#tcp — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #tcp, aggregated by home.social.
-
Что происходит, когда вы открываете сайт в браузере: путь одного запроса
Вы вводите адрес в браузере и нажимаете Enter. Через долю секунды на экране появляется страница — настолько привычное действие, что мы не задумываемся, сколько всего происходит между нажатием клавиши и первым отрисованным пикселем. А происходит немало. Браузер превращает имя сайта в IP-адрес и договаривается с сервером о шифровании. Затем он отправляет запрос, дожидается ответа, разбирает полученный код и превращает его в картинку на экране. Все это укладывается в миллисекунды. Разбираться в этом пути полезно не только из любопытства. Когда сайт долго грузится, это понимание сразу подсказывает, где искать причину: в DNS, в медленном ответе сервера или в тяжелом JavaScript, который блокирует отрисовку. То же понимание помогает осознанно выбирать хостинг и настройки сервера. Дальше — весь путь по шагам: от разбора адреса до отрисованной страницы.
https://habr.com/ru/companies/timeweb/articles/1073860/
#dns #http #tcp #ip #tls #браузеры #вебразработка #сети #timeweb_статьи
-
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.
Pulse ID: 6a7a12d3522ba6e36cd8b6c3
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d3522ba6e36cd8b6c3
Pulse Author: AlienVault
Created: 2026-08-10 18:05:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault
-
Канал свободен, а пинг под нагрузкой скачет до секунды: разбираемся с bufferbloat и очередями
Гигабитный канал может быть загружен лишь наполовину, а пинг под нагрузкой всё равно взлетает до сотен миллисекунд. Разбираемся, где копятся очереди, как распознать bufferbloat и какие механизмы действительно удерживают задержку под контролем.
https://habr.com/ru/companies/otus/articles/1065670/
#bufferbloat #задержка_сети #управление_очередями #TCP #AQM #FQCoDel #CAKE #ECN #L4S #BBR
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
https://wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated -
WireguardTCP: WireGuard over TCP
-
#Development #Launches
Global TCP Traceroute · Run TCP traceroutes from around the world https://ilo.im/16euqu_____
#Traceroute #Connections #Network #Latency #Domains #IP #TCP #Host #DevOps #WebDev #Backend -
Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.
TCP knocks, waits for an answer, then hands over every box in order and gets a signature.
UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.
Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.
#TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts
-
Приложение открывается только с VPN. Разбирался почему
Пользователи из регионов начали писать в поддержку одно и то же: приложение не открывается. Симптомы у всех разные. У кого-то вечная загрузка, у кого-то белый экран, у кого-то заходит, только если включить VPN. На своём компьютере всё летает. С зарубежного сервера проверяю, тоже без проблем. Сижу, чешу затылок. Сначала списал на случайные глюки у провайдеров. Мало ли, бывает. Но обращений становилось больше, а не меньше, и в какой-то момент стало ясно: это не совпадение, это системная штука. Пришлось лезть в сетевой дебаг с головой. В этой статье расскажу, как искал причину таймаутов, что в итоге поменял в инфраструктуре и почему обычная сборка Vite с разбивкой на чанки превратилась в проблему, а не в оптимизацию.
https://habr.com/ru/articles/1065126/
#cdn #nginx #vite #selectel #tcp #сетевая_доступность #frontend #отказоустойчивость #spa #сервер
-
Как интернет ушёл от hosts.txt и почему это было неизбежно
Откройте терминал и выполните cat /etc/hosts. Скорее всего, там лежит пара строк про localhost и, может быть, несколько ваших локальных записей… А когда‑то этот файл содержал адреса всех компьютеров интернета и обновлялся по телефонному звонку. Под катом расскажу, как весь интернет работал через один текстовый файл, кто его обновлял и куда он в итоге делся. Читать
https://habr.com/ru/companies/ruvds/articles/1063488/
#hosts #dns #arpanet #история_it #bind #файл_hosts #linux #tcp #системное_администрирование #ruvds_статьи
-
TCP/IP-Stack: AmiTCP_NG 4.1.3a
AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.
-
#Development #Visualizations
200ms in the life of an HTTP request · Scroll down and the clock advances https://ilo.im/16elev_____
#HTTP #DNS #TLS #TCP #Nodejs #Network #Database #Server #WebDev #Frontend #Backend -
Vinton Cerf is retiring: https://techcrunch.com/2026/06/30/the-father-of-the-internet-is-finally-retiring/ He is known as one of the fathers of the internet. Being one of the creators of TCP/IP.
I had the privileged to see him give a keynote presentation at IEEE Globecom back in 2019. I remember his wits and his ability to present his work in a manageable easily consumable way.
I remember his joke about being the only person on Hawai'i wearing a three piece suit. -
Ditch CUBIC's loss-based congestion. Enable TCP BBR on Linux 4.9+ for model-driven throughput without bufferbloat. Use fq qdisc for pacing and set tcp_congestion_control to bbr. Get the config snippet: #linux #tcp #bbr
https://www.valtersit.com/vault/enabling-tcp-bbr-congestion-control-for-throughput-83e5e3/
-
Testing optional #TCP out #proxy in #psocks
https://codeberg.org/YGGverse/psocks/pulls/4PR1 was closed but its route implementation is interesting also
https://codeberg.org/YGGverse/psocks/pulls/1
#Rust -
Нейро сети для самых маленьких. Часть первая (которая после нулевой). Удобство в прокрустовом ложе оптимизации
Это первая (после нулевой) статья из серии Нейро сети для самых маленьких , в которой мы разбираем инфраструктуру для запуска нейронных сетей. Для обучения и инференса нейросетей и для любых видов High Performance Computing используются специализированные технологии: GPU/TPU, RDMA, Kernel bypass, NVLink, InfiniBand, RoCE и другие. Про некоторые из них большинство только что-то слышали, но сталкиваться с ними не приходилось