All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
πΊπΈ USA KVM VPS β Kansas & Texas | Starting at $5/mo Unmetered BW
KhanWebHost offers affordable KVM VPS Servers in the USA, with locations in Kansas and Texas. Our VPS plans are designed for developers, websites, applications, VPNs, game servers, and other workloads requiring full KVM virtualization.
We've been providing hosting services since 2016, offering VPS, dedicated servers, web hosting, and related infrastructure services.
For the LowEndTalk community, we're offering special recurring pricing on selected USA KVM VPS plans.
β 2 GB USA KVM VPS β $5/mo or $60/year
- 40 GB SSD Storage
- Unlimited Bandwidth
- 2 GB RAM
- 2 CPU Cores
- 1 IPv4
- IPv6 Included
- KVM Virtualization
- Location: Kansas or Texas, USA
- Instant VPS Deployment
- DDoS Protection
- 24/7 Support
Order: Order USA VPS
β 3 GB USA KVM VPS β $7.50/mo or $90/year
- 60 GB SSD Storage
- Unlimited Bandwidth
- 3 GB RAM
- 2 CPU Cores
- 1 IPv4
- IPv6 Included
- KVM Virtualization
- Location: Kansas or Texas, USA
- Instant VPS Deployment
- DDoS Protection
- 24/7 Support
Order: Order USA VPS
β 4 GB USA KVM VPS β $10/mo or $120/year
- 80 GB SSD Storage
- Unlimited Bandwidth
- 4 GB RAM
- 4 CPU Cores
- 1 IPv4
- IPv6 Included
- KVM Virtualization
- Location: Kansas or Texas, USA
- Instant VPS Deployment
- DDoS Protection
- 24/7 Support
Order: Order USA VPS
π LowEndTalk Special Offer
The prices listed above are recurring prices and apply to eligible VPS plans.
Locations: Kansas, USA & Texas, USA
βοΈ VPS Features
- KVM Virtualization
- SSD Storage
- Unlimited Bandwidth
- IPv4 Included
- IPv6 Included
- DDoS Protection
- Custom ISO Support
- OS Reinstallation
- Instant Provisioning
- Multiple Linux Distributions
- Windows Server available where supported
- 24/7 Support
- Additional IPv4 available
- RDNS/PTR Support
π» Available Operating Systems
Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS and other supported Linux distributions.
Custom ISO installation is also supported where applicable.
β Frequently Asked Questions
1. Do you support RDNS/PTR?
Yes.
2. Can I install a custom ISO?
Yes, custom ISO installation is supported.
3. Can I reinstall my VPS?
Yes, VPS reinstallations are supported.
4. Is IPv6 included?
Yes, IPv6 is included with the VPS.
5. Are additional IPv4 addresses available?
Yes, subject to availability and applicable requirements.
6. Where are the VPS servers located?
We currently offer Kansas and Texas, USA locations.
7. Is DDoS protection included?
Yes, DDoS protection is included.
8. Do you provide support?
Yes, support is available 24/7.
π³ Payment Methods
We accept multiple payment methods, including:
- PayPal
- Credit/Debit Cards
- Cryptocurrency
- Local payment methods where available
π’ About KhanWebHost
KhanWebHost has been providing hosting services since 2016. We provide VPS, dedicated servers, web hosting, and infrastructure services to customers worldwide.
Our goal is to provide affordable infrastructure while maintaining reliable service and responsive customer support.
If you have any questions about the offer, feel free to reply to this thread or contact our support team.
Discord Channel: https://discord.gg/hfMuNwv

Comments
First. GLWS!
GLWS!
You mention "Unlimited Bandwidth," but when I check the control panel, the bandwidth is 1TB?
it will not be suspended on over usage dont worry or raise tikcet will increase it
This service is currently part of our BETA testing program for our NAT VPS infrastructure. We are migrating our existing NAT VPS platform from OpenVZ 7 to our in-house built LXC-based virtualization platform and management panel.
During this testing phase, the service may experience changes, interruptions, resets, or other issues as we continue testing and improving the new platform. The service may also be terminated at any time without prior notice or announcement.
