Accounts and Services

Guide to BandwagonHost and DMIT Account Security, Avoiding Resale Pitfalls, and Writing Effective Support Tickets

Compiled by the VPSMap Editorial Team · Updated 2026-09-26 · 32-minute read · Plain-Text Version

With Unmanaged cloud servers, the provider's technical team is responsible only for reliable physical host hardware, data center power, and backbone connectivity. Software deployment, access controls, and account-level security above the operating system are entirely the user's responsibility.

BandwagonHost and DMIT have long served the high-bandwidth, premium cross-border routing market, including CN2 GIA, CMI, and AS9929. Some promotional or limited-edition plans are scarce and trade frequently among independent developers and website operators. However, unclear console permissions, ownership-recovery vulnerabilities in resales, and ineffective support tickets submitted without checking credentials have long troubled many administrators.

Based on official technical specifications and everyday operations, this article examines the two providers' key differences in security architecture, billing and refunds, secondary-market risk controls, and support tickets, with practical guidance.


一、 基础设施账户的分层防御模型#

Protecting VPS assets goes far beyond the Linux system's sshd_config hardening. In the cloud, the chain of control over asset ownership follows a strict top-down hierarchy:

Commands / Configuration
+--------------------------------------------------------------+
| 1. 注册主邮箱 (最高司法权:可发起密码重置、接受安全验证码)    |
+------------------------------+-------------------------------+
                               |
                               v
+--------------------------------------------------------------+
| 2. 商家客户门户 (Client Area) (账单结算、API 密钥、双因素验证) |
+------------------------------+-------------------------------+
                               |
                               v
+--------------------------------------------------------------+
| 3. 底层管理控制台 (Out-of-Band Management)                   |
|    - 搬瓦工: KiwiVM Control Panel (独立管理密码)             |
|    - DMIT: 实例控制面板 (Access 控制 / VNC Console)          |
+------------------------------+-------------------------------+
                               |
                               v
+--------------------------------------------------------------+
| 4. 虚拟机系统内层 (Guest OS) (SSH 密钥对、系统 root 密码)     |
+--------------------------------------------------------------+

1. Foundational Defense: How Ownership of the Registered Email Address Is Determined#

在主流国际主机商的法理判定体系中,The Primary Registered Email Address Linked to the Account Is Treated as the Asset's Legal Controller. Regardless of whose credit card or PayPal account is linked to the service, if the registered email account is compromised, an attacker can instantly dismantle all higher-level defenses through password recovery.

  • 安全策略: Be sure to use a mainstream professional email service with a hardware security key (FIDO2 / WebAuthn) or strong TOTP two-factor authentication enabled, and never use passwords exposed in publicly known credential-stuffing datasets.
  • 隔离策略: For accounts hosting critical servers, use a dedicated email address to avoid exposing the registered address through everyday spam.

2. 平台防御:客户门户与 TOTP 二次验证#

Both BandwagonHost and DMIT natively support RFC 6238 TOTP two-factor authentication in the client area's Security Settings, using apps such as Google Authenticator, 1Password, or Bitwarden.

  • Configuration Standards:启用 2FA 时,商家系统生成的 Emergency Recovery Codes(紧急救援备用码) must be exported and stored on secure media physically separate from the authenticator.
  • 找回门槛: if you lose your phone and have no recovery codes, removing 2FA requires multiple manual reviews, including submitting an identity verification ticket and checking historical payment Transaction IDs. The process is extremely cumbersome and time-consuming.

