amuck-landowner

Psychz Networks / PhotonVPS new DC - Downtown Los Angeles

Profuse-Jim

New Member
Verified Provider
We recently completed a new datacenter build in downtown Los Angeles and wanted to share some pictures with you.  Total build time from start to finish was about 3 months.

Let me know if you have any questions and I'll do the best to answer them.

40BAynfMIwQqCSl.jpg


cPRJ2yBFdmW2FLz.jpg


Pgs0zRDha24pLnP.jpg


Yx8MP9TvJLZZOfn.jpg


GKNm1MQXkoSOhKU.jpg


cD7D9mA21RIwOmK.jpg


sHPJbg7zENPACzK.jpg


QT1cyQbRA168uKg.jpg


aC2rIMBr6HwspAh.jpg


Evnzyy9dGFydE4g.jpg


D6viPibmgYTMTqQ.jpg


37zbWdzHooNaquM.jpg


iFFuk5yjsOnjtVX.jpg


8LpjCCPHR4P0oMp.jpg


gmU7d9e0Kfdr5TK.jpg


9wtSilWT7r84Fwd.jpg
 
Last edited by a moderator:

tonyg

New Member
Lovely, I had to ban a bunch of IPs from this host due to crazy amount of nefarious activity coming from their clients.
 

MannDude

Just a dude
vpsBoard Founder
Moderator
Looks great. I always love seeing DC builds. Be sure to keep posting photos as progress is made!
 

Aldryic C'boas

The Pony
Sure, I have a question.  Do you have alternative contacts aside from abuse@?  I've personally reported a number of incidents in the past couple of years that were never resolved (the abuse continues for days/weeks after reporting), and I've never received a reply to.
 

Aldryic C'boas

The Pony
When was the last time you send an email to [email protected]?  You should have received a ticket number for tracking purposes.
Probably about 8-10 months ago.  I do remember receiving automated replies - but to be honest I just started deleting those and gave up after a good number of ignored reports since I could never get a response from a human, or even get someone to curb the abuse.  For a very long time we simply blocked all traffic from your IP space.  Especially email.

Which brings me to my other question I forgot to ask - you guys have had at least 4 ROKSO listings since February, with one currently active:


Are you doing anything to actually remove these abusers, or is it safest to simply continue blocking all email from your ranges?
 
Last edited by a moderator:

Wintereise

New Member
Bullshit.

Just because there's one Spamhaus listing doesn't mean your net isn't crawling with filth. You're the only provider from the US that I have to regularly filter prefixes from due to the sheer amount of portscanning and related activity originating there.

I'd really recommend better vetting who you sell stuff to, because at this rate, a AS wide drop policy seems to be the last resort -- and I know for a fact that I'm not the only network considering that.
 
Last edited by a moderator:

Aldryic C'boas

The Pony
So, that alternate contact I was asking for?  An address where someone will actually reply to incident reports?

Yes, you only have one current listing.  A Quick Query shows that you have a pretty nasty ROKSO history - quite a few with the same person gaining multiple listings for psych.net.  Is action now being taken to keep your network clean, or is it safest to continue blocking mail from your network?  (I ask this here because, as stated before, I've never received a response from your 'official' POCs, and the staggering amount of abuse that has come from your IP space is enough to put any netadmin on edge).
 
Last edited by a moderator:

Profuse-Jim

New Member
Verified Provider
The only email for abuse is [email protected]. Our abuse is actually automated now, our clients that do not update the forwarded abuse ticket will have their VM or IP null-routed within 24 hours.
 

Damian

New Member
Verified Provider
Due to the complete lack of response to abuse reports, IPXcore ended up just dropping networks in AS40676.

The filter was implemented March 23rd. This is the results from March 25th:


core01.nj#show access-l IPXCore_Custom_Filter

Extended IP access list IPXCore_Custom_Filter

    10 deny ip 108.171.240.0 0.0.15.255 any (858 matches)

    20 deny ip 216.24.192.0 0.0.15.255 any (1242 matches)

    30 deny ip 74.117.56.0 0.0.7.255 any (1306 matches)

    40 deny ip 192.184.32.0 0.0.31.255 any (3760 matches)

    50 deny ip 107.160.0.0 0.0.255.255 any (398 matches)

    60 deny ip 198.13.96.0 0.0.31.255 any (533 matches)

    70 deny ip 173.224.208.0 0.0.15.255 any (2615 matches)

    80 deny ip 208.87.240.0 0.0.3.255 any (3670 matches)

    90 deny ip 199.119.200.0 0.0.7.255 any (426 matches)

    100 deny ip 199.71.212.0 0.0.3.255 any (258 matches)

    110 deny ip 192.210.48.0 0.0.15.255 any (1102 matches)

    120 deny ip 23.238.128.0 0.0.127.255 any (267 matches)

    130 deny ip 23.228.192.0 0.0.63.255 any (1637 matches)

    140 deny ip 199.15.112.0 0.0.7.255 any (865 matches)

    150 deny ip 216.99.144.0 0.0.15.255 any (1196 matches)

    160 deny ip 199.83.88.0 0.0.7.255 any (198 matches)

    170 deny ip 23.91.0.0 0.0.31.255 any (398 matches)

    180 permit ip any any (41721 matches)

core01.nj#

That's a hell of a lot of hits in two days.

(edit) Now i'm not saying that there was absolutely no abuse from any other source, but there's no other egregious single-source for abuse. How do you not get your connection axed by your upstreams?
 
Last edited by a moderator:

Aldryic C'boas

The Pony
But it's okay, they only have one listing.

Never mind that it's a ROKSO.  Or that there's a nasty history of repeat-ROKSO listings.  Or that the network in general is just bloated with abuse.

Yeah, I don't think I'll be removing our filters any time soon, either.
 

Profuse-Jim

New Member
Verified Provider
For all of you that complain that our abuse department is not handling abuse report, would you mind sharing proofs of such abuses?  Our abuse department is very strict when it comes to spamming and abuse matters.  I am sure you guys can understand how the web hosting business works, not everyone that joins will use a services for productive means; thus why this becomes an endless battle. 

 

We have clients from all over the world, so managing 200k IP address becomes an endless hustle. I am sure your network too has clients that use your services to send SSHD botnet attacks, spamming, DDoS to other networks etc...

 

I highly recommend to showing proofs instead of bashing a thread.

 

[email protected] abuse matter are handled automatically by our staff of senior security members.

 

NOTE:  we work closely with http://www.uceprotect.net/ our ID AS40676.  Check it out if you don't believe me
 

DomainBop

Dormant VPSB Pathogen
NOTE:  we work closely with http://www.uceprotect.net/ our ID AS40676.  Check it out if you don't believe me
So f**king what? Uceprotect is an anti-spam organization.  The outbound abuse that historically has come from your network isn't spam.  Your network AS40676 is infamous for the volume of botnets, comment spammers, brute force attackers, malware, etc that have been hosted there.  Do a google search for psychz networks botnets (or just do a google search for unassigned.psychz.net) and tell me there isn't a problem.
 

Aldryic C'boas

The Pony
Do you see anything recent?  Didn't think so.
[...] you guys have had at least 4 ROKSO listings since February, with one currently active:

That doesn't qualify as recent?

Happens when there's a lot of kiddie hosts.
Lovely, another Fabozzi/Biloh.  Spam blocks and all.
 
Top
amuck-landowner