Stay away from Digital Ocean
gsundeep.com
gsundeep.com
1) They shut down my servers and suspended my account without notifying me. If your server is doing 1Gbs outbound I would expect them to shut it down ASAP for many reasons. Likely a more senior person detected the issue and shut down the server, then passed it on to 1st line support to contact you.
2)After contacting them, they immediately accused me of "launching an attack from their platform". You launched an attack vs a sever you are responsible for launched the attack, it's semantics but the support agent could certainly have worded it better, but not a big deal in my view.
3)After they performed their "investigation", they refused to give me any details and kept my account locked and servers offline. The investigation probably wasn't any more than their networks team detecting very high outbound traffic originating from your VPS IP that was clearly malicious. In that case the only explanations are that you are deliberately breaking their terms or your server is compromised, there is nothing else to discuss. They should really have sent you some standard text helping realise the reality of the situation but it wouldn't have hanged anything.
4)They refused to give me a copy of my data which delayed getting it hosted elsewhere (had to get ssl certs reissued etc). This is not great but if your server is compromised you have to accept that you will need to work from backups. First line support probably don't have a way of getting the data without starting the machine which they can't do in the circumstances. I'm sure one of their sysadmins could mount the virtual machine as a disk image to get the data for you, but that's not part of the service they offer or you're paying for. They can probably get your data given time and/or if you pay them but it's not reasonable for them to do this as a priority, especially as they are a budget host.
If the server is compromised then it should be permanently shut down immediately.
Seriously though, why not be nice first, and ask for the things you need, before saying you are gonna post publicly about something. You have to consider that maybe the person communicating with you is just a support flunky that doesn't know how to grab the data you need off of your disk images.
Think of the amount of skilled labor they would need to expend to get your data off the disk images. Even if its just an hour, most engineers cost $80-100/hour. If you are paying $5/month for your basic Digital Ocean instance, that means more than a year worth of revenue on your account needs to be spent to make you whole, because you fucked something up and allowed a third party to exploit your server.
If you don't make backups and don't administer your websites correctly, I think Digital Ocean will probably be happy to see you go, since you are probably a negative revenue customer in the long run. They send you to Amazon or Google with their blessings.
edit: they should definitely have emailed you to let you know that they were suspending your account though.
In Case anyone wants to check.
The Blog Post : http://serdardogruyol.com/?p=122 The HN Thread : https://news.ycombinator.com/item?id=6438761
1. Backup your data offsite.
2. Monitor your servers or at the very least, your sites. If a site is important enough to pay for hosting, I would think it would be important enough to monitor for uptime. Bonus points for monitoring server resources as well.
3. Trust noone. Who's to save Linode, Amazon, or Google would act any differently if they detected a compromised server on their network.
These things should be done regardless of how much you are paying for your hosting.
Coincidentally, early this morning, I received a notification email from a droplet i own. It(my security agent process) had noticed repeated attempts to login and that it had blocked the offending IP address. When i traced the IP address, it was from Digital Ocean's network!
I am getting unnerved with all of this. Looks like DO is now a popular target for hackers. I would think the vast majority of droplets (despite their owners trying to keep things secure to the best of their knowledge) don't have much of a chance against a sustained attack by a capable and determined hacker.
So yes, I agree that keeping as near to real-time backup as possible seems to be the only takeaway from all of this (assuming that we would want to continue with such a discount hosting provider).
I think they're probably inundated with novices who don't do basic securing of their VPSes and experiencing a lot of abuse as a result.
At least some sort of notification should be in place.
What Digital Ocean did here seems completely reasonable.
So you get what you pay for, I wouldn't move my money making sites to a service like that.