3. Separating Console and System Credentials#

两家 Providers 在控制台架构与默认安全基线上存在显著差异,日常运维不可混为一谈:

BandwagonHost( BandwagonHost ):三权分离与 KiwiVM 控制台#

BandwagonHost uses a distinctive permission-isolation system, with management credentials divided into three completely independent categories:

  1. Client Area 密码: Used to log in to the official client area and manage invoices, renewals, support tickets, and ticket authentication.
  2. KiwiVM Control Panel Password: The separate management password for the infrastructure control panel. In addition to single sign-on (SSO) from the client area, administrators can log in directly through the KiwiVM entry point using this password.
  3. System root Password:Linux 虚拟机内部的超级管理员密码。

[!IMPORTANT] KiwiVM integrates Interactive Console and Root Shell - interactive. Even if the SSH service crashes or firewall rules are misconfigured (such as accidentally blocking port 22), KiwiVM access allows you to connect directly to the terminal through a browser with emulated physical keyboard input for recovery.

DMIT: Zero Trust by Default and Enforced SSH Keys#

DMIT Applies Stricter Production Security Standards When Creating or Resetting Instances:

  1. Remote root Password Login Disabled by Default: When creating an instance, the system requires an SSH public key to be injected, and the default image template disables SSH password authentication (PasswordAuthentication no)。
  2. Global SSH Key Repository: Users can add multiple SSH Keys to the DMIT account console in advance, then select them when creating or resetting an instance.
  3. Access Panel and How Changes Take Effect: If you need to change the root password or add an SSH key, go to the instance details page's Access tab to submit the changes.
  4. 硬重启生效约束: after changing the Access configuration in the DMIT panel,You Must Fully Shut Down / Reboot the Instance Using Panel Commands, allowing the underlying Cloud-init automation to rewrite credentials on the system disk. Simply running a command inside the system reboot often cannot synchronize the new credentials configured in the console.

Two. Comparison of Billing Cycles, Suspension Risk Controls, and Refund Policies#

Keeping server assets running reliably requires a clear understanding of each provider's billing triggers. The two providers have different strict rules for invoice generation, grace periods, and dispute-related refunds.

Evaluation CriteriaBandwagonHost( BandwagonHost )DMIT
Renewal Invoice Generation TimeBefore the Due Date 7 days Generate a Renewal InvoiceBefore the Due Date 7 days 生成续费账单(month付周期)
Automatic Payment PolicyDo not initiateautomatic credit card/PayPal charges; deductions occur only when the prepaid account balance is sufficient, otherwise payment must be made manuallyDepends on the configuration; supports automatic settlement using prepaid credit, or requires manual payment of generated outstanding invoices
逾期宽限与数据保留The Instance Stops Immediately When the Invoice Is Overdue; After Brief Disk-Image Retention, the System Permanently Destroys ItAfter Shutdown for an Overdue Invoice, Data Is Generally Retained for Only 3 days grace period, after which unpaid data is permanently erased from physical storage
Full Refund Window for New PurchasesAfter Purchase Within 30 DaysAfter Purchase Within 3 Days
Traffic and Usage Thresholds for RefundsCurrent Monthly Traffic Usage Must Below 10% of the Allowance; and the IP is not blocked by a firewall or blacklistedCumulative Network Traffic Usage No More Than 30GB;且需符合适用退款的服务 Type
Partial Refund (Remaining Value)No Daily Prorated Partial Refunds; Only Full Refunds When the Terms Are MetAfter Purchase Within 30 Days and, when the terms of service are met, a refund of the remaining value is supported after deducting consumed resources and processing fees
Consequences of a RefundOnce the refund request is confirmed, the associated instance and disk data will bePermanently Delete ImmediatelyThe Instance Immediately Enters Decommissioning and Reclamation, with Its Data Irreversibly Erased

关键防踩坑细节:#

  • BandwagonHost Account Balance Protection and Renewal Pitfalls: Because BandwagonHost does not initiate automatic charges through linked payment channels, such as PayPal recurring agreements, watch for Invoice reminders sent to your registered email as expiration approaches. Without prepaid credit or manual invoice payment, service moves directly to Suspended status when due.
  • DMIT's Strict 3-Day Recovery Window: DMIT enforces suspension for overdue payment decisively. Once service is suspended, the invoice must be paid within 3 days; otherwise, the underlying storage volume is released into the shared pool and the data cannot be recovered.
  • Strict Refund Risk-Control Limits: Both providers impose strict risk-control penalties for abuse of their refund policies. If an IP is blocked because of prohibited activity, such as packet-flood attacks or seriously abusive scanning, refund eligibility will be revoked.

