+ Reply to Thread
Page 1 of 2
1 2 LastLast
Results 1 to 15 of 16

Thread: OVH / kimsufi is one of the worst providers i've ever delt with

  1. #1

    OVH / kimsufi is one of the worst providers i've ever delt with

    Hello all.

    This is just a quick note to tell you to stay away from OVH / kimsufi.

    I've got a dedicated server with them that has recently suffered a few DDOS attacks. I initially e-mailed them and it took them over 7 days to implement their "DDOS protection" which basically rate limits the downstream of the server to 3k/s (if you are lucky) and didn't block any of the attacks. The attacks stopped and I asked them to remove this pathetic feature which again took them more than a week.

    Today another attack started and they sent me the following e-mail:

    Dear Sir or Madam,

    We had to conduct an urgent intervention on your dedicated server
    ksxxxx.kimsufi.com to block an attack. It looks like your dedicated server
    has a security fault or a malicious user has obtained access.

    We had to deactivate your server. Full re-installation of the
    server is needed due to the scale of the attack. Please
    contact our support if you need advice on necessary measures.

    You will find below the information about processes run and ports open on your server at the beginning of intervention

    ------- BEGINNING OF ADDITIONAL INFORMATION ABOUT ATTACK -------

    attack


    ------- END OF ADDITIONAL INFORMATION ABOUT ATTACK -------


    They then proceeded to reboot my server into "rescue mode" which basically just allows me to mount the disk and retrieve data.

    The first thing I did was call them and the person on the end of the phone seemed completely disinterested, he wanted me to e-mail them (?) and ask them to re-instate the server which he said would then be passed to their technical team. I explained to him that every time I have to deal with their technical team it takes at least 48 hours for any sort of response but he didn't seem to care. He said "the fastest way to get your server back on-line would be to reformat it and reinstall all your data" i then replied "why should I have to download 20GB of data to my home machine then re-upload it again because you incorrectly think my server has been hacked?" to which he replied "well we can sell you a mountable 500GB usb drive to put your data on before the re-install".

    I e-mailed them and got the following response:

    ---------------------
    Dear customer,

    I'm afraid that we have little room for these sort of cases. If a hacking has been detected from your server is because a serious breach has happened, we don't request the reinstallation of the server because of petty things.

    I'm afraid that the only option left is reinstallation. You've been given access codes to get to the server and retrieve your data and after that, you can launch a reinstallation.

    Kind regards

    Marc
    OVH Customer Support Adviser
    ------------

    So they are trying to force me to waste 6 hours re-installing the server when I know for a FACT that it hasn't been compromised.

    Poor service.

    To be honest I'm shocked.

    Anyone else with OVH customer support experiences?

  2. #2
    Certified VIP Host
    I have made 5165 posts
    251 posts within 6 months
    Contact Me, Company profile
    JamieBeeston is on a distinguished road
    That doesnt sound fun, just out of interest, how much are you paying for the server?

    J
    Register1.net
    .eu £7.95
    .com .net .org .uk £5.48
    Premium UK Virtual Hosting from £16 a year
    Quad Core 2.83Ghz 1GB 2TB 250GB Xeon Servers from £49
    Company reg: 04186664 VAT reg: GB 815 5899 88
    [Any views expressed on this forum are my own, and may not represent the views of any organisation that I own or am connected with.]

  3. #3
    My last monthly invoice was £68.98

  4. #4
    Certified VIP Host
    I have made 5165 posts
    251 posts within 6 months
    Contact Me, Company profile
    JamieBeeston is on a distinguished road
    Do you know why you're being DDoS'd so frequently? It's not something that most websites will experience ever, let alone frequently
    Register1.net
    .eu £7.95
    .com .net .org .uk £5.48
    Premium UK Virtual Hosting from £16 a year
    Quad Core 2.83Ghz 1GB 2TB 250GB Xeon Servers from £49
    Company reg: 04186664 VAT reg: GB 815 5899 88
    [Any views expressed on this forum are my own, and may not represent the views of any organisation that I own or am connected with.]

  5. #5
    All I run on the server is a small java game that has around 90 people on-line at maximum and a forum. I presume some kid with a botnet got banned and decided to take revenge but honestly I don't have a clue.

