amuck-landowner

Search results

  1. tchen

    Proxmox

    I've been hesitant to try that with mine.  Any gotchas when doing dist-upgrades or is it fully transparent after that first bit of somersault bootstrapping?
  2. tchen

    Test Services / Help with cgroups / KVM abusability?

    At the risk of being that guy that posts 'the manual',  https://www.kernel.org/doc/Documentation/scheduler/sched-bwc.txt Specifically, are you running the normal scheduler or the RT?  You kinda dumped it all.  Things to do/look at:  look at the cpu.stat's for the number of times your current...
  3. tchen

    Proxmox

    The ESXi license is free. Yes, you need a license for commercial usage but that's still free. Technically speaking proxmox community edition also requires a license for commercial use although it's provided closer on the shrink wrap and doesn't require a VMware account sign up.
  4. tchen

    Is there a way to automate kvm re/installs?

    I came across this while looking up the pre-seeding texteditor mentioned. http://fai-project.org/fai-cd/ I'm not sure if it needs a separate DHCP address to bootstrap itself though.
  5. tchen

    Whatever happened to Xen?

    I'm actually surprised you didn't use Cloudstack with XCP.  Any reason for using KVM instead there?
  6. tchen

    Target confirms leak of 40mil CC data

    Regarding PIN on card and resettability its the same.  The CVV2 for us though fall under the card network guidelines.  * CVV2s can be transmitted to a third party but PCI compliance dictates that it never touches ground and is only used during auth on the card network. PINs are only direct...
  7. tchen

    BuyVM Legal Defense Fund? LOL

    It's good to be neutrally bland in the PR. Incident reports do need to detailed enough. Even Ramnode's post incident report mentions Robert Clark by name along with Solus***. That one didn't generate a stink so where's the line drawn? My guess, separate the PR from the IR. Nick uses twitter...
  8. tchen

    BuyVM Legal Defense Fund? LOL

    They did that with SolusVM. I miss my Solus CP. :( The WHMCS 0 days hit anyone who didn't have modsecurity up and running. And even if you did, chances were good you disabled some of the sql injection rules because the admin backend passes queries in the post. Sure, some people find coding...
  9. tchen

    BuyVM Legal Defense Fund? LOL

    For what it's worth, I was actually impressed that you guys set up remote logging alerts after the second? breach. It didn't fully stop the third try but at least you managed to catch and stop it in progress. People don't tend to deal with security on a daily basis and don't know how it works...
  10. tchen

    Yahoo! Mail possible breach.

    Man, there are only so many permutations of 's3cr3t' I can do...
  11. tchen

    BuyVM Legal Defense Fund? LOL

    I doubt the 25k are all active but the thing is, there's so much vitriol against CVPS who in their right mind would randomly post 'hey, I have CVPS boxes and they're fine'. He doesn't prompt people to post reviews on his behalf like some providers at WHT so where's the impetus? For the record...
  12. tchen

    Tool for detecting if a VPS node is "slabbed" or not

    You've still got a chance.  Run it on the OVZ VPS.  Despite it being posted directly on their website, I'm sure it'd be enough to drum up a multi-pager LET thread or two :P
  13. tchen

    Target confirms leak of 40mil CC data

    I actually missed the bit where there was a dump of 2million CCs offered for sale*... so um... yes - they were exfiltrated successfully.  Rough indeed. The sad part was  * the analysts verified with some banks that those cards were indeed used at Target during those dates.
  14. tchen

    Target confirms leak of 40mil CC data

    The official investigation's still ongoing.  Although from various accounts they say a vendor credential was compromised, then it went laterally within the network to the point of sale system.  A control/exfiltration server was also installed within the network so its likely they managed to get...
  15. tchen

    BuyVM Legal Defense Fund? LOL

    There's reverse engineering which is a sideline to standard copyright cases.  You actually don't need to directly copy code in order for those to proceed.  Access to code, either directly provided or indirectly via disassembly is sufficient.  Franciso's been on record numerous times about fixing...
  16. tchen

    Target confirms leak of 40mil CC data

    Canada's field testing the chip-and-pin :)  There's a whole slew of liability shifts that are involved from customers to merchants to banks.  But that said, the CVV2 code serves more or less the same purpose.  That code isn't embedded in the magnetic stripe and any authorization that's done...
  17. tchen

    BuyVM Legal Defense Fund? LOL

    I can't talk for anyone else but all the provider bashing going around has actually had an effect on my purchasing plans.  For not the very reason you may think but the opposite.  Any provider that's jumping in picking fights and mudslinging automatically notches themselves down in my books...
  18. tchen

    Gotcha!

    Sure.  http://lowendbox.com/blog/chicagovps-6-45-512mb-xen-vps-exclusive-offer/ From the blurb: You made about 5 comment-replies in that offer without batting an eyelash.
  19. tchen

    Gotcha!

    Sure you own the hardware.  You also admittedly buy a bulk of it wholesale from CC which you then setup as nodes to sell downstream or directly.  Your time and that of your employees is the markup.  Frankly, I don't see anything wrong with that description as the majority of this industry does...
  20. tchen

    Ionity Transfers KC Customers to Batts

    IIS isn't that bad.  It's the plethora of crap that inevitably comes with SBS installations, or sites that rely on poorly written third-party .NET libs that give it a bad vibe.  LAMP stacks only avoid that issue because of the way the ecosystem is structured slightly different.  If you get too...
Top
amuck-landowner