Please do not use this service for production or critical workloads.
Order Now 0.00$
there's an issue with the email template.

YABS:
EDIT : My bad
there is no issue with email tempalte cheapkvm is also our sister company
can you please check the IPv6 is its working now ?
Its working
i little tested ur system with my little hands @AK_KWH. some things like tun/tap or unlimited cpu can be intentional, but there are several things you should fix before putting untrusted customers on it. the biggest issue is the container has basically all 41 capabilities, including
CAP_SYS_ADMIN,CAP_SYS_PTRACE,CAP_NET_ADMIN,CAP_NET_RAW,CAP_SYS_MODULE,CAP_BPF, andCAP_DAC_READ_SEARCH.CAP_SYS_ADMINis a serious problem because the container can do mount operations. tmpfs, proc, bind mounts, mount propagation, all worked.mount --make-rshared /also worked. the host is currentlyrprivate, so the mount i tested didn't escape to the host, but you shouldn't depend on that staying true. apparmor isunconfinedtoo. seccomp blocks some dangerous syscalls, which helps, but you shouldn't rely on seccomp alone while giving the container this much capability.CAP_SYS_PTRACEis also way too permissive. i was able to ptrace container pid 1 in the later test, even more permissive than the earlier test. i'd check what changed between those two. networking is the same.AF_PACKETworks, so packet capture and arp spoofing work directly. if raw l2 access isn't something you want to offer, dropNET_RAWandNET_ADMIN. the container can also create tun/tap interfaces. fine if vpn support is intentional, but customers can build tunnels and route around your nat/accounting controls. decide if that's actually what you want. check port isolation. the container can bind0.0.0.0:80,443,9000, etc. i didnt prove an external host port hijack from this, but your nat/dnat setup needs to make sure one tenant can't step on host or other tenant ports./sys/blockleaks information too, the container can see other tenants' lvm/container names and disk details. block device access itself was blocked, which is good, but the metadata shouldnt be exposed either. cpu and io are wide open too,cpu.maxismaxandio.maxis empty. if fair share hosting is the intended model, that's your call, but right now it's straight up noisy neighbor risk.idk if this is a vibe coded system or not, but idk how to help you fix this. maybe ask someone who knows more about container security. if there are any mistakes, correct me. still idk about the forum ones, maybe @rpqu would know, cuz he's always replying
. I thinks its easy to break the host and gain access
i didnt actually try harder to break out to the host. i only did these tests because you said this was still the testing phase, and all the vpses are for testing purposes.
The containers were already unprivileged, with root mapped to a unique host UID range for each VPS. The unconfined status visible inside the container referred to its inner AppArmor namespace; the host confirmed that the outer LXD AppArmor profile was running in enforce mode.
We have nevertheless strengthened the configuration by explicitly enabling LXDβs default seccomp deny list and removing unnecessary capabilities, including SYS_MODULE, SYS_RAWIO, SYS_BOOT, SYS_TIME, MAC_ADMIN, MAC_OVERRIDE, SYSLOG, ** **AUDIT_CONTROL, AUDIT_READ, PERFMON, BPF, and CHECKPOINT_RESTORE. The remaining capabilities are restricted to the unprivileged container namespace and are required for normal VPS administration, systemd, networking, TUN/TAP, and WireGuard support.
Access to /dev/lxd is disabled, every VPS uses an isolated UID/GID mapping, MAC filtering and port isolation are enabled.
Your report helped us identify areas where the effective protections needed to be made more explicit and where additional defense-in-depth controls were appropriate. Thank you again for taking the time to test the platform responsibly.
I'll say that those permissions likely introduce more attack surface, even on unprivileged state. And as @forest says, many host (in and outside LET) allows traffic snooping because the networking is poorly implemented. So, there's gonna be lots of tests
Hopefully @AK_KWH could hardened the system and get 3rd party professional pentest.
It definitely does increase attack surface, but that's a price you have to pay with containers. It doesn't directly allow compromising the host, but there are a lot of vulnerabilities that end up being exploitable from within containers.