  6. #6
    Certified VIP Host
    I have made 1611 posts
    293 posts within 6 months
    Contact Me, Company profile
    goscombtech is on a distinguished road
    Quote Originally Posted by reedox View Post
    So they are trying to force me to waste 6 hours re-installing the server when I know for a FACT that it hasn't been compromised.
    May I ask how you know for a fact it hasn't been compromised?
    Goscomb Technologies Limited - www.goscomb.net / AS39326

    E: sales@goscomb.net P: +44 (0) 203 129 4400 F: +44 (0) 203 129 4410

    Free IPv4/IPv6 Dialup! p: 08456043047 u: dial@goscomb.net.uk p: dial
    IP Transit :: Colocation :: Dedicated Servers :: Leased Lines :: DSL
    Registered in England and Wales No. 05672987 - VAT Registration No. 853 7954 80

  7. #7
    Mooharr
    no reviews yet. Post Review
    Certified VIP Host
    I have made 2378 posts
    273 posts within 6 months
    Contact Me, Company profile
    JamesSykes is on a distinguished road
    Quite certain Kimsufi/Ovh are just warez havens.... Quite common for people on tracker forums to mention em.

    Probably why the service is so shit.
    Mooharr
    E-Mail Hosting Services

    These are not my views and i cannot be held accountable for anything he says.

  8. #8
    Ed
    Ed is online now
    Certified Standard Host
    I have made 720 posts
    115 posts within 6 months
    Contact Me, Company profile
    Ed is on a distinguished road
    Quote Originally Posted by JamesSykes View Post
    Quite certain Kimsufi/Ovh are just warez havens.... Quite common for people on tracker forums to mention em.

    Probably why the service is so shit.
    Theres no doubt they are a haven for Warez, but i'd not say the service is that bad. I've got a kimsufi server - the web-based control panel does what it say's and works. Connectivity isn't bad, infact it's excellent over my Virgin Media connection. I don't use it for anything serious, I use the box for trashing things but have no problems what so ever with the server I rent from them.
    Virtual Linux.

  9. #9
    Mooharr
    no reviews yet. Post Review
    Certified VIP Host
    I have made 2378 posts
    273 posts within 6 months
    Contact Me, Company profile
    JamesSykes is on a distinguished road
    Quote Originally Posted by Ed View Post
    Theres no doubt they are a haven for Warez, but i'd not say the service is that bad. I've got a kimsufi server - the web-based control panel does what it say's and works. Connectivity isn't bad, infact it's excellent over my Virgin Media connection. I don't use it for anything serious, I use the box for trashing things but have no problems what so ever with the server I rent from them.
    Yeah but you can imagine, if your customers are warez users then you might not be so concerned with the way you handle them
    Mooharr
    E-Mail Hosting Services

    These are not my views and i cannot be held accountable for anything he says.

  10. #10
    Quote Originally Posted by goscombtech View Post
    May I ask how you know for a fact it hasn't been compromised?
    OVH sent me this message after I waited a week for a response from them:

    "Dear customer,

    sorry for the delay, I must apologize, but it's been quite difficult to collect the information.

    your server has been closed because of the following file found in your server:

    -rwxr-xr-x 1 root root 48 May 14 23:58 syn

    #!/bin/bash
    while true; do
    synd
    sleep 20

    It looks like somebody has broken into your server and left this, or at least that's what we have to believe.

    Therefore, the security of the server has been compromised, and reinstallation is needed. Till you have done that, you won't be able to use it. I suggest you to go ahead and do it as soon as possible."

    Now the synd script is:

    PHP Code:
    #!/bin/sh
    load_conf()
    {
        
    CONF="/usr/local/synd/synd.conf"
        
    if [ -"$CONF" ] && [ ! "$CONF" ==    "" ]; then
            source $CONF
        
    else
            
    head
            
    echo "\$CONF not found."
            
    exit 1
        fi
    }

    head()
    {
        echo 
    "Syn-Deflate version 0.1 alpha"
        
    echo "Based on Dos-Deflate - felosi <admin@nix101.com>"
        
    echo
    }

    showhelp()
    {
        
    head
        
    echo 'Usage: synd.sh [OPTIONS] [N]'
        
    echo 'N : number of SYN_RECV connections (default 10)'
        
    echo 'OPTIONS:'
        
    echo '-h | --help: Show    this help screen'
        
    echo '-c | --cron: Create cron job to run this script regularly (default 1 mins)'
        
    echo '-k | --kill: Block the offending ip making more than N SYN_RECV connections'
    }

    unbanip()
    {
        
    UNBAN_SCRIPT=`mktemp /tmp/unban.XXXXXXXX`
        
    TMP_FILE=`mktemp /tmp/unban.XXXXXXXX`
        
    UNBAN_IP_LIST=`mktemp /tmp/unban.XXXXXXXX`
        echo 
    '#!/bin/sh' $UNBAN_SCRIPT
        
    echo "sleep $BAN_PERIOD" >> $UNBAN_SCRIPT
        
    if [ $APF_BAN -eq 1 ]; then
            
    while read line; do
                echo 
    "$APF -d $line" >> $UNBAN_SCRIPT
                
    echo $line >> $UNBAN_IP_LIST
            done 
    $BANNED_IP_LIST
        
    else
            while 
    read line; do
                echo 
    "$IPT -D INPUT -s $line -j DROP" >> $UNBAN_SCRIPT
                
    echo $line >> $UNBAN_IP_LIST
            done 
    $BANNED_IP_LIST
        fi
        
    echo "grep -v --file=$UNBAN_IP_LIST $IGNORE_IP_LIST > $TMP_FILE" >> $UNBAN_SCRIPT
        
    echo "mv $TMP_FILE $IGNORE_IP_LIST" >> $UNBAN_SCRIPT
        
    echo "rm -f $UNBAN_SCRIPT" >> $UNBAN_SCRIPT
        
    echo "rm -f $UNBAN_IP_LIST" >> $UNBAN_SCRIPT
        
    echo "rm -f $TMP_FILE" >> $UNBAN_SCRIPT
        
    $UNBAN_SCRIPT &
    }

    add_to_cron()
    {
        
    rm -f $CRON
        sleep 1
        service crond restart
        sleep 1
        
    echo "SHELL=/bin/sh" $CRON
        
    if [ $FREQ -le 2 ]; then
            
    echo "0-59/$FREQ * * * * root /usr/local/synd/synd.sh >/dev/null 2>&1" >> $CRON
        
    else
            
    let "START_MINUTE = $RANDOM % ($FREQ - 1)"
            
    let "START_MINUTE = $START_MINUTE + 1"
            
    let "END_MINUTE = 60 - $FREQ + $START_MINUTE"
            
    echo "$START_MINUTE-$END_MINUTE/$FREQ * * * * root /usr/local/synd/synd.sh >/dev/null 2>&1" >> $CRON
        fi
        service crond restart
    }


    load_conf
    while [ $]; do
        case $
    1 in
            
    '-h' '--help' '?' )
                
    showhelp
                
    exit
                ;;
            
    '--cron' '-c' )
                
    add_to_cron
                
    exit
                ;;
            
    '--kill' '-k' )
                
    KILL=1
                
    ;;
             *[
    0-9]* )
                
    NO_OF_CONNECTIONS=$1
                
    ;;
            * )
                
    showhelp
                
    exit
                ;;
        
    esac
        shift
    done

    TMP_PREFIX
    ='/tmp/synd'
    TMP_FILE="mktemp $TMP_PREFIX.XXXXXXXX"
    BANNED_IP_MAIL=`$TMP_FILE`
    BANNED_IP_LIST=`$TMP_FILE`
    echo 
    "Banned the following ip addresses on `date`" $BANNED_IP_MAIL
    echo >>    $BANNED_IP_MAIL
    BAD_IP_LIST
    =`$TMP_FILE`
    netstat -ntu grep SYN_RECV awk '{print $5}' cut -d: -f1 sort uniq -sort -nr $BAD_IP_LIST
    cat $BAD_IP_LIST
    if [ $KILL -eq 1 ]; then
        IP_BAN_NOW
    =0
        
    while read line; do
            
    CURR_LINE_CONN=$(echo $line cut -d" " -f1)
            
