19/10/2014 - Patched Poodle SSLv3 Vulnerablity
We were recently notified about the poodle sslv3 vulnerablity on all of our servers. More information
Gird your loins, sysadmins: The Register has learned that news of yet another security vulnerability - this time in SSL 3.0 - is probably imminent. (And indeed so it turned out to be - the Poodle vuln. You heard it here first. - Ed)
Maintainers have kept quiet about the vulnerability in the lead-up to a patch release, which is expected in in the late European evening, or not far from high noon Pacific Time.
Details of the problem are under wraps, purportedly due to the severity of the vulnerability. El Reg cannot confirm whether or not it is indeed a serious bug as we have not received details of the vuln.
To that end, it is unknown what platforms were impacted, but as SSL is very widely used, any flaw will require plenty of urgent attention – and probably be unwelcome news to a tech community already reeling from the recent Shellshock vulnerability in Bash and the Heartbleed flaw.
The SSL flaw won't be the only thing keeping security bods and system administrators busy. A dangerous worm has been discovered exploiting a zero-day flaw (CVE 2014-4114) in all versions of Microsoft Windows and Server 2008 and 2012.
The Register will provide more information on the flaws as we hear more.
Terms of Services
Revision date: 5/19/2013
All services provided by vps4.me ("vps4.me") may be used for lawful purposes only. Transmission, storage or presentation of any information, data or material in violation of any United States federal, state or city law is prohibited. This includes, but is not limited to: copyrighted material, material we judge to be threatening or obscene, or material protected by trade secret and other statute. The subscriber agrees to indemnify and hold harmless vps4.me from any claims resulting from the use of service which damages the subscriber or any other party.
Prohibited are sites that promote any illegal activity or present content that may be damaging to vps4.me' servers, or any other server on the Internet. Links to such materials are also prohibited.
Examples of unacceptable content or links:
Child Porn
Zeus Bot
Carding Bots
Exploits
Spamming
NOTICE: IF YOUR ACCOUNT IS FOUND TO CONTAIN ZEUS BOT, CHILD PORN, CARDING BOTS, EXPLOITS YOUR ACCOUNT WILL BE TERMINATED IMMEDIATELY, WITHOUT NOTICE.
Traffic Usage
All account plans come with a predetermined amount of traffic allowance.
Server Abuse
Any attempt to undermine or cause harm to a server or customer of vps4.me is strictly prohibited. As our customer you are responsible for all your accounts. Should you violate the Terms of Services outlined within, your account will be cancelled without chance of refund.
Refusal of Service
We reserve the right to refuse, cancel or suspend service, at our sole discretion.
All sub-networks, distributive hosting sites and dedicated servers of vps4.me must adhere to the above policies, with the exception of system resources in respect to dedicated servers.
Billing
By the Account Activation Date of each month, vps4.me shall either:
(1) debit the client's credit card (when such information has been provided by the client); or
(2) deliver, by e-mail or regular mail, an invoice in accordance with the applicable Service Fees for services rendered for the current month. When an invoice is delivered to the client, payment shall be remitted to vps4.me by no later than the specified payment due date. vps4.me shall be entitled to immediately terminate this agreement for client's failure to make timely payments. You will be provided with an invoice on a monthly basis. All credit cards are billed automatically on a monthly basis. It is the client's responsibility to ensure that they have sufficient credit to cover this transaction. In the event that there is insufficient credit, we will send an e-mail notification, at which point we will need to be provided with another credit card account number within 24 hours. If we do not receive a response within 24 hours, the account, and all accounts under that account plan, will be suspended.
Service Fees
Certain services carry a setup fee charged by vps4.me to client, which must be paid by client in order to have use of said services. If client terminates this agreement, client shall be responsible for any and all outstanding fees owed to vps4.me and agrees to pay any and all fees incurred by client. Because the services are provided on a monthly basis, the client will be responsible for service fees incurred each month, regardless of when client provides notice of termination. Thus, for example, if the client provides notice of termination on the 15th day of a particular month, the client will be responsible for service fees for the entire month, and such fees will not be pro-rated or refunded.
Money back guarantee & refund policy
We do not generally refund cancelled contracts. For example, if your contract is quarterly and you request a refund after two months, no refunds will be admitted. No refunds are issued for setup charges, add-on charges, domain-registrations, add-on purchases, SSL certificates or overage charges. In case of AUP violations, any and all refunds are forfeit.
Account Deactivations
Any account deactivated due to non-payment will require a reactivation fee of $10.00 prior to reactivation.
