my site has been back up for last hour or so. I contacted there support team this morning asking for a eta on when full service will be returned to normal and this is there response.
Seems they're finally getting it under control. Host-stage, What security have you now implemented to prevent this happening again? I appriciate that hosting can be a nasty business with ddos and hacking. How ever like many I can't exactly afford to have my sites down for such a lentgh of time.
We are setting a dual layer of security and we may be adding a third. Actually, we have set a firewall (hardware wise) which would be able to filter the incoming connections and this would be on the top of the server instead on the server directly. Also, we have implemented a way to filter legitimate packets from non legitimate packets and null route the ones which are meant to harm the server in any kind.To give you further insights, the DDoS attacks are generating packets with a "signature" and this footprint allows to filter the packets without affecting the legit packets. This layer would be by far the most efficient one and has been possible thanks to the datacenter we are working with. The shared server from this week end event has been secured already of course.
However, it is important to know that protecting at 100% against DDoS attacks is fairly impossible which was the reason of my inaction before.
Finally, the third security layer which would be considered is to add a CDN to all web hosting accounts (cloudfare for instance) by default. You can already do it on your own, but making it a standard would reduce here again the risk considerably. As far as an attack would be contained in the network and as far as they are generally geographically spread, it would attack different location of the CDN, hence a greater allowance.
Thank you for your response but I changed the log's folder and created a new log, disabled dropbox (backups) and only used GSA and Captcha breaker to try and diagnose the issue. The exact same happened, after a day the server restarted itself and has been everyday since september. My renewal is coming up this week and I for one will not be renewing this service as it defeats the purpose of using automated tools if I have to be checking back on them everyday.
Please open a support ticket so I can identify your VPS and come with a proper solution with your issue. If your VPS is being restarted it is because it is slowing down the whole node. The disk access latency issue will be cleared in our new upcoming line of VPS but to be able to follow the demand serious investments has to be made. I can't tell more at the moment, but it is coming.
Why was my VPS terminated? I was running GSA google ranker, an SEO tool. Your thread clearly indicates that SEO tools are allowed. The "complaints" linked are not even formal complaints as well.
Hello,
We have received some complains about forum spamming as shown below :
http://www.stopforumspam.com/ipcheck/
http://www.projecthoneypot.org/ip_
We don't support forum spamming throughout our network. Your VPS has been terminated without any possibility of recovery.
Please, let us know if we can further assist you,
Best Regards
Daniel Johnson
Technical Analyst Level I
HostStage Technical Support
This is a very spacific issue. As stated in the sales thread, we do not support Xrumer without anonymous proxies hence forum spamming. We used to be able to take the heat 2 year ago but presently it isn't possible. GSA does include a forum spamming module and we have received complaints on your IP address because either you didn't use proxies or your proxies weren't anonymous. We have kept your VPS along with your data and if you can fix this issue, we will be swapping your IP and set you back online. It is natural that we don't cut the VPS for the sake of doing it, if we do it which is very rare, it is because there is a serious reason behind, and forum spamming is one serious reason. And to go even further, whenever it happened in the past, a refund is issued. So here you have the choice to be up and running again if appropriate measures are undertaken to clear the future spamhaus complains or you can get a full refund.
I just signed up to use GSA to, is this right enough? i think i might need to look elsewhere.
Graham
No problem with GSA. Hundreds of users are using it for months. But as stated above, GSA is causing 2 issues that aren't HostStage's specific. The first is the forum spamming problem which can be fixed easily by using GSA along with anonymous proxies. The second is that GSA is keeping a text file with all the URL crawled, and where the links has been posted to. According to your usage, this log file is growing way too fast and it is stressing the disk access. If you were on a dedicated server there wouldn't be any issue.
=====
Please find below some tips to use with GSA and optimize your user experience :
- If you are starting a new project, you can remove the logs in C:/Users/Administrator/Appdata/localroaming/GSA/ (verified.txt ...)
- Open your option panel in GSA, select the Advanced tab, and hit the remove html debug files.
It will help greatly, and you should have a better experience.
=====
To conclude, this week-end has been quite a busy one to say the least, one of the worse ever no doubt! Be insured that every unsatisfaction is taken very seriously to keep improving our services. And to be completly honest, dealing with that much of complaints at once is a first, and hearing HostStage used to be great once is something that i don't want to hear ever and as we are working for you changes will be made! Stay tuned.