Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


DDoS protected cPanel shared host
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

DDoS protected cPanel shared host

IThinkUFailedIThinkUFailed Member
edited May 2015 in Requests

Hi!

One of my sites has been getting regular floods which I've been told are similar to Syn Floods.

I tried one service provider whos network was just not picking up the DDoS correctly and thus not being able to mitigate it. I don't hold this against them though.

We're after something along the lines of 20GB although currently using only 8gb roughly storage for this site which is an addon domain to another so we will need one addon domain.

We require regular backups preferably off site. We're kind of wanting to make sure we'll be protected and that as a guarantee.

We're willing to pay a decent amount.

We'd prefer a European location but anywhere works really... We would ideally like UK or very close located EU locations. US Location will need to have excellent routing to Europe.

We may also be investing in a CDN once we're back up. The site only gets about 50-100 visits a day so we are on a budget. We do need GMP enabled as our site uses it to convert currencies.

If you think you can help us and you are willing to help us get protected as decently as possible within a budget.

bandwidth? We don't use much so a maximum of 200GB ... Usually under 15GB/mo. (Average is about 50-100 visitors a day.)

I have not really got a specific budget in mind but less than $15/mo would be ideal...

If you need more information on the site in question before you post an offer then please PM me.

Site is a wordpress site running WooCommerce not sure that really affects anything at all. So a person who is familiar in protecting wordpress based sites would be preferred as our host ;). (We do run WordFence for security and a cache plugin already)

Comments

  • JonchunJonchun Member

    @IThinkUFailed said:
    Hi!

    One of my sites has been getting regular floods which I've been told are similar to Syn Floods.

    I tried one service provider whos network was just not picking up the DDoS correctly and thus not being able to mitigate it. I don't hold this against them though.

    We're after something along the lines of 20GB although currently using only 8gb roughly storage for this site which is an addon domain to another so we will need one addon domain.

    We require regular backups preferably off site. We're kind of wanting to make sure we'll be protected and that as a guarantee.

    We're willing to pay a decent amount.

    We'd prefer a European location but anywhere works really... We would ideally like UK or very close located EU locations. US Location will need to have excellent routing to Europe.

    We may also be investing in a CDN once we're back up. The site only gets about 50-100 visits a day so we are on a budget. We do need GMP enabled as our site uses it to convert currencies.

    If you think you can help us and you are willing to help us get protected as decently as possible within a budget.

    bandwidth? We don't use much so a maximum of 200GB ... Usually under 15GB/mo.

    I have not really got a specific budget in mind but less than $15/mo would be ideal...

    If you need more information on the site in question before you post an offer then please PM me.

    Site is a wordpress site running WooCommerce not sure that really affects anything at all. So a person who is familiar in protecting wordpress based sites would be preferred as our host ;). (We do run WordFence for security and a cache plugin already)

    I can do this for you in NL. Staminus filtering. PM me if you want to work something out.

  • IThinkUFailedIThinkUFailed Member
    edited May 2015

    @Jonchun said:
    I can do this for you in NL. Staminus filtering. PM me if you want to work something out.

    Sent you a message. Thanks for replying.

  • raindog308raindog308 Administrator, Veteran

    @Francisco and http://buyshared.net/ is another option in Luxembourg, though I'm not 100% certain they DDOS-protect their shared.

  • FranciscoFrancisco Top Host, Host Rep, Veteran

    @raindog308 said:
    Francisco and http://buyshared.net/ is another option in Luxembourg, though I'm not 100% certain they DDOS-protect their shared.

    Neeeeeewp.

    If users want filtering they can pay the reasonable rates we charge for a VPS + voxility filtered IP address. If OP is kosher with VestaCP or something similar then we could get well under his budget.

    cPanel is $11/month + everything else.

    Francisco

  • @Francisco said:
    cPanel is $11/month + everything else.

    Which does push it out of my range but you are in my considerations regardless as I said under $15 per month would be ideal but we'll cross that bridge if need be. I know Francisco offers a quality product so wouldn't mind paying the premium. I also don't know how well cPanel would run on the 512MB vps you suggested so that may play a factor as well...

    Thanked by 1Francisco
  • JonchunJonchun Member

    @Francisco said:
    Francisco

    Just putting it out there, another reasonable solution would be to setup a nginx reverse proxy on the small VPS + voxility filtered IP, then proxy it to BuyShared. You'll get the backend security/stability of BuyShared + a nice static content cache + ddos filtering.

