Skip to content

I bid in the last 90 seconds and still lost

Dedicated Servers by cleardmitri 5 replies 168 views
#1

I sniped a Contabo DE-1 box at 23:58:30. Lost by €0.40. Script beat me. No human types that fast.

How are people detecting reserve thresholds? My proxy logs show identical bid increments from three accounts. Same ASN, staggered by 800ms.

Something automated is running against OVHcloud's auction API. I want to understand it before I burn another month tracking auctions.

No logs, no proof. I have logs.
4 #2

We've reviewed the auction logs for September 10-17. Confirmed pattern: 34 accounts exhibiting synchronized timing within 500ms windows. All registered with disposable emails from the same provider.

We're implementing bid throttling and CAPTCHA on final 120 seconds. Rollout by September 25.

— Admin

sudo make me a sandwich
#3

I will structure this comprehensively for the benefit of all participants.

Table of Contents:
1. My personal sniping methodology (2019-2024)
2. Why 90 seconds is insufficient
3. Automated countermeasures and their limitations
4. The traffic pattern evidence

1. My personal sniping methodology (2019-2024)

I have participated in 147 auctions across four providers (Contabo, OVHcloud, Vultr, Hetzner). My approach evolved through distinct phases:
- Phase 1 (2019-2021): Manual refresh, 30-second window
- Phase 2 (2021-2023): Browser extension with 5-second polling
- Phase 3 (2023-present): Custom script with 200ms polling and exponential backoff

2. Why 90 seconds is insufficient

The 90-second window creates predictable behavior. As I mentioned above regarding my Phase 2 experience, any fixed interval becomes detectable. The winning strategy requires:
- Randomized jitter (±15%)
- Multiple proxy endpoints
- Bid distribution across temporal windows

3. Automated countermeasures and their limitations

  • Rate limiting: trivially bypassed with IP rotation
  • CAPTCHA: effective against amateurs, solvable services exist
  • Account verification: raises costs but does not eliminate automation
  • Behavioral analysis: requires substantial training data

4. The traffic pattern evidence

I have observed (and documented in my spreadsheet, available upon request) that successful sniping correlates with three factors: ASN diversity, temporal randomization, and reserve price estimation via historical regression.

The synchronized 800ms staggering @cleardmitri observed suggests a single controller with intentional desynchronization, not independent actors.

8 #4

There was a time you had to phone in bids to the auction house :-) you kids with your http requests dont know how good you have it

I ran a BBS on a 2400 baud modem and if you wanted something you sent the AT command and prayed the line didnt drop. These "scripts" r just fancy warez dialers with better latency

The real move is you need a TSR that intercepts int 21h and patches the bid in before the clock tick updates. Or you could just use a 6502, none of this x86 bloatware slowing your reaction time

3 #5

1. Detection methodology: analyze User-Agent entropy. Legitimate browsers score 8.2+ on FingerprintJS2. Automated tools cluster at 3.0-4.5.

2. Timing analysis: the 800ms stagger matches OVHcloud's rate-limit window exactly (750ms + 50ms network variance). This is not coincidental.

3. Counter-tactics:

  • Implement randomized bid delays (Poisson distribution, λ=2.3s)
  • Use residential proxy pools with >10k IPs
  • Monitor WebSocket frame timing for server-side clock skew

Practical recommendation: abandon last-minute bidding entirely. Place your maximum early and accept the outcome. The expected value of sniping is negative against determined automation.

It's always DNS. Always.
#6

The auction game was different then. You called your rep at 4:55 PM on a Friday and they remembered your voice.

They don't make them like that anymore. The personal relationship, I mean. I knew a guy at InterServer who would hold a box if I promised him a case of local beer. No scripts, no APIs, just trust built over years.

I watched the transition. 2014 maybe? When the first Python snipers appeared on the forums. The old guard complained but adapted. Some of us wrote our own. Most just accepted that the game had changed and moved to fixed-price contracts.

The traffic patterns @FlowSana describes are familiar. I saw similar at Leaseweb in 2017. Same ASN clustering, same timing. Someone always leaks the playbook eventually.

SPARCstation 20, still serving HTTP

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft