No support Linux hosting shutting down from hack
nosupportlinuxhosting.com
nosupportlinuxhosting.com
----------
Experts Host Sites Here for $1/month
Do you like paying extra so other people can ask amateur questions? That's how it is at other hosting companies where beginners and experts pay the same price. Beginners drive up the cost by asking a lot of novice support questions while the experts don't contact support. That is great for amateurs, and unfair to the experts like you.
No Support Linux Hosting has a completely different business model. We ignore the support questions, and pass the savings on to you! If you are an expert who does not want to pay extra for help with amateur support issues, then you can host with us and save big money.
Experts like you can sign up now for free. We charge $1/month per website, and there is no limit to the number of websites you can host in your account. This is the best deal in the web hosting industry, as long as you are the type of person who can find his or her own answers.
-----------
From https://web.archive.org/web/20201109042643/https://www.nosup...
I guess they took savings from security too.
> Each website in your account can use up to 1GB of disk space and 30GB of monthly bandwidth. These resource limits are enough for most normal websites. Each website can set up 3 databases and 25 email accounts.
The server specs are here
https://web.archive.org/web/20200618180933/http://www.nosupp...
Unless you have a griefer with a broadband connection and half an hour of time I guess?
If you need support, you pay $5/month extra.
Be less minutes than that I dare say. $20 an hour tech costs, then you have overheads and that's without a profit margin. I'd say 5 mins be more closer to the mark. Really gets down to how many support calls you have as if you have a couple admins who have to dip into a support queue, then their hourly rate would be higher. However if you have a nice frontline 1st line support pool with 2nd and 3rd for escalation model/scale then it will get cheaper.
That all said you have to factor in how much support they use and maybe your average user will need one or two tickets a year and then at the other end you the types who fail to read FAQ's and end up needing more support to use their computer, let alone the service and blur the lines contacting you for an issue that after some back and forth turns out to be the user's end. Those will be costly. So you balance things out - and go with the average and yet at the same time, dread some types of customers.
In all fairness, support costs also include all of the techs' phones, computers, networking, software licenses for Teamviewer et al, and office overhead. So a $20/hr bill is pretty cheap for a minimum wage technician.
Hell, I am just a sysadmin/developer with minimum experience (2yrs) and make ~$32/hr.
I assume that includes "when the tech has no tickets, they /do not/ work on anything that would improve the service for everyone"?
> "Essentially, if you want support, you’re not really paying for the answer to a question. You’re paying for somebody who knows what the heck they’re doing to be there when you have a question"
Often no, what I need from support is something I could technically do or am willing to work out, but cannot because it needs to be done on your side of the customer/business security boundary, or needs information from your side of it. e.g. the difference between support resets passwords vs self-service password resets.
This is covered down at the end of the comments in a list of recent support examples, many of them can be potentially fixed by the customers who are using the support as a consultancy service, but a couple cannot. Take password resets, you can design your company to have a self-service one or not at your choice and a good self-service one will mean fewer support requests. Thus, if you charge for support, it would incentivise you to have no self-service reset so that you can get support money for salaries. But you need to pay salaries either way because you need some techs available to run the service, and to provide support-as-consultancy.
> "Although there is a distinct response time benefit to subscribing before you need support, we do expect that a nontrivial number of people will wait until the first time they need support to subscribe. Leaving the first month at $5.00 helps protect us in that scenario."
1. There are parts of the system customers cannot get to, cannot find out about, which can go wrong, so there is the risk of every customer needing support at some point. 2) People who willingly pay a support subscription also go times when they aren't using that support. 3. The people paying for the support and not using it are subsidising the retainer fee of the technical employees being still available when the other peolpe waiting until they need support to subscribe have something still around to subscribe to. 4. Technical people employed and not doing support can do things to benefit all customers.
It only makes sense to include the cost in the fees charged to everyone. It can still be prioritised by inverse usage, or etc.
1) Unlike software objects, it is not yet possible to instantiate qualified support personnel as needed.
2) Unlike virtual machines, people get very cranky if you attempt to suspend them to disk or delete them to save resources when not in use.