    Of course, this takes a little bit more skill than a VPS+vesta, but hey thought I'd put the solution out there in case anyone else was interested. I'm sure if you ask nicely enough, @Francisco might even help you configure the reverse proxy.

  • @Jonchun said:

    Very useful information even if it isn't really applicable to me. Thanks!

  • You might wanna check our packages: https://mrapidhost.com/plans.html

  • @IThinkUFailed from what I've seen, the most common security issue would be "wplogin". Is that properly secured as well?


    cPanel will be quite okay but since it's an ecommerce store, perhaps you should consider running it on your own server with or without cPanel.

  • belinikbelinik Member
    edited May 2015

    @Jonchun said: Just putting it out there, another reasonable solution would be to setup a nginx reverse proxy on the small VPS + voxility filtered IP, then proxy it to BuyShared. You'll get the backend security/stability of BuyShared + a nice static content cache + ddos filtering.

    this, the lowest package plus buyshared should be well under your budget.

  • @belinik said:
    this, the lowest package plus buyshared should be well under your budget.

    This is actually the method being tested as of currently with Jonchun who has been very accomodating

    @century1stop said:

    IThinkUFailed from what I've seen, the most common security issue would be "wplogin". Is that properly secured as well?


    cPanel will be quite okay but since it's an ecommerce store, perhaps you should consider running it on your own server with or without cPanel.

    We use 2 factor authencation on the WP-login and we're also running wordfence security.

    Only one user has administrative rights and it's changed from the default user too. The password securing it is over 20 characters fully randomized.

    We try to take security as serious as possible.

  • @IThinkUFailed glad to hear that. well if you need DDoS mitigated hosting and/or budget KVM, just let me know. Currently running a 30% recurring discount.

  • Only WordFance wont protect you in wordpress. You need another firewalls to block the IP's that are trying access your WP-Admin. The best option is to go with Managed Services and let the Pros do the hard things for you.

    I hope you will find your desired provider. Good luck.

    Regards,
    Gregory

  • IThinkUFailedIThinkUFailed Member
    edited May 2015

    @MisterHost_NET said:
    Only WordFance wont protect you in wordpress. You need another firewalls to block the IP's that are trying access your WP-Admin. The best option is to go with Managed Services and let the Pros do the hard things for you.

    I hope you will find your desired provider. Good luck.

    Regards,
    Gregory

    We have firewalls blocking the IPs. We also have 2 Factor auth to protect us. Currently Jonchun's proxy method is looking like it will work. The issue was never the security of my sites as we take precautions as best as possible and the host also deals with bruteforcers and such too. The issue at hand was the site was under a flood and needed protection from the flood.

    I specified we run WordFence simply to show we try our best with security mainly and do try to keep ourselves protected as best possible on a shared platform.

  • belinikbelinik Member

    the buyvm proxy behind the ip should work quite well. just make sure you don't accidentally expose your buyshared ip to public, dns record or mail.

  • @belinik said:
    the buyvm proxy behind the ip should work quite well. just make sure you don't accidentally expose your buyshared ip to public, dns record or mail.

    Of course. @Jonchun is working hard to get everything working flawlessly and I've got every bit of faith in him. He's been working with me to optimize the proxy method and a few other tweaks to make sure it does what it needs to. So far so good.

  • century1stopcentury1stop Member
    edited May 2015

    couldn't you just implement SYN flood accordingly in csf? That's what I did with cPanel server and the only problem left was wplogin security issue.

  • @century1stop said:
    couldn't you just implement SYN flood accordingly in csf? That's what I did with cPanel server and the only problem left was wplogin security issue.

    Unsure as I don't have root access or access to any firewalls as I'm only on shared hosting... We also want the site to be better protected in general because of the general nature of the market we're selling towards (Selling CD keys to games and thus meaning we deal with the DDoS happy gamers that seem to riddle the internet now).

  • definitely but make sure you don't block any legit traffic, it happens....... can't be overly secure

  • @century1stop said:
    definitely but make sure you don't block any legit traffic, it happens....... can't be overly secure

    But... if no traffic comes in that means no bad traffic can either! It's fool proof!

    In all seriousness. We're trying to protect ourselves without the cost being too extreme and what Jonchun is doing looks like it will suit our needs perfectly.

  • yup optimum levels will do.

    best of luck with your porn cd's then.....

Sign In or Register to comment.