Three. Secondary-Market Transfers and Transaction Risk Prevention#

Some legacy BandwagonHost optimized plans, such as limited-edition CN2 GIA-E and THE PLAN series, and some cost-effective DMIT optimized plans, such as early low-bandwidth PVM.LAX.Pro plans, are not routinely available for purchase, leading to active secondary-market trading. Such transactions, however, carry extremely high ownership risks.

1. BandwagonHost: Email-Transfer Sales and Recovery Through Original Payment Evidence#

历史上, BandwagonHost 因未推出官方 instance Push(过户)功能,二级市场交易通常采用“连带原账户改邮箱”的方式进行。这直接滋生了灰色“找回”产业链:

  • How Account Recovery Works:卖家在转让 accounts 并配合买家修改登录邮箱后,数周或数month后向官方技术支持提交工单,出示最初 Buy 时的支付流水账单(如支付宝订单号、PayPal Transaction ID、原始信用卡对账单),声称“ accounts 遭遇恶意入侵且邮箱被篡改”。由于境外主机商严格奉行**“财务支付流水与最初注册凭证优先级高于当前登录态”**,官方往往会将邮箱直接 Reset 回初始所有者。
  • Official 120-Hour Cooling-Off Lock: to curb such disputes, BandwagonHost has implemented strict fraud controls for email address changes:
    1. After initiating an email address change in the console, it does not take effect immediately;
    2. The System Sends Alert and Confirmation Emails to Both the Old and New Addresses;
    3. 变更请求将在 5 days(120 hours ) takes effect only after the cooling-off period ends. During that time, the original email owner can click the cancellation link in the email to reverse the change and trigger a security lock with one click.
  • Ultimate Consequences of Risk-Control Enforcement: BandwagonHost's Terms of Service explicitly prohibit account resale without official approval. If an ownership dispute in support tickets reveals evidence of account trading, the risk-control team's usual response is直接永久冻结该账户, with neither a refund nor a return to either party.

2. DMIT: Risk Controls and Transaction Risks#

  • Multidimensional Anti-Fraud Review:DMIT 的风控系统(MaxMind)对登录 IP、支付人姓名与账户真实所在地有着严格的交叉校验。在二级市场接盘二手 accounts 若直接使用与原注销地跨度极大的代理 IP 登录,极易触发欺诈封禁(Fraud Status)。
  • Cascading Repercussions of Payment Disputes (Chargebacks): If a resale seller later files a Dispute / Chargeback through the original PayPal account or card issuer, DMIT immediately locks the corresponding account and terminates all its instances. The buyer may lose both data and money without warning.

3. Practical Checklist for Avoiding Resale Pitfalls#

Before taking over an account in any form, review each of the following steps:

Verification StepsActions and Security Criteria
Step 1: Thoroughly Verify IP StatusBefore the transaction, ask the seller for the currently assigned IPv4 address and use a third-party multi-node Ping tool to test reachability from overseas and mainland China.
For BandwagonHost,If the Current IP Is Blacklisted, KiwiVM Immediately Locks “Migrate to another DC”,导致其彻底失去迁往其他机房自救的价值。
Step 2: Transfer Full Ownership of the Email Account凡是无法交割“原始注册邮箱(首显邮箱)”的交易,一律视为高风险交易。若必须改邮箱,务必等待 120-Hour Security Period 完全平稳度过,且需明确知晓历史支付凭证依然留在卖家手中这一既定事实。
Step 3: Clean Up Billing InvoicesAfter logging in, review historical Invoices in the Client Area. Confirm that all previous billing periods are marked Paid and that no unresolved items remain under Unpaid / Collections.
Step 4: Immediately Revoke All Existing CredentialsAfter Receiving the Account, Immediately Perform Four Resets:
① Change the client area password and force all existing Web Sessions to log out;
② Reset and bind your own 2FA TOTP key;
③ Reset 底层管理密码( BandwagonHost KiwiVM 密码 / DMIT Access 凭据);
④ Generate a new SSH key pair and completely remove the system's original ~/.ssh/authorized_keys the leftover public keys in it.