3) Unlike physical hardware, uploading large volumes of data to people so they can produce useful output is extremely time-consuming and resource-intensive.
Here's a more serious answer:
When you seek (qualified) support, you're not paying for the time it takes the person to type the right answer; you're paying for them to know the right answer. (See also: https://www.snopes.com/fact-check/know-where-man/)
It took us quite a while to figure that out, and we tried pay-as-you-go support along the way, as someone linked below. l-lousy correctly guessed the outcome of that: more time spent arguing with people about how much we charged them for support than providing support.
Worse, that's how the person providing support makes their (minimal) income: by nickels and dimes and on other people's schedules. So, if you're doing that job, you're making very little money and frequently dealing with angry people due to a system you have no control over.
It's the tech support version of being an Amazon delivery driver. Amazon may be cool with treating people like that, but I'm not.
One detail l-lousy did get wrong (as others observe) is the 15 minutes. $5 is 5 minutes or less of a qualified person's time.
That does assume people want qualified support and not first-tier "I can't be bothered to search the FAQ, read me the right one!" interactions.
Usually, but by no means always, that's a reasonable assumption for us. People looking for that level of hand-holding tend to be much more successful with other hosting services with multiple tiers of support and (usually) phone support.
An easy to understand price schedule: $4/month per account, and $1/month for every 64MiB ram. Please note; this means all plans come with $4/month worth of support.
While that copy is old, and our pricing reflects the hardware we run on today, the quip has now been updated to: "You get $5/month of support," which is the price of the smallest package we offer.
That wisecrack aside, the reality of the support we provide is more in-line with our byline: "We do not assume you are stupid." In practice, and with a hat tip to pera replying to you here, that means we provide what you might call peer support--we explain what's going on, what steps are necessary to correct it, and take responsibility when we caused the issue. And expect similar candor.
As you might expect, most of the technical support we provide is routine--with sufficient information communicated to both parties the problem is typically straightforward to resolve. But we treat tickets on their merit and customer reports do come in that admit more substantive investigation and resolution:
the LAN of 16 Million Hosts: https://prgmr.com/blog/2020/07/17/classful-networking.html
Possible Data Corruption on Debian Buster: https://prgmr.com/blog/2020/07/15/debian-buster.html
Debugging freebsd.org Resolution Failure: https://prgmr.com/blog/2020/04/23/debugging-freebsd-resoluti...
The people you talk to when you write us have the authority to investigate and--if correctable on our end--resolve your problem.
I now stick to reputable “value” providers like BuyVM. Having an operator I can discord and get frank answers, as well as a commitment to privacy (Tor exit nodes welcomed), is nice.
For personal hosting I think one of the problems that makes this more complicated is that even as a group, you’re nobody’s biggest customer. You’re just a side business for someone selling hosting B2B, usually. I know that the local grocery store will make sure that they can still sell to local customers, because that’s the core of their business; I’m not so sure that cloud providers care much about my dinky website.
Only if you let them.
Do people seriously NOT perform backups via independent methods utterly independent of their primary cloud service provider?
No one remembers Photobucket or the hundreds of other cloud services that went "poof" into the night?
There is no cloud, just someone else's computer - always have backups of some other means. A different provider with a different account, alternate mechanisms (i.e. email addresses with different email providers, etc.) to get to that data and accounts...
It's even easier now with VM's, snapshots, free open source backup software that understands all of that - fairly inexpensive commercial solutions like veem - there is zero excuse.
My favorite was a small SAAS provider that had all their backup infrastructure on AWS under the same account as the test/dev and operations - and someone got in and deleted it all. Partitioning - yes, it's an essential thing. And not just for technical. Separation of duties. Requiring concurrence by more than one person for critical operations. Lessons that should have been learned from past experience.
Peoples (especially developers) eyes glaze over with documents like NIST 800-53 - but all those controls exist from experience. The bigger/more critical your system is to your survival, the more of those controls you should have answers for!
And fuck me if I'm ever writing a BIND zonefile ever again.
Uh what? Really?
