10G)          | 4.59 Gbits/sec  | 2.94 Gbits/sec  | 14.0 ms
    Eranium         | Amsterdam, NL (100G)      | 5.27 Gbits/sec  | 6.96 Gbits/sec  | 7.79 ms
    Uztelecom       | Tashkent, UZ (10G)        | 1.71 Gbits/sec  | 1.28 Gbits/sec  | 89.2 ms
    Leaseweb        | Singapore, SG (10G)       | 1.07 Gbits/sec  | 844 Mbits/sec   | 158 ms
    Clouvider       | Los Angeles, CA, US (10G) | 1.25 Gbits/sec  | 925 Mbits/sec   | 141 ms
    Leaseweb        | NYC, NY, US (10G)         | 2.07 Gbits/sec  | 1.83 Gbits/sec  | 84.2 ms
    Edgoo           | Sao Paulo, BR (1G)        | 1.05 Gbits/sec  | busy            | 205 ms
    

    EDIT : My bad :smile:

    there is no issue with email tempalte cheapkvm is also our sister company

    can you please check the IPv6 is its working now ?

  • @AK_KWH said: can you please check the IPv6 is its working now ?

    Its working

    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    #              Yet-Another-Bench-Script              #
    #                     v2026-07-24                    #
    # https://github.com/masonr/yet-another-bench-script #
    # ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## ## #
    
    Wed Sep  2 06:25:32 PM UTC 2026
    
    Basic System Information:
    ---------------------------------
    Uptime     : 0 days, 5 hours, 2 minutes
    Processor  : AMD EPYC 7543 32-Core Processor
    CPU cores  : 1 @ 2799.998 MHz
    AES-NI     : βœ” Enabled
    VM-x/AMD-V : βœ” Enabled
    RAM        : 244.1 MiB
    Swap       : 0.0 KiB
    Disk       : 4.8 GiB
    Distro     : Debian GNU/Linux 12 (bookworm)
    Kernel     : 5.15.0-190-generic
    VM Type    : LXC
    IPv4/IPv6  : βœ” Online / βœ” Online
    
    IPv6 Network Information:
    ---------------------------------
    ISP        : dataforest GmbH
    ASN        : AS58212 dataforest GmbH
    Host       : dataforest GmbH
    Location   : Frankfurt am Main, Hesse (HE)
    Country    : Germany
    Warning: Could not parse free space format for /: ''
    
    fio Disk Speed Tests (Mixed R/W 50/50) (Partition /dev/lxc-lvm/containers_akmvl9ij--8mi1fsld):
    ---------------------------------
    Block Size | 4k            (IOPS) | 64k           (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 55.72 MB/s   (13.6k) | 608.47 MB/s   (9.2k)
    Write      | 55.83 MB/s   (13.6k) | 611.68 MB/s   (9.3k)
    Total      | 111.55 MB/s  (27.2k) | 1.22 GB/s    (18.6k)
               |                      |
    Block Size | 512k          (IOPS) | 1m            (IOPS)
      ------   | ---            ----  | ----           ----
    Read       | 1.24 GB/s     (2.3k) | 1.22 GB/s     (1.1k)
    Write      | 1.31 GB/s     (2.5k) | 1.31 GB/s     (1.2k)
    Total      | 2.55 GB/s     (4.8k) | 2.54 GB/s     (2.4k)
    
    iperf3 Network Speed Tests (IPv4):
    ---------------------------------
    Provider        | Location (Link)           | Send Speed      | Recv Speed      | Ping
    -----           | -----                     | ----            | ----            | ----
    Clouvider       | London, UK (10G)          | 2.92 Gbits/sec  | 1.51 Gbits/sec  | 13.9 ms
    Eranium         | Amsterdam, NL (100G)      | 2.55 Gbits/sec  | 5.19 Gbits/sec  | 7.76 ms
    Uztelecom       | Tashkent, UZ (10G)        | 937 Mbits/sec   | 784 Mbits/sec   | 90.1 ms
    Leaseweb        | Singapore, SG (10G)       | 1.02 Gbits/sec  | 300 Mbits/sec   | 158 ms
    Clouvider       | Los Angeles, CA, US (10G) | 981 Mbits/sec   | 554 Mbits/sec   | 137 ms
    Leaseweb        | NYC, NY, US (10G)         | 1.38 Gbits/sec  | 351 Mbits/sec   | 85.5 ms
    Edgoo           | Sao Paulo, BR (1G)        | busy            | 360 Mbits/sec   | 205 ms
    