Four. Emergency Control Panel Operations and Self-Service Troubleshooting#

Before clicking “Open Ticket” to ask the provider's engineers for help, users should first diagnose the issue using the out-of-band management tools provided by both companies. Most cases described as “server unreachable” are caused by local connection instability or an operating system kernel deadlock, rather than hardware failure.

1. BandwagonHost KiwiVM 核心排障功能矩阵#

  • Interactive Console:位于面板侧边栏。当虚拟机因 SSH 配置失误、UFW/Iptables 规则封闭或系统 OOM( Memory 溢出)导致 Networking 接口挂死时,此工具能够绕过外网 Networking 栈,直接唤, from基于 WebSocket 的底层虚拟终端。
  • IP 状态与黑名单自检: KiwiVM includes IP checks and migration logic. Normally, users can move data centers freely to change outbound routes. If infrastructure probes identify the IP as blacklisted and unroutable, migration is locked automatically. Instead of repeatedly asking support to force migration, restore IP availability through an officially permitted process.
  • OS Reinstallation (OS Reload):提供常见 Linux 发行版原版 image 的自动化抹盘 deployment 。请注意,重装将彻底销毁当前磁盘上的所有数据,必须预先确认快照(Snapshots)是否已备份。

2. DMIT 控制台核心排障功能矩阵#

  • Emergency VNC Console: Provides a fully graphical emulated display. If an instance suffers a failed kernel upgrade (Kernel Panic), a read-only system disk, or missing boot entries that leave it at GRUB, use the VNC Console to inspect on-screen error logs and perform single-user recovery.
  • Repair Access Credentials: If a lost SSH key or accidentally deleted public key prevents login, reselect the public key under Access and perform a forced Power Cycle from the console. The underlying agent automatically writes the public key back to the host-mounted volume.
  • Audit Traffic and Network Status: DMIT plans have different throttling or blocking policies after exceeding the data allowance, depending on the series (such as Premium optimized routes, Lite international routes, or Eyeball routing). If the server loses connectivity without warning, first check whether the current month's Traffic Usage meter on the billing page has reached the 100% allowance limit.

Five. Guidelines for Writing Effective Technical Support Tickets#

The Core Principle of Technical Support for Self-Managed Servers Is:The provider is responsible only for infrastructure and does not intervene in the user's operating system or application layer。

1. Defining After-Sales Support Responsibilities#

Commands / Configuration
                  +----------------------------------------------+
                  |               官方技术受理范围               |
                  |  (硬件损坏 / 母机宕机 / 核心上游骨干路由中断)   |
                  +----------------------+-----------------------+
                                         |
                       [ 基础设施层边界:边界路由 / 宿主机 ]
                                         |
                  +----------------------v-----------------------+
                  |               用户自主运维范围               |
                  |  (系统崩溃 / 端口防火墙 / Web环境配置 / 脚本调试)|
                  +----------------------------------------------+
  • 属于官方 SLA 范畴:
    • Physical Host Failures (ECC Memory Errors, Degraded RAID Arrays, or Unexpected Power Loss);
    • Data center power failure or core switching network outage;
    • 官方宣告的上游 Networks (如电信 CN2 GIA、联通 9929、移动 CMIN2)出现大面积骨干网路由中断、黑洞或非正常绕行;
    • Billing settlement errors, payment gateway reconciliation failures, and automated IP Provisioning failures.
  • Outside Support Scope (The Ticket Will Be Politely Declined):
    • “The Docker container I installed cannot access the internet”;
    • “How to configure an Nginx reverse proxy and SSL certificates”;
    • “Hackers installed a backdoor on my server and it is sending attack traffic; please remove the malware”;
    • “国内某个偏远省份的本地运营商 Ping 延迟偏高,请帮我优化”。