This doubles your failure surface.
These companies are often unstable, so regular backups of anything you might be sad losing are vital. I recommend paying by the month, if that is available, and using this whitelist of low end providers who have been in business for a reasonable length of time[0].
cool name (know the show)
I'll have to check these out I've been using OVH all this time, also GitHub pages is pretty cool.
Notorious for "Deadpooling", providers sell ultra cheap hosts. Run them on over-provisioned servers for a year or two and disappear overnight.
ex: https://tech.slashdot.org/story/19/12/08/1549222/20-low-end-...
What does that mean - what would it mean to "police legal content"?
The "reason Amazon gave" was "content that threatens the public safety, such as by inciting and planning the rape, torture, and assassination of named public officials and private citizens", with examples given in:
https://www.courtlistener.com/recap/gov.uscourts.wawd.294664...
So it's a bad example of something being dismissed for ideological reasons, and a bad example of something whose reasons can be assumed when the answer was easily available.
That's an excellent reason to downvote something. It's simply not accurate.
The "whatever" being any cause they could justify their actions with.
The way it was written, it doesn't surprise me that people didn't read it that way, and downvoted. It comes against a background of people loudly claiming to be oppressed for ideological reasons and failing to support that claim or acknowledging that a serious act of violence has just occurred by people professing the same ideological reasons. At the very least, I felt it was worth pointing out how it reads, so that they might consider it without requiring others to specifically seek an assumption-of-the-best.
Each action was ideological.
Without knowing what reason Amazon gave that leaves me to go look it up; I do, and see various news site quotes including "District Judge Barbara Rothstein sided with Amazon, which argued that Parler would not take down posts threatening public safety." quote on npr.org, and "Amazon told Parler it would boot the company from its web-hosting service [...] because of repeated violations of Amazon's rules" on NYTimes.com, I try to find an official looking source of exactly what reasons Amazon gave and get to the filing for the lawsuit/legal case between Parler and Amazon[1] which includes on page 3 "17. During this same time period, AWS claims that it received reports that Parler was failing to moderate posts that encouraged and incited violence, in violation of the terms of the CSA and AWS’s Acceptable Use Policy (“AUP”). Exec. 2 Decl., ¶ 4; Ex. C (AUP). The AUP proscribes, among other things, “illegal, harmful, or offensive”". It's not clear here whether Amazon is claiming it was illegal or not, or whether it actually was illegal or not.
I google "inciting violence illegal usa" and get to a Cornell Law School[2] page on 18 U.S. Code § 2101 - Riots - saying, abridged, "whoever uses a facility of interstate commerce including but not limited to telegraph, telephone, radio, to incite a riot or promote or organize a riot, or aid or abet any person rioting or commiting any act of violence furthering a riot, shall be fined or imprisoned". Still not clear whether Parler was actually breaking the law or whether Amazon was alledging that they were, or whether this has been decided, or what exact reason Amazon gave.
I know there are arguments about whether hosts are or aren't responsible for content on them, or are just blind transmission systems, but I don't know which way it falls in which scenarios.
It reads more like a complaint about Parler being taken down than a helpful explanation, and could be more clearly and directly said "(policing legal content) means a company removing things against their content policies, even if the things are legal" in as much space and effort.
[1] https://www.courtlistener.com/recap/gov.uscourts.wawd.294664...
And that's assuming they'll actually try to stick to their claim. I find that isn't the case when it is really put to the test.
Un-moderated, or "we have no content policy or acceptable use policy separate from the law".
[0]: https://web.archive.org/web/20190608074736/https://www.nosup...
What they provide to me: a place to upload my static web pages to, period.
What I ask from them: serve these web pages I've uploaded, period.
I don't want or need support for any of that. If something breaks on my part, I can and will diagnose and fix it. If something breaks on their end and they need to fix it, then that's a bug report and not a support request.
In exchange for that, their prices are dirt cheap and perfect for the things I need it for. I couldn't possibly host it myself for the prices they charge me. I think that's a good example of there the business model makes a huge amount of sense for all involved.