    iperf3 Network Speed Tests (IPv6):
    ---------------------------------
    Provider        | Location (Link)           | Send Speed      | Recv Speed      | Ping
    -----           | -----                     | ----            | ----            | ----
    Clouvider       | London, UK (10G)          | 1.96 Gbits/sec  | 1.48 Gbits/sec  | 13.2 ms
    Eranium         | Amsterdam, NL (100G)      | 2.86 Gbits/sec  | 6.46 Gbits/sec  | 7.99 ms
    Uztelecom       | Tashkent, UZ (10G)        | 1.10 Gbits/sec  | 526 Mbits/sec   | 99.4 ms
    Leaseweb        | Singapore, SG (10G)       | 623 Mbits/sec   | 235 Mbits/sec   | 254 ms
    Clouvider       | Los Angeles, CA, US (10G) | 954 Mbits/sec   | 514 Mbits/sec   | 138 ms
    Leaseweb        | NYC, NY, US (10G)         | 1.57 Gbits/sec  | 446 Mbits/sec   | 88.4 ms
    
  • i little tested ur system with my little hands @AK_KWH. some things like tun/tap or unlimited cpu can be intentional, but there are several things you should fix before putting untrusted customers on it. the biggest issue is the container has basically all 41 capabilities, including CAP_SYS_ADMIN, CAP_SYS_PTRACE, CAP_NET_ADMIN, CAP_NET_RAW, CAP_SYS_MODULE, CAP_BPF, and CAP_DAC_READ_SEARCH. CAP_SYS_ADMIN is a serious problem because the container can do mount operations. tmpfs, proc, bind mounts, mount propagation, all worked. mount --make-rshared / also worked. the host is currently rprivate, so the mount i tested didn't escape to the host, but you shouldn't depend on that staying true. apparmor is unconfined too. seccomp blocks some dangerous syscalls, which helps, but you shouldn't rely on seccomp alone while giving the container this much capability. CAP_SYS_PTRACE is also way too permissive. i was able to ptrace container pid 1 in the later test, even more permissive than the earlier test. i'd check what changed between those two. networking is the same. AF_PACKET works, so packet capture and arp spoofing work directly. if raw l2 access isn't something you want to offer, drop NET_RAW and NET_ADMIN. the container can also create tun/tap interfaces. fine if vpn support is intentional, but customers can build tunnels and route around your nat/accounting controls. decide if that's actually what you want. check port isolation. the container can bind 0.0.0.0:80, 443, 9000, etc. i didnt prove an external host port hijack from this, but your nat/dnat setup needs to make sure one tenant can't step on host or other tenant ports. /sys/block leaks information too, the container can see other tenants' lvm/container names and disk details. block device access itself was blocked, which is good, but the metadata shouldnt be exposed either. cpu and io are wide open too, cpu.max is max and io.max is empty. if fair share hosting is the intended model, that's your call, but right now it's straight up noisy neighbor risk.

    idk if this is a vibe coded system or not, but idk how to help you fix this. maybe ask someone who knows more about container security. if there are any mistakes, correct me. still idk about the forum ones, maybe @rpqu would know, cuz he's always replying :hushed:. I thinks its easy to break the host and gain access

    i didnt actually try harder to break out to the host. i only did these tests because you said this was still the testing phase, and all the vpses are for testing purposes.