Cancellation Refunds
We DO NOT refund partial monthly fees to accounts. We require 30 days notice for a cancellation.
Refusal of Service
We reserve the right to refuse, cancel or suspend service, at our sole discretion.
Limitation of Liability
vps4.me shall not be responsible for any claimed damages, including incidental and consequential damages, which may arise from vps4.me ' servers going off-line or being unavailable for any reason whatsoever. Furthermore, vps4.me shall not be responsible for any claimed damages, including incidental or consequential damages, resulting from the corruption or deletion of any web site from one of vps4.me ' servers. All damages shall be limited to the immediate termination of service.
Violations
Violations of these Acceptable Use Policies should be referred to support@vps4.me. All complaints will be investigated promptly. Failure to follow any term or condition will be grounds for immediate account deactivation.
Disclaimer
vps4.me cannot be held liable for system down time, crashes or data loss. We cannot be held liable for any predicated estimate of profits which a client would have gained if their site was functioning. Certain services provided by vps4.me are resold. Thus, certain equipment, routing, software and programming used by vps4.me are not directly owned or written by vps4.me. Moreover, vps4.me holds no responsibility for the use of our clients' accounts. Failure to comply with any terms or conditions will result in the automatic deactivation of the account in question. We reserve the right to remove any account, without advance notice for any reason without restitution, as vps4.me sees fit.
Account Activation
By activating your account with vps4.me, you agree to the above policies and disclaimer. Upon requesting activation of an account, you are required to accept these policies, guidelines and disclaimer, and a copy of your acceptance is forwarded along with your activation request to be maintained with your account information.
NOTICE: If you sign up for an account and fail to comply with these terms, no refunds will be given. We will, however, advise you by e-mail or phone prior to taking any action to provide you with an opportunity to correct the problem.
Server Uptime Guarantee
Although vps4.me has an excellent record for reliability, we do not offer an uptime guarantee. However, our network and servers are monitored continuously, and are rarely down except for scheduled maintenance and hardware and software upgrades.
vps4.me reserves the right to amend any or all of the above policies, guidelines and disclaimer without notification. We also retain the right to increase any pricing and make changes to our account plans without notification.
Privacy
Revision date: 5/19/2013
vps4.me has created this privacy statement in order to demonstrate our firm commitment to privacy. The following discloses the information gathering and dissemination practices for this Web site.
Information Automatically Logged
We use your IP address to help diagnose problems with our server and to administer our Web site. We use this information for no other reason.
Order Forms
Our site uses an order form for customers to request services. (256 bit encryption). We collect sensitive information which is used only for our purpose, not third party receives any type of information from us.
Contact information from the order forms is used to get in touch with the customer when necessary.
Billing information that is collected is used to bill the user for services.
Unique identifiers are collected from Web site visitors to verify the user's identity.
Demographic and profile data is also collected at our site.
We use this data to tailor our visitor's experience at our site showing them content that we think they might be interested in, and displaying the content according to their preferences.
Security
This site has security measures in place to protect the loss, misuse, and alteration of the information under our control. We use strong SSL encryption to ensure your privacy.
Third Parties
Information collected on this site is strictly for our use, NO OTHER OUTSIDE PERSONS MAY VIEW YOUR PERSONAL INFORMATION SUCH BILLING INFORMATION, ETC.
Contacting the Web Site
If you have any questions about this privacy statement, the practices of this site, or your dealings with this Web site, you can contact: support@vps4.me
Acceptable Use Policy
Revision date: 5/19/2013
As a provider of web site hosting and other Internet-related services, vps4.me offers its customer (also known as "Subscribers") and their customers and users the means to acquire and disseminate a wealth of public, private, commercial and non-commercial information. vps4.me respects that the Internet provides a forum for free and open discussion and dissemination of information. However, when there are competing interests at issue, vps4.me reserves the right to take certain preventive or corrective actions. In order to protect these competing interests, vps4.me has developed an
Acceptable Use Policy ("AUP"), which supplements and explains certain terms of each customer's respective service agreement, and is intended as a guide to the customer's rights and obligations when using vps4.me' services. This AUP will be revised from time to time.
One important aspect of the Internet is that no one party owns or controls it. This fact accounts for much of the Internet's openness and value, but it also places a high premium on the judgment and responsibility of those who use it, both in the information they acquire and in the information they disseminate to others. When subscribers obtain information through the Internet, they must keep in mind that vps4.me cannot monitor, verify, warrant or vouch for the accuracy and quality of the information they acquire. For this reason, the subscriber must exercise his or her best judgment in relying on information obtained from the Internet, and also should be aware that some material posted to the Internet may be sexually explicit or otherwise offensive. Because vps4.me cannot monitor or censor the Internet, and will not attempt to do so, vps4.me cannot accept any responsibility for injury to its subscribers resulting from inaccurate, unsuitable, offensive or illegal Internet communications.