Unlike this thing they are both super friendly to all manner of linux nerd stuff yet provide excellent, gracious support where they teach you the stuff you don’t know.
Edit: Apparently their "sister company" sells virtual private servers, and appears to still be alive. http://nosupportvpshosting.com/index.php
The "no vm per user" means any privilege escalation bug lets a hacker wipe it all. And your unsupported customers are probably running all sorts of vulnerable stuff.
Altough not fancy, the security model is actually quite mature. Security problems in these servers come from misconfigured permissions and scripts, not the security stack.
Rather, it was popular software like bulletin boards and blogging platforms that built the demand. PHP used to have one of the lowest barriers to entry because you could get by with plain HTML and incrementally add business logic inline.
Not that I would ever recommend using as a templating language in 2021 :) but it’s cool that it can do that without any external library.
Not quite true. With shared hosting it was (is?) uncommon for a user directory to have ExecCGI enabled. If you wanted scripts to run they had to live in the cgi-bin directory. Additionally mod_rewrite could be expensive on low powered servers. This all meant doing anything dynamic meant "ugly" URLs and meta tag forwards if you were on such a shared host. It was also non-trivial amounts of effort to get some random CGI script working since you needed to know enough to get the shebang path correct for the server and set the right permissions.
Contrast this to PHP where you dropped a .php file into your user directory and you've got some dynamic content. Platforms built on PHP became popular because you could upload them to your user folder and they just sort of worked. There were no special executable paths, no shebangs, and no execute permissions to set.
Perl was huge in the CGI space for a long time but the (consumer) content platforms built on it weren't nearly as successful because of the difficulty of mere mortals getting them running on their shared hosting plans.
There was a reason that in ~2000-2005 you could find PHP shared hosts for $1/$2 month, and that Python/Perl/etc. shared hosts were much harder to find and more expensive. People started using PHP bulletin boards and blogging platforms because at the time it was easier and cheaper to run, but that's an effect and not a cause.
Chroot, containers/jails, SElinux, these are all OSwide and would protect PHP just as much a Python or nodejs. There’s a reason PHP is dying off.
Is there anything like php or bml (bradfitz's equivalent for perl) for python, so that you can put code right in your html to be replaced at serving time with the code's output?
PHP made "deployment" very simple. On the other hand, Python is complicated to deploy even today.
Python is great if you want to run your own server or VM per site. It's not so great if you want to run a shared server and it's shared servers (not VMs) that brought the price down and therefore opened the floodgates of allowing people to run their own sites cheaply and easily.
Just a guess, of course.
People need to stop looking at containers as a cheap way to get security. They might be a more convenient way to get lots of apps running on a single machine, but they're not very secure.
2. It sounds like this paper is mainly about covert channels not side channels. Covert channels assume cooperation between both sides, so they're only relevant if one of the sides can't communicate trivially (e.g. via network)
agreed. AWS gets a lot of flak, but open sourcing firecracker was really great. I'd really prefer to see us move toward vms instead of containers, even if we kept the same k8s abstractions.
> .. covert ..
thanks for the catch, should have taken more time. Here's a better paper:
1. For me containers are one of those abstractions, defined by exposing an application controlled userspace. Containers can be implemented by different isolation technologies, from simple chroot/cgroup/namespaces... to VMs.
2. I'd still use chroot&co to partially isolate containers within a pod, while using VMs to strongly isolate pods from each other. This enables features like shared block-devices, unix-domain-sockets and monitoring the processes in an application container from a separate diagnostics container.
Containers absolutely are intended to be a security boundary.
VMs on the other hand actually are designed as a security boundary, but even then there are still attacks you can do against other VMs on the same box.
A key feature of OS virtualisation is the strong segmentation boundary between
1. Guests
2. Guests and the hypervisor.
For this reason, VMs are seen to provide a stronger security boundary than containers and are used in preference where that aspect is critical owing to environment, multi-tenancy, business context.
See also https://searchcloudsecurity.techtarget.com/tip/VMs-vs-contai...