  • AK_KWHAK_KWH Member, Patron Provider

    @itzsenu said:

    i little tested ur system with my little hands @AK_KWH. some things like tun/tap or unlimited cpu can be intentional, but there are several things you should fix before putting untrusted customers on it. the biggest issue is the container has basically all 41 capabilities, including CAP_SYS_ADMIN, CAP_SYS_PTRACE, CAP_NET_ADMIN, CAP_NET_RAW, CAP_SYS_MODULE, CAP_BPF, and CAP_DAC_READ_SEARCH. CAP_SYS_ADMIN is a serious problem because the container can do mount operations. tmpfs, proc, bind mounts, mount propagation, all worked. mount --make-rshared / also worked. the host is currently rprivate, so the mount i tested didn't escape to the host, but you shouldn't depend on that staying true. apparmor is unconfined too. seccomp blocks some dangerous syscalls, which helps, but you shouldn't rely on seccomp alone while giving the container this much capability. CAP_SYS_PTRACE is also way too permissive. i was able to ptrace container pid 1 in the later test, even more permissive than the earlier test. i'd check what changed between those two. networking is the same. AF_PACKET works, so packet capture and arp spoofing work directly. if raw l2 access isn't something you want to offer, drop NET_RAW and NET_ADMIN. the container can also create tun/tap interfaces. fine if vpn support is intentional, but customers can build tunnels and route around your nat/accounting controls. decide if that's actually what you want. check port isolation. the container can bind 0.0.0.0:80, 443, 9000, etc. i didnt prove an external host port hijack from this, but your nat/dnat setup needs to make sure one tenant can't step on host or other tenant ports. /sys/block leaks information too, the container can see other tenants' lvm/container names and disk details. block device access itself was blocked, which is good, but the metadata shouldnt be exposed either. cpu and io are wide open too, cpu.max is max and io.max is empty. if fair share hosting is the intended model, that's your call, but right now it's straight up noisy neighbor risk.

    idk if this is a vibe coded system or not, but idk how to help you fix this. maybe ask someone who knows more about container security. if there are any mistakes, correct me. still idk about the forum ones, maybe @rpqu would know, cuz he's always replying :hushed:. I thinks its easy to break the host and gain access

    i didnt actually try harder to break out to the host. i only did these tests because you said this was still the testing phase, and all the vpses are for testing purposes.

    The containers were already unprivileged, with root mapped to a unique host UID range for each VPS. The unconfined status visible inside the container referred to its inner AppArmor namespace; the host confirmed that the outer LXD AppArmor profile was running in enforce mode.

    We have nevertheless strengthened the configuration by explicitly enabling LXD’s default seccomp deny list and removing unnecessary capabilities, including SYS_MODULE, SYS_RAWIO, SYS_BOOT, SYS_TIME, MAC_ADMIN, MAC_OVERRIDE, SYSLOG, ** **AUDIT_CONTROL, AUDIT_READ, PERFMON, BPF, and CHECKPOINT_RESTORE. The remaining capabilities are restricted to the unprivileged container namespace and are required for normal VPS administration, systemd, networking, TUN/TAP, and WireGuard support.

    Access to /dev/lxd is disabled, every VPS uses an isolated UID/GID mapping, MAC filtering and port isolation are enabled.

    Your report helped us identify areas where the effective protections needed to be made more explicit and where additional defense-in-depth controls were appropriate. Thank you again for taking the time to test the platform responsibly.

  • rpqurpqu Member
    edited September 3

    @itzsenu said:

    idk if this is a vibe coded system or not, but idk how to help you fix this. maybe ask someone who knows more about container security. if there are any mistakes, correct me. still idk about the forum ones, maybe @rpqu would know, cuz he's always replying :hushed:. I thinks its easy to break the host and gain access

    i didnt actually try harder to break out to the host. i only did these tests because you said this was still the testing phase, and all the vpses are for testing purposes.

    I'll say that those permissions likely introduce more attack surface, even on unprivileged state. And as @forest says, many host (in and outside LET) allows traffic snooping because the networking is poorly implemented. So, there's gonna be lots of tests :s
    Hopefully @AK_KWH could hardened the system and get 3rd party professional pentest.

    Thanked by 1AK_KWH
  • @rpqu said: I'll say that those permissions likely introduce more attack surface, even on unprivileged state. And as @forest says, many host (in and outside LET) allows traffic snooping because the networking is poorly implemented. So, there's gonna be lots of tests :s

    It definitely does increase attack surface, but that's a price you have to pay with containers. It doesn't directly allow compromising the host, but there are a lot of vulnerabilities that end up being exploitable from within containers.

    Thanked by 1rpqu
Sign In or Register to comment.