amuck-landowner

Robert Clarke DDoS'd Brings the Internet Down...

kaniini

Beware the bunny-rabbit!
Verified Provider
Yeah I meant yesterday's packet loss. I don't know what happened with Clarke and kaniini, et al, but I think that was resolved before the Seattle issues.
Wasn't related to us, the last attack we saw was Thursday morning, and I am pretty sure was just the normal level of DDoS for ServerCrate.
 

Virtovo

New Member
Verified Provider
Wasn't related to us, the last attack we saw was Thursday morning, and I am pretty sure was just the normal level of DDoS for ServerCrate.
Some posts I've read in this thread suggest you are part of Centarra?  Is that correct?
 

kaniini

Beware the bunny-rabbit!
Verified Provider
Some posts I've read in this thread suggest you are part of Centarra?  Is that correct?
Tortoise and Centarra have in effect been the same enterprise since middle of last year.  Integration of both brands is on track to take effect at the end of this month.  In essence, that move has enabled us to build out more advanced services offerings, which will be available soon.  This has, in effect been known for some time to customers... nothing has yet been announced publicly because the brands are not yet integrated.  In an overly simplified way of explaining things, Centarra is what we did with Avante's assets.

Wait, you actually host that guy?  Knowing what he's done?
He was an Avante customer, so we picked him up as a result of that.  He grew with us into a full cabinet.

But, I want to take a moment to address this "knowing what he's done" thing, because I am really disappointed that someone like you would use that argument.

As far as I know, all he has actually done is run a couple of exploits he copied and pasted from a blog.  There are rumors he boots people, but he hasn't done it from our network (and if he ever did, he would be dropped as a customer).  Why should I deny someone service simply because they have made bad decisions in the past?  Why is nobody being critical of those providers for taking absolutely no security measure to prevent the exploit from working?  (Hint: proxying SolusVM control panel through Apache or nginx using mod_security would have stopped the exploit from working.)

This lynchmob mentality against the kid is something I find somewhat disturbing.  While what he did was certainly a dick move, SolusVM was already known to be crap, and people should have already hardened against it.  Instead of blaming the kid for running the exploit (again, was a dick move), we should also blame the provider for not having taken any preventative steps knowing that SolusVM is a security disaster.
 
Last edited by a moderator:

Virtovo

New Member
Verified Provider
Tortoise and Centarra have in effect been the same enterprise since middle of last year.  Integration of both brands is on track to take effect at the end of this month.  In essence, that move has enabled us to build out more advanced services offerings, which will be available soon.  This has, in effect been known for some time to customers... nothing has yet been announced publicly because the brands are not yet integrated.  In an overly simplified way of explaining things, Centarra is what we did with Avante's assets.

He was an Avante customer, so we picked him up as a result of that.  He grew with us into a full cabinet.

But, I want to take a moment to address this "knowing what he's done" thing, because I am really disappointed that someone like you would use that argument.

As far as I know, all he has actually done is run a couple of exploits he copied and pasted from a blog.  There are rumors he boots people, but he hasn't done it from our network (and if he ever did, he would be dropped as a customer).  Why should I deny someone service simply because they have made bad decisions in the past?  Why is nobody being critical of those providers for taking absolutely no security measure to prevent the exploit from working?  (Hint: proxying SolusVM control panel through Apache or nginx using mod_security would have stopped the exploit from working.)

This lynchmob mentality against the kid is something I find somewhat disturbing.  While what he did was certainly a dick move, SolusVM was already known to be crap, and people should have already hardened against it.  Instead of blaming the kid for running the exploit (again, was a dick move), we should also blame the provider for not having taken any preventative steps knowing that SolusVM is a security disaster.
Where does ChrisK and yourself fit into Centarra?  Was it simply a merger of both brands?  
 

kaniini

Beware the bunny-rabbit!
Verified Provider
Where does ChrisK and yourself fit into Centarra?  Was it simply a merger of both brands?  
We have not really decided any formal titles, but in essence he is on our board.

He is mainly dealing with the network and colo side of the business.  My guys are handling the on-demand infrastructure part of the operation.  I am working on basically all aspects of the operation at a high level.
 

Virtovo

New Member
Verified Provider
We have not really decided any formal titles, but in essence he is on our board.

He is mainly dealing with the network and colo side of the business.  My guys are handling the on-demand infrastructure part of the operation.  I am working on basically all aspects of the operation at a high level.
Cool I only ask because I've trawled through your panel codebase before.  I know Avante probably brought infrastructure to the table.  I just wondered who was the larger of the two before the merger?
 

Aldryic C'boas

The Pony
But, I want to take a moment to address this "knowing what he's done" thing, because I am really disappointed that someone like you would use that argument.


As far as I know, all he has actually done is run a couple of exploits he copied and pasted from a blog.  There are rumors he boots people, but he hasn't done it from our network (and if he ever did, he would be dropped as a customer).

To clarify:  he was proven to try and intentionally run the exploit, knowing full well what it did, on quite a few providers.  Us included.  There's also the massive collateral damage he caused to RamNode.  As far as booters?  No clue, don't care.  But if he weren't already banned from service with us before pulling that little stunt with the exploits, that alone would be enough for me to blacklist him for good.