There's a world of difference between the amalgamation of hacks that comprise cgroups and something like BSD jails, which are and afaik always have been intended to be a security boundary, which implements real first-class kernel isolation for jailed processes, not just another subtree under proc that provides some direction to the kernel around resource consumption/priority and relies on UID/GID hacks to control access.
A minimal VM, like firecracker has a small attack surface, so I'm willing to trust that privilege escalation/VM escapes will be rare.
A process restricted by cgroup/namespace/etc. still has access to the huge API surface exposed by the kernel, so privilege escalation is common, and I'm unwilling to trust this mechanism to isolate malicious code.
They didn't start out at the design phase that way, but they absolutely are today.
This was back in the early 2000's, and still seems to work rather well for the basic webhosting.
[1] https://unit42.paloaltonetworks.com/breaking-docker-via-runc...
Edit: It does login over http, plaintext passwords over the wire. Heh.
As a tip for the future, in case you're interested: you can use hn.algolia.com, search "sudo", time window something like "past month", and you'd have found it.
hn.algolia.com is a great resource and I'm certain not everybody here knows about it.
Though they would have had to also get into the admin server running (probably) WHMCS.
The sudo bug would let a hacker take over a server where the customer code ran, but not the main admin server. They would have needed some other weakness to get that. Perhaps aided by owning one of the customer servers.
https://www.linux-magazine.com/Online/News/Decade-Old-Sudo-F...
Edited to add: Here's another article about it (you should be able to find quite a few more, too):
* Wed Jan 20 2021 Radovan Sroka <rsroka@redhat.com>
- 1.8.23-10.1
- RHEL 7.9.Z ERRATUM
- CVE-2021-3156
Resolves: rhbz#1917729It's even possible that while this seems to be a very likely attack vector that the attacker used something else. One place to look if they had a billing system hit and all their hosting systems is if maybe the billing system got breached first. There are automated provisioning and C&C things built into, say, WHMCS or WHM Autopilot that would be an ideal vector to all the hosting servers if someone breached the billing and provisioning system first.
I don't know how many different individual hosting systems we're talking about. Having a user account to use the sudo vuln on each and every one of them and then also breaching the billing server seems unlikely. It seems more likely the centralized tool was taken over (perhaps using one or a few hosting systems as a springboard) and used to spread to all the hosting systems automatically.
(For context, unless you pay 20% extra for AWS support, you basically get no support. There is a public forum for those that like to scream into the void.)
When there's a thermonuclear strike, we'll mark down the services we think are dead as yellow.
On Google Cloud for over four years, with three kubernetes clusters and a few dozen VMs across three projects... and this thing you describe has never happened. Have you had a different experience with them?
They then are resolved several times without an actual resolution. The last time it happened I only found out in the end it was fixed was because I managed to speak to a member of the technical team for a different reason and enquired.
It was the API Gateway dropping headers that contained underscores that happened for about 6 months last year if it impacted anyone else.
In relative terms though, they are far and away better than the alternatives. At least I can get to speak to people quite easily, and I was able to even speak to folks on the team working on API Gateway and they even got my ticket.
Apache used to silently drop http headers with underscores in them because they state incorrectly that it is against spec, which Nginx then decided to copy in the name of "security" although it was just a flag so could be ignored if you aren't doing CGI scripting.
AWS silently added this to load balancers in 2019 until there was a backlash and they restored functionality, and then tried again to add this to API Gateways in early 2020 until, again, people complained.
HA Proxy doesn't, never did and likely never will because underscores are valid.
https://serverfault.com/questions/855720/how-to-prevent-hapr...
If you pay 29 or 100 per month you get very good support - it HAS too be a loss leader.
If you need it you can pay more and get more
They'll give you general information from your account with the support plan but can't investigate any resources or logs without you owning a support plan on the other account and opening a ticket there.
Also, many companies will have this set up on each account and hardly use it. I don't think it's a loss leader.
That being said, I've definitely had cases where the engineering time to solve a case was worth more than that specific account was paying for support (at least for that month).
That is in stark contrast to other providers to which I give a lot more money, and who can't be bothered to answer in a week... And when they do ally do answer, it takes another full week to do finally have a solution.
