New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Comments
Just got another three false-positive warnings from JustHost. Is it acceptable to block outgoing TCP/80 and TCP/443 for Globalping so it can at least still do other types of work, or would it be better for me to just uninstall it?
Personally, at that point I wouldn't bother running it anymore. I would only do it if it was possible to do on Globalping's side, like having probes announce what types of measurements they want to allow, but it is not.
@antonpa Yet again I had three false-positive reports resulting in service restriction, and I feel like I'm being ignored. This has been going on for multiple threads now. We were told we could run Globalping, but we are repeatedly being suspended for non-malicious activities that are allowed within your ToS.
Please answer us simply: Is Globalping no longer allowed?
@angstrom Is there anything that can be done with a provider that is ignoring customers repeatedly? Even just asking them to look into this issue would be helpful, because they are taking actions not covered by their ToS and suspending for actions they have said were allowed.
Well, they finally replied:
Apparently, after saying Globalping is allowed until the very last minute when one more report causes permanent suspension, they tell you to remove it. That is extremely dishonest behavior.
cc @zGato
@forest, @zGato — thank you for your patience, and sorry for the delay.
Questions about specific software on a specific service are handled in a ticket, per service, where the team can see the actual VM. If a service is restricted, reply to the ticket with your explanation — each case is reviewed individually and we'll do our best to restore normal operation.
@zGato — send me the service ID for your MOW1 service and the ticket number for the Zagreb → Tirana move, and I'll look into both personally.
I did reply with an explanation and asked many times if it was allowed, but in tickets I was never answered. I was only now told to uninstall Globalping but I was also threatened that another (even false) report would cause permanent blocking.
I would like your confirmation whether I am allowed to run:
And whether or not I will get permanently blocked due to false-positive reports.
Can you please answer that without only saying that you review tickets? I need a human to reply.
The lack of real communication is harming your reputation on LET.
Why? It's applicable to everyone who wants to run it on your servers.
Globalping's website explains what it is: https://globalping.io/about-us
Just give a yes or a no, it's as simple as that.
While we're working to address the core of the issue with GP probes, like /.env requests I wanted to note a few things:
Can someone explain how this abuse check is even triggered? The VM provider MITMs the traffic between the VM running the probe and the internet to detect such requests?
Understanding the implementation of the block would be helpful
LOL, pulling the lever
They use AbuseIPDB reports. For the rest of the abuse reports, they just check destination IP & port for each connection and track how many you do in X.
Feedback is ignored, by you here in the past few threads, and by your own support:

The feedback is forwarded to their /dev/null team, they handle everything related to that
It's absolutely overzealous. Unfortunately for some strange reason, a large number of providers and their LIRs have started counting individual AbuseIPDB reports as serious and I have no idea why. I suspect some popular IP reputation database has started adding IPs with single reports or something.
They point the probe to a domain which runs a WAF that automatically submits any IP that connects to certain "restricted" paths that are commonly accessed maliciously, and suddenly every single probe that participated in that query gets an AbuseIPDB entry. So clearly someone is intentionally trying to fuck with Globalping volunteers.
If you go to
retrokitty.net/.envfor example, it'll show a message that you've been blocked, and your IP will shortly appear on AbuseIPDB (don't actually go to that URL). That website says in its privacy policy "We use Wordfence to help protect this site from malicious traffic and unauthorised access. Wordfence is a security plugin provided by Defiant, Inc.".I opened it before reading

Now your IP is probably going to be public on AbuseIPDB.
unfortunately my experience with this provider is terribly bad.
one of my vps just became fully unusable cause of heavy overselling or just cause of other issues with their hardware.
when im talked with support about situation - they're said that all of their vps is on fair use policy and on my vps everything is works as it should be.
only one option is that they offered to me - move my vps to another location with erasing all my data. what a great offer, huh!
Here is combined screenshot with how fair use policies on justhosting looks like according to their support staff (open image on new tab for enlarge if you're interested):

Steal time on almost idling machine: 30+
VPS reboot time: almost one hour.
Network speed: 3mbits upload and 6mbits download.
This is prepaid for 6 months vps and thank god this is last month of billed period.
Im gonna to terminate all of my other services on this provider cause of zero quality customer treatment. Totally disappointed with them.
Bonus: awesome sysbench points. just fast as tetris gaming pad worth 4 bucks/mo vps.

but hey, at least it isn't suspended. win!!!!
Can you say which location are you currently in experiencing those issues?
It's pretty easy to migrate yourself without erasing data. Just copy your disk image somewhere, migrate the VPS to a new location with the same disk size, restore the disk image, then edit the network config from VNC.
If you need space to copy the disk image, I'd be happy to let you copy it to one of my servers (encrypted first of course) before the migration so you can retrieve it after the migration.
Here we go again, my CH VPS has been suspended. I won’t be renewing any of my VPS plans with them... especially with their "support". I’ll try to get a refund, perhaps they’ll show some mercy, but I’m not expecting much
.
What was the suspension reason? I assume another AbuseIPDB false positive?
@antonpa You're losing customers here. Please listen to us.
@forest, consider making the filter for false AbuseIPDB
Sadly won't stop @antonpa's service from incorrectly flagging everything.
I wonder if there's a way to get him to realize how these are false positives. You know, there are plenty of honeypots which auto-report the moment they see even a single SYN and don't wait for a handshake to complete. And there are a number of providers here who don't adhere to BCP38. How many prefixes does Baxet Group announce, again?
How about showing in real-time how it works? Make tools that could reproduce the false positive.
You could even demonstrate how a corrupt honeypot may be fatal.
Further, make a plug-in that works better than his current tooling
"And for my next trick, I will make 10k angry customers with auto-suspended services appear out of thin air!"
All joking aside, his broken system could easily be abused by a competitor to completely destroy his business in about 15 minutes, and he has no idea that he's setting that possibility up.
Well, you already got AS210464. So, it's feasible
That's right. It's a serious vulnerability, a simple turnkey to L7 DOS
@angstrom @FAT32 please understand the frustration
Not the only one I've got that doesn't filter.
LOL LMAO
I'll decide whether to stick with them when the next renewal comes up in... checks date 2031.
You'll think you last that long with all the abuse reports? 🤣