Why should I deny someone service simply because they have made bad decisions in the past?
Maybe I'm more skilled in pattern recognition than some.. but this isn't the first time he's caused grief, either through intent or ignorance.  Why do I deny service to someone because they made bad decisions in the past?  Because keeping the peace of mind for our clients is worth far more than a couple bucks from a repeat troublemaker.  If my stance on that dissappoints you.. it just means you don't really know me that well.  There are plenty of folks that can attest to my lack of tolerance, and the inevitable result of wasting second chances.
 

kaniini

Beware the bunny-rabbit!
Verified Provider
Cool I only ask because I've trawled through your panel codebase before.  I know Avante probably brought infrastructure to the table.  I just wondered who was the larger of the two before the merger?
In essence, Avante gave us a fairly large jump start on things we were already working on.  I'll just leave it at that.
 

kaniini

Beware the bunny-rabbit!
Verified Provider
To clarify:  he was proven to try and intentionally run the exploit, knowing full well what it did, on quite a few providers.  Us included.  There's also the massive collateral damage he caused to RamNode.  As far as booters?  No clue, don't care.  But if he weren't already banned from service with us before pulling that little stunt with the exploits, that alone would be enough for me to blacklist him for good.

Maybe I'm more skilled in pattern recognition than some.. but this isn't the first time he's caused grief, either through intent or ignorance.  Why do I deny service to someone because they made bad decisions in the past?  Because keeping the peace of mind for our clients is worth far more than a couple bucks from a repeat troublemaker.  If my stance on that dissappoints you.. it just means you don't really know me that well.  There are plenty of folks that can attest to my lack of tolerance, and the inevitable result of wasting second chances.
Well, Clarke has a full cabinet.  It is a lot more than "a couple of bucks."

For the record, one of the conditions of his being able to do business with us as Centarra is that he would discontinue this crap.  And, I haven't heard of him doing anything more since he decided to transfer over from Avante.  If there is any further incident involving him, you better believe we'll be on him about it.

If I thought that he was not going to discontinue the crap, he wouldn't be on our network right now.  I am sure you can recognize that ;)
 

Aldryic C'boas

The Pony
Well, Clarke has a full cabinet.  It is a lot more than "a couple of bucks."
May be.. but honestly the amount would be irrelevant for me. Even if the guy wanted to drop a couple grand a month on us (which funny enough still wouldn't make him one of our biggest clients), he still wouldn't be welcome.

For the record, one of the conditions of his being able to do business with us as Centarra is that he would discontinue this crap.  And, I haven't heard of him doing anything more since he decided to transfer over from Avante.  If there is any further incident involving him, you better believe we'll be on him about it.

If I thought that he was not going to discontinue the crap, he wouldn't be on our network right now.  I am sure you can recognize that ;)
That pretty much sums up my assumption of the situation (and which I was hoping you would say, to negate anyone else wanting to take the piss for your choice of retaining him). I hope he actually has changed and gives you no grief.. but his bridge burning means I won't have to find out first hand :p
 

kaniini

Beware the bunny-rabbit!
Verified Provider
May be.. but honestly the amount would be irrelevant for me. Even if the guy wanted to drop a couple grand a month on us (which funny enough still wouldn't make him one of our biggest clients), he still wouldn't be welcome.


That pretty much sums up my assumption of the situation (and which I was hoping you would say, to negate anyone else wanting to take the piss for your choice of retaining him). I hope he actually has changed and gives you no grief.. but his bridge burning means I won't have to find out first hand :p
It's not really in his interest to give us grief as we are very efficient at unracking a cabinet. :p
 

DomainBop

Dormant VPSB Pathogen
This lynchmob mentality against the kid is something I find somewhat disturbing.  While what he did was certainly a dick move
Are we talking about the lynch mob mentality against the kid Robert Clarke or the lynch mob mentality against the kid, ChrisK?  Both kids deserve the bad reps they earned for their dick moves.  You might recall that it was only a year ago that Avante's low end VPS customers had to beg little ChrisK for refunds for a service which they paid for and which he stopped providing to them,and about the only way they were able to get refunds from the little shit was by publicly posting their grievances and refund requests on threads like these http://lowendtalk.com/discussion/5271/avante-hosting and http://lowendbox.com/blog/avante-hosting-6half-yearly-128mb-kvm-or-xen-in-florida-usa/
 

kaniini

Beware the bunny-rabbit!
Verified Provider
Are we talking about the lynch mob mentality against the kid Robert Clarke or the lynch mob mentality against the kid, ChrisK?  Both kids deserve the bad reps they earned for their dick moves.  You might recall that it was only a year ago that Avante's low end VPS customers had to beg little ChrisK for refunds for a service which they paid for and which he stopped providing to them,and about the only way they were able to get refunds from the little shit was by publicly posting their grievances and refund requests on threads like these http://lowendtalk.com/discussion/5271/avante-hosting and http://lowendbox.com/blog/avante-hosting-6half-yearly-128mb-kvm-or-xen-in-florida-usa/
I am referring to Clarke there, but you know, whatever.  ChrisK certainly got in over his head with Avante's VPS line, but as far as I know, that situation has pretty much gotten resolved.

The only take away I take from the Avante VPS situation is that running a successful lowend product is not for the inexperienced.  But I already knew that anyway.
 

nunim

VPS Junkie
 ... Maybe I'm more skilled in pattern recognition than some.. but this isn't the first time he's caused grief, either through intent or ignorance.  Why do I deny service to someone because they made bad decisions in the past? ... 
The best predictor of future behavior is past performance. 
 
Top
amuck-landowner