VPS provider (Hetzner) suggesting attacks coming from my machines

I don’t know Hetzner per se, but you should have access to “remote console”. It is independent what you are running on the server and it is accessible whenever the server is on. You should have access to it somewhere under your account on Hetzner web.

@DavidMc0 imo that’s ‘blackbox invoked scanning’ based on suspect behaviour profiles Hetzner conjured up, which is, to say the least, inconvenient.

It’s not permissioned scanning, really Hetzner should seek a court order, or be telling the customer the government has invoked a court order and told them to do it, justifying their reasoning to invoke the scan on your traffic.

Hetzner cant just turn on that stuff and start blocking traffic (unless its turning into HH over there aka the 1930s).

Oh I forgot, they just do what they want… ;/

I’d get a legal opinion and push back, politely and firmly and slip the lawfare into the conversation during the chat. ie “Should I seek legal advice? , I asked myself and, of course I did that…” , It might be in Hetzner’s Terms of Service , that they can do stuff like that, so have a look before engaging, :wink:

2 Likes

not at hetzner, the server ALDI…

you can reboot into a pxe booted vnc-kvm to see whatsup, for the rest you’re in the dark if the server doesnt boot…

1 Like

Has anyone had a older version of safenode running by any chance and still got this flag from Hetzner?

A friend of mine has not updated his nodes for a few weeks, other than that running identical setup. He however did not get flagged. This may indicate it’s something in the most recent update. Can anyone verify?

Similar problem again, got mail from what seems to be every server. Seems it might be linked to when network encountered stress this night, maybe all nodes which went down was on Hetzner and when those alive trying to reconnect it triggers their automatic detection system?

2 Likes

Same again here… hopefully they’ll say it’s an error again. Frustrating!

1 Like

Was anyone using DO affected?

Hmmm what do nodes do when the network cable gets plugged out? Do they start checking if connection returns in intervals or do they go bonkers and try reconnecting to every possible peer like crazy so it does look like an attack when the network finally gets plugged in again and 100 nodes are hammering against the door?

7 Likes

Same this night, got new mails from Hetzner for all servers as the network lost a lot of nodes during the night.

1 Like

Same… loads here… getting annoying!

1 Like

I have five nodes running on a cheap Hetzner VPS with no emails so far.

2 Likes

Maybe they were not connected to the 10-15k nodes which went down last night? Just a feeling that it has something to do with that.

I think 5 nodes is simply not enough connections (to the same destination) to be considered a port scan

I’d assume @tobbetj and @DavidMc0 are running powerful dedicated servers with around 100 nodes or so

2 Likes

I’ve been in touch with Hetzner and they mentioned they’re working on a fix to resolve these false positive flags from happening.

Think it’s good news to hear they acknowledge they are indeed false positives and that they’re actively working to prevent it from happening again.

4 Likes

They locked my server though…

1 Like

Hetzner needs to get their shit together, they sent my provider an email saying one of my servers carried out a port scan attack on them. WTF ya’ll need to spread out a bit and stop pilling in on a single provider like Hetzner.

2 Likes

Highlights the need for decentralization.

4 Likes

Seems 90% of Autonomi is on Hetzner, why are they the number one choice?

They are bound to get aggravated soon.

2 Likes

Value for money
Easily accessible for most
Normally excellent service
I kept posting my affiliate link as did others

Previously I worried that most of Autonomi was on Digital Ocean
They are (IMHO justifiably) upset that many folk have taken cheap offers and abused the ToS by running CPU intensive nodes on machines which specifically state that they are unsuitable for that task

Its their hardware and they can make the rules.

2 Likes

It was the best value when I was looking (using their server auctions), and they’re pretty easy to set up and use.

I will look for alternatives.

4 Likes