Hetzner Hostage
wlad.svbtle.com
wlad.svbtle.com
http://www.ovh.com/us/blog/a1171.protection-anti-ddos-servic...
And:
http://forum.ovh.co.uk/showthread.php?6661-URGENT-AND-IMPORT...
"Our surplus network has a capacity over 2 Tbps. We have three VAC in production, so we can manage up to 480 Gbps/480 Mpps."
I did this due diligence for a 10-user app. These guys have no excuse for not planning for a DDoS with a serious business.
They got DOSed so Linode shut them down, then they found a new provider but had problems moving to them since they couldn't get into the linode server to copy the data.
http://www.whaleoil.co.nz/2014/01/ferals-faults-fixes-co-pil...
With a single provider, it's a gamble, although the expectation for any reasonable provider is that they just let you saturate your link speed with no questions asked, and block the offending traffic in their router if you can identify it for them.
I guess the original post perfectly explains how such low prices are attainable (no customer support, etc).
I'm picturing a setup where you run on a cheap Hetzner host or similar with the DB synced to a slave replica on EC2 or other cloud provider and a build system so that you can spin up a whole replacement infrastructure on EC2 if there is a severe outage or failure in commercial relationship and switchover by changing the DNS settings.
cloudflare adds a direct.* subdomain that points to your actual IP.
One of my servers were once used in a amplification attack (DNSSEC...) for a few days before I noticed. I guess Hetzner didn't detect this because just the uplink got saturated. Had to manually request a null route so I could SSH to another IP alias on the box. I wouldn't mind if they automatically did this for me since the offending IP would be unavailable either way. At least they don't charge you for DDoS traffic, like my current European budget provider does.
If you move to something like Cloudflare, make sure to at least firewall off everything but their IP addresses. Otherwise it will be trivial for the attacker to connect to all the port 80's in the IP allocation to the provider they know you were using, and compare the responses to what they get from Cloudflare, to obtain your service's origin.
Doesn't sound like they have changed at all in the interim.
As others have mentioned they've got DDOS protection on some of their newer plans.