2. Four Essentials of a High-Quality Technical Support Ticket#

To avoid an inefficient cycle of “describe the issue -> support asks for configuration details -> provide more information -> wait in the queue again,” the initial ticket must include the following:

  1. Precise Asset Identification: Include the specific Service ID、Primary IPv4 Address 以及所在 Data Center Region Code(such as BandwagonHost USCA_6 / DMIT LAX.Pro).
  2. Timestamp with Time Zone: State when the incident began and ended, and explicitly specify the time zone (such as 2026-09-26 14:00 UTC+8),严禁使用“刚才”、“昨天”等模糊词汇。
  3. Structured Diagnostic Logs: never provide only a screenshot of a single ping line. You must provide, from your local machine to the target IP,MTR Trace Reports with Multiple Samples in Both Directions or One Direction (At Least 100 Test Packets Recommended)。
  4. Statement of Factors Ruled Out:明确告知工程师已 Passed 控制台(KiwiVM Console / VNC)验证了系统内部运行正常(如 Load Average 处于安全水位、内核 Networking 栈正常监听),排除了本地宽带故障(已在不同运营商 Networking 如移动 5G、电信宽带下做过交叉验证)。

Six. Practical Production Support Ticket Templates in Chinese and English#

模板一:跨国骨干网 Networks 异常与持续性丢包报障#

适用场景:已排除本地 Networking 原因,服务器控制台正常,但特定大陆核心 Networks (如美西 CN2 GIA / Japan Pro Networks )遭遇大面积高丢包或 Overseas 路由异常绕路。

Ticket Subject: Network Routing Degradation & Packet Loss Investigation - [Your Server IP]

text
Dear Support Team,

I am opening this ticket to report an abnormal network degradation issue regarding my service [填入 Service ID, 例如: 1234567], Main IP: [填入你的服务器IP], located in [填入机房节点, 例如: Los Angeles - DC6 / LAX Pro].

1. Symptom Description:
Starting from [故障时间, 例如: 2026-09-26 10:30 UTC+8], we observed a severe network performance drop when communicating with this server from China Mainland. The average packet loss rate abruptly climbed to over 35%, accompanied by severe latency spikes.

2. Verification & Troubleshooting Already Performed:
- Host Status: Checked via out-of-band console (KiwiVM / DMIT VNC). The operating system is fully responsive, system load average is under 0.3, and local network daemon is listening properly.
- Environment Isolation: Tested through two separate local ISPs (China Telecom AS4134 and China Mobile AS9808 cellular network); both observed identical routing degradation.
- Packet Loss Metric: MTR path analysis shows packet loss starts immediately after entering the upstream transit border router.

3. MTR Diagnostic Report (100 packets sent, report mode):
------------------------------------------------------------
[在此处完整粘贴本地终端执行 mtr -rzc 100 <服务器IP> 输出的纯文本内容]
------------------------------------------------------------

Could you please assist in checking whether there is upstream fiber degradation, trans-Pacific transit congestion, or BGP route hijacking affecting this transit node?

Thank you for your time and assistance.

Best regards,
[你的姓名或账户称呼]

模板二:账单已扣款但系统未入账 / instance 暂停异常申诉#

Use Case: A third-party payment channel has charged successfully, but gateway callback delays or network timeouts leave the invoice Unpaid in the console, causing overdue service suspension.

Ticket Subject: Billing Discrepancy: Payment Completed but Invoice Remains Unpaid - Invoice #[Invoice Number]

text
Dear Billing Department,

I am writing to request manual verification for Invoice #[填入待支付账单编号], which is currently flagged as "Unpaid" on my Client Portal, despite funds having been successfully captured by the payment processor.