When subscribers disseminate information from the Internet, they must keep in mind that vps4.me does not review, edit, censor or take responsibility for any information its subscribers may create. When users place information on the Internet, they have the same liability as other authors for copyright infringement, defamation and other harmful speech. Also, because the information created is carried over vps4.me' network and may reach a large number of people, including both subscribers and non-subscribers of vps4.me, subscribers' postings to the Internet may affect other subscribers and may affect vps4.me' goodwill, business, reputation or operations. For these reasons, subscribers violate vps4.me policy and the Service Agreement when they, their customers, affiliates or subsidiaries engage in the following prohibited activities:
Facilitation a Violation of this AUP:
Advertising, transmitting or otherwise making available any software, program, product or service that is designed to violate this AUP, which includes the facilitation of the means to spam, initiation of pinging, flooding, mail bombing, denial of service attacks and piracy of software.
Usenet Groups:
vps4.me reserves the right not to accept postings from newsgroups where we have actual knowledge that the content of the newsgroup violates the AUP.
Other Illegal Activities:
Engaging in activities that are determined to be illegal, including, but not limited to, advertising, transmitting or otherwise making available ponzi schemes, pyramid schemes, fraudulently charging credit cards and pirating software.
Other Activities:
Engaging in activities, whether lawful or unlawful, that vps4.me determines to be harmful to its subscribers, operations, reputation, goodwill or customer relations.
As we have pointed out, the responsibility for avoiding harmful activities just described rests primarily with the subscriber. vps4.me will not, as an ordinary practice, monitor the communications of its subscribers to ensure that the comply with vps4.me' policy or applicable law. However, when vps4.me becomes aware of harmful activities, it may take any action to stop the harmful activity, including, but not limited to, removal of information, shutting down a web site, implementing screening software designed to block offending transmissions, denying access to the Internet, or any other action deemed appropriate by vps4.me.
vps4.me is also aware that many of its subscribers are themselves providers of Internet services, and that information reaching vps4.me' facilities from those subscribers may have originated from a customer of the subscriber or from another third party. vps4.me does not require its subscribers who offer Internet services to monitor or censor transmissions or web sites created by customers of its subscribers. vps4.me reserves the right to directly take action against a customer of its subscribers. Also, vps4.me may take action against the vps4.me' subscriber because of activities of a customer of the subscriber, even though the action may affect other customers of the subscriber. Similarly, vps4.me anticipates that subscribers who offer Internet services will cooperate with vps4.me in any corrective or preventive action that vps4.me deems necessary. Failure to cooperate with such corrective or preventive measures is a violation of vps4.me policy.
vps4.me will not intentionally monitor private electronic mail messages sent or receive by its subscribers, unless required to do so by law, governmental authority or when public safety is at stake. vps4.me may, however, monitor its service electronically to determine that its facilities are operating satisfactorily. Also, vps4.me may disclose information, including, but not limited to, information concerning a subscriber, a transmission made using our network, or a web site, in order to comply with a court order, subpoena, summons, discovery request, warrant, statute, regulation or governmental request. vps4.me assumes not obligation to inform the subscriber that subscriber information has been provided and, in some cases, may be prohibited by law from giving such notice. Finally, vps4.me may disclose subscriber information or information transmitted over its network where necessary to protect vps4.me and others from harm, or where such disclosure is necessary to the proper operation of the system. However, vps4.me will never sell information to other services or outside companies.
vps4.me expects that its subscribers who provide Internet services to others will comply fully with all applicable laws concerning the privacy of online communications. A subscriber's failure to comply with those laws will violate vps4.me policy. Finally, vps4.me wishes to emphasize that, in signing the Service Agreement, subscribers indemnify vps4.me for any violation of the Service Agreement, law or vps4.me policy resulting in loss to vps4.me or the bringing of any claim against vps4.me by any third party. This means that, if vps4.me is sued because of a subscriber's or customer of a subscriber's activity, the subscriber will be responsible for payment of any damages awarded against vps4.me, plus costs and reasonable attorney's fees.
We hope this AUP is helpful in clarifying the obligations of Internet users, including vps4.me and its subscribers, as responsible members of the Internet. Any complaints about a subscriber's violation of this AUP should be sent to support@vps4.me.