As far as what we run on the machines goes (OS, applications) we are fine dealing with that ourselves. It's what we did back when our machines were machines we owned at a colocation facility, and its not much different when its on a VM at Amazon.
When something goes wrong that affects us and requires AWS intervention, 99.9% of the time it is something that is going wrong for many other people too, some of those will have paid support and bring it to Amazon's attention if it isn't something Amazon notices on their own, and when Amazon fixes it that fix will fix it for all of us.
I can only recall one time it didn't work that way. I was trying to track down a problem with our applications that involved something whose processing involved steps on three different systems. I needed to rely on the logs from those three systems to figure out the order things had happened in, and it was making no sense. I checked the clocks, and found that the three systems had wildly different notions of time.
It turned out that the clocks on some of our instances were ticking at the wrong rate. They were ticking at steady rates, and normally the time code in Linux systems can figure out how far off the rate is and apply a correction, but some of the AWS instances had rates that were something like an order of magnitude more than the Linux code can deal with.
We found some other people talking about this in the forums, but it apparently wasn't hitting anyone with paid support. Someone finally bought some paid support and reported it, and it got fixed. (It turned out that it had only affected one fairly small instance type, and only an older version of it that you were supposed to migrate away from over the next few months, which made it so that only a very small fraction of VMs were affected).
2) Hosting is getting more expensive because cPanel keeps jacking up prices, and I strongly suspect that this host threw in the towel due to the severity of the compromise but also the razor thin margins. Digging out from under it was likely more trouble than it was worth, especially if they didn't have insurance for this kind of thing.
3) KEEP YOUR OWN BACKUPS. For the love of all data that is important, keep your own backups. Did I mention that anyone with a website on any provider on any continent should keep their own backups? By all means, keep your own backups. Because if you don't keep your own backups, you'll wish you'd kept your own backups.
There's also Plesk, but let's face it. Nobody likes Plesk.
To add the rest of my usual mantra: AND TEST YOUR BACKUPS.
Memories of the look on someone's face when I had to tell them that their laptop drive was truly dead (unless they wanted to pay a data recovery company a pile o' cash) and the USB stick they'd been saving copies of important documents too appeared to be silently corrupting everything written to it...
Classic response :)
How dare they simply delete everyone’s content? That’s on another level of stupidity and/or evil.
It's not the "no support" part that concerns me, is that they've pocketed the customers money until there was a major problem, then just shut down, customers be damned.
Sounds like someone placed a server in their basement, added cPanel and a PayPal link and totally ignored whatever happened to that server.
I guess you get what you pay for.
Really, not everything on the web needs to be mission-critical.
> All customers should immediately download backups of their websites and databases through cPanel.
Another poster pointed out they pocket around ~70k/year so I don't think it's that.
A cheap low reliability non-spammy service is a pretty good niche for hobbyists. Who cares that it shut down. It did a job while it lasted.
No cost, good discoverability, easy updates...just sucks for those of us who won’t use the platform.
That explains how they could so easily offer ipv4 addresses with their vps offerings on the sister site.
internet vandalism saddens me.
Welcome to 99% of shared web hosting businesses.
WHM + cPanel is the combo you need to know if you ever want to run a webhosting company.
I know I'm going to get flack for victim blaming, but not putting something like cPanel behind a VPN or SSH reverse proxy is on the same level as not wearing a seatbelt. At this point we should all know better, and those who don't will have to suffer the consequences.
It's a pretty significant barrier and dramatically reduces the amount of attack surfaces out there.
Mobile/Desktop OS's have come a LONG way in VPN support, so requiring VPN access for critical access (and administrative access should always be considered critical!) is not near the barrier of entry it used to be. Heck anyone can set a VPN server up on a raspberry pi in minutes that can handle hundreds of megabits of traffic - piVPN with Wireguard is drop dead simple to configure and deploy (WAY easier than the mess that is OpenVPN); the amount of friction to implement a VPN these days is just about negligable. It's a harder problem for service providers like this one that have thousands of customers - but they certainly had some sort of user account management/provisioning system; it' way past time to expect those to be able to handle security certificate management too.