1. Transaction Particulars:
- Service ID / IP: [填入关联的实例ID或IP]
- Invoice Number: #[账单编号]
- Amount Paid: $[交易金额] USD
- Payment Gateway Used: [例如: PayPal / Credit Card / UnionPay / Alipay]
- Payment Timestamp: [填入支付完成时间, 例如: 2026-09-26 15:20 UTC+8]
- Gateway Transaction ID: [至关重要:粘贴支付渠道提供的订单流水号 / Transaction ID]

2. Problem Impact:
Because the automated payment webhook was delayed, the associated VPS instance has entered Suspended status. This instance hosts critical service components. 

3. Attached Proof of Payment:
[在此处说明或粘贴支付软件收据详情:包括 Merchant Name, Transaction Reference, Amount]

Could you please reconcile this payment manually, credit the invoice, and lift the suspension on the affected service as soon as possible?

Sincerely,
[你的姓名或账户称呼]

Template Three: Internal Gateway Unreachable / Verify Network Configuration After an Infrastructure-Level Instance Reset#

Applicable scenario: the system completely loses network connectivity after an OS reinstallation through the panel or a kernel upgrade, and a VNC inspection shows that the network interface cannot obtain an IP address via DHCP or that the default gateway configuration is missing.

Ticket Subject:Network Interface Unreachable via Out-of-Band Verification - [您的服务器 IP]

text
Dear Technical Staff,

My VPS instance (Service ID: [服务ID], IP: [服务器IP]) has completely lost public network connectivity. I have conducted an initial inspection through the Web Emergency Console (VNC) and suspect a physical switch/DHCP lease issue on the host node.

1. Console Diagnosis Findings:
- Successfully logged into the guest OS via the emergency interactive console.
- Interface `eth0` is UP, but it fails to acquire an IP lease from the internal DHCP server (or static IP configuration no longer responds to ARP queries from the gateway).
- Pinging the default gateway [填入网关IP, 如: 154.xx.xx.1] from within the server results in: "Destination Host Unreachable".
- No internal iptables/nftables firewall rules are blocking outgoing or incoming ICMP traffic.

2. Network Interface Dump (Output of `ip addr` & `ip route`):
------------------------------------------------------------
[在此粘贴在 VNC 终端中执行 ip addr show 以及 ip route show 的回显信息]
------------------------------------------------------------

Could you please verify if the bridge port on the host node or the virtual switch configuration associated with my VPS container/KVM tap interface is operating normally?

Thank you for your support.

Best regards,
[你的姓名或账户称呼]

七、 总结:构建高韧性的云上资产管理习惯#

Whether you choose BandwagonHost, with decades of experience optimizing overseas routes back to China, or DMIT, known for hardware performance and ultra-fast network routing, the underlying principles for protecting cloud assets and keeping services running smoothly are the same:

  1. Credential Security Is the First Line of Defense: Use a securely protected email account with independent 2FA as the foundation of ownership. Make effective use of BandwagonHost's separate KiwiVM management password and DMIT's automated SSH key distribution mechanism to eliminate weak-password and brute-force attack risks.
  2. Treat Unofficial Account Transfers with Caution: clearly understand both providers' billing risk controls and rules for determining ownership. For secondhand account transfers through email changes without official guarantees, remain alert to the risk of losing access through support-ticket claims based on original payment records.
  3. 技术报障讲求证据链:明确自主管理型 VPS 的责任分界线。遇障先查控制台并收集多维度 MTR 测试数据,使用专业、准确的技术语言组织工单,才能在关键时刻驱动 Providers 工程 Team 迅速定位并解决问题。

相关 Providers 与 Plan 入口

The following are referral links, and this site may earn a commission after a purchase. Pricing, stock, and terms of service are governed by the provider's checkout page.