    CURR_LINE_IP=$(echo $line cut -d" " -f2)
            if [ 
    $CURR_LINE_CONN -lt $NO_OF_CONNECTIONS ]; then
                
    break
            
    fi
            IGNORE_BAN
    =`grep -c $CURR_LINE_IP $IGNORE_IP_LIST`
            if [ 
    $IGNORE_BAN -ge 1 ]; then
                
    continue
            
    fi
            IP_BAN_NOW
    =1
            
    echo "$CURR_LINE_IP with $CURR_LINE_CONN SYN_RECV connections" >> $BANNED_IP_MAIL
            
    echo $CURR_LINE_IP >> $BANNED_IP_LIST
            
    echo $CURR_LINE_IP >> $IGNORE_IP_LIST
            
    if [ $APF_BAN -eq 1 ]; then
                $APF 
    -d $CURR_LINE_IP
            
    else
                
    $IPT -I INPUT -s $CURR_LINE_IP -j DROP
            fi
        done 
    $BAD_IP_LIST
        
    if [ $IP_BAN_NOW -eq 1 ]; then
            dt
    =`date`
                    
    hn=`hostname`
    #        if [ $EMAIL_TO != "" ]; then
    #            cat $BANNED_IP_MAIL | mail -s "IP addresses banned on $dt $hn" $EMAIL_TO
    #        fi
            
    unbanip
        fi
    fi
    rm 
    -f $TMP_PREFIX.* 
    Basically it just checks for syn connections and blocks people in the firewall.

  11. #11
    Registered User e107xs is on a distinguished road
    Quote Originally Posted by reedox View Post
    So they are trying to force me to waste 6 hours re-installing the server when I know for a FACT that it hasn't been compromised.
    So I assume you didn't place this script there yourself?

    Still interested in how you could be so 100% sure that you hadn't then find out that you had been breached!

  12. #12
    Certified VIP Host
    I have made 1340 posts
    98 posts within 6 months
    Contact Me, Company profile
    midnightsoftwar is on a distinguished road
    Erm - you know this is from 4 months ago don't you?
    Leigh Jepson
    Midnight Software (soon to be Serviture Ltd)
    Tel: 01925 320022 - VAT: 896 9527 43
    Email: leigh@midnightsoftware.co.uk

  13. #13
    Certified VIP Host
    I have made 3351 posts
    1237 posts within 6 months
    Contact Me, Company profile
    Ed-Freethought is on a distinguished road
    Quote Originally Posted by midnightsoftwar View Post
    Erm - you know this is from 4 months ago don't you?
    Now you got caught out with deleted posts :P
    Freethought Internet Limited
    Hosting and communications
    Freethought Internet Limited registered in London No. 5862996. Registered office: The Old Church Hall, 2A Cromwell Street, Lincoln, LN2 5LP.
    Xion Internet and Powercore Networks are trading names of Freethought Internet Limited.

  14. #14
    Certified VIP Host
    I have made 1340 posts
    98 posts within 6 months
    Contact Me, Company profile
    midnightsoftwar is on a distinguished road
    Hehe, what goes around comes around
    Leigh Jepson
    Midnight Software (soon to be Serviture Ltd)
    Tel: 01925 320022 - VAT: 896 9527 43
    Email: leigh@midnightsoftware.co.uk

  15. #15
    Registered User e107xs is on a distinguished road
    I think Leigh just started spaming old thread and you guys are covering for him!

+ Reply to Thread
Page 1 of 2
1 2 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Ovh
    By properganda in forum Discuss a hosting company
    Replies: 2
    Last Post: 15th January 2008, 12:26 PM
  2. 1&1, rack365, 123-reg or OVH for ~£50pm dedi?
    By Marsbar in forum Dedicated Servers, VPS and Colocation
    Replies: 10
    Last Post: 9th February 2006, 09:06 PM
  3. Your worst present??
    By richard in forum General Chit Chat & Discussion
    Replies: 7
    Last Post: 31st December 2002, 08:16 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Content Relevant URLs by vBSEO 3.5.0 RC2