It's far less effort than cleaning up messes like the one being profiled here! And if you have sensitive data? Once your system is compromised it's no longer sensitive. It's now public knowledge :p
Exactly. It's astonishing at the amount of crap that has absolutely no business being directly connected to the Internet but shouldn't be.
Convenience or security - it's either/or not a yes/yes.
Anyone know of any similar services one might procure?
Asking for a friend...
If you're okay without Cpanel, there's a bunch of providers advertising dirt cheap VPS instances on https://lowendbox.com.
As this thread indicates, though, you get what you pay for.
If you are fine doing your own setup and have low resource needs, you can get a 1$/month VM from a number of places. Cheaper if your resource needs are really low, or you don't need a dedicated IPv4 address.
There are even search engines collating them, https://www.serverhunter.com/ for instance. Just do a little background research before picking the cheapest, if you care anything for what you host.
Think I still had like 6 bucks in my account with them, but frankly, who gives a shit. The cheapness of the service was baked in such that eating a couple of bucks doesn't really matter. We had a good run of 4-5 years. Sad to see them go though.
Might just be the end of the road for that site as I’m not about to spend more than $12/year to keep it going.
If you don't want to maintain a legacy app liable to be compromised, going static using wget + a few scripts is a lovely trick.
No maintenance, no pain, and free hosting :)
I personally doubt static websites will go out of fashion anytime soon.
Given the name "nosupportlinuxhosting.com" I would expect many using the service to ba capable of knowing/understanding "apt install nginx php-fpm" and so forth.
Though obviously cPanel and its ilk still offer some time-saving convenience even if you could setup everything yourself.
Alternatively PaaS like Google's App Engine have 'always free' tiers sufficient for hobby sites.
Do hackers have a copy of all customer data?
NSH was my go to for years for quick unimportant sites. Like a decade ago. They actually were very helpful the once or twice I contacted them (trying to get bigger instances). And $1 a month!
Fine for simple static hosting, or a bit of low concurrency more-dynamic server-side stuff, or running simple services like DNS.
Aka you're on your own...
My guess is that if it was worth starting fresh, they did so with a new brand that makes no mention of the old service.
There were significant changes to cPanel licensing not long ago which caused some consternation as it would result in some hosts needing to pay more. IIRC it moved from a per-server model to per-user, with a block of users included in the minimal fee so for small hosts the change had no effect, but for a host like this with many small accounts the extra cost there would make already small margins even more tenuous.
Presumably the little profit still made was better than nothing if the maintenance needed was minimal, but not (for this reason and/or others) large enough to be worth the rebuilding effort after this attack.
That's interesting. And it would have hit those providers that were grossly oversubscribing the hardest. Guessing this service was in that bucket.
Rebuilding their clientele after a unmitigated disaster like this would probably take so much time that they would never get back in the black, especially since they are trying to do it on $12/year per customer. That requires a LOT of customers and they will have lost most of their existing ones before they would be able to rebuild.
Add on that they probably have outdated software, probably a lot of it custom/customized, that have unknown security holes...
Then advertising themselves as a hosting site for experienced people makes all this mess quite poetic.
They probably have been slowly losing customers for years.
Heck, for $5/mo and a setup fee you can sometimes get a small dedicated server (only an Atom CPU, but 500Gb storage and half decent bandwidth) from Kimsufi and their ilk.
Whether NSLH is shutting down or not, it's a good time to make backup copies.
I'd love to know the types of sites they hosted. Anyone here have the skillz to find out?
My bet is on slimming tablets and viagra sales.
The model of course is shared IP so there are dozens, even hundreds of sites at the same IP address.
I did some kind of lookup once to see who shared an IP with my site. It was stuff like churches, auto repair shops, high school kids experiments, plumbers. This was before Wix and friends. There was nothing scammy or spammy I saw on that particular IP anyway.
Its also nice to know that a low price point doesn't automatically act as a bad-player magnet.
Since they apparently had a class C one could look at each IP to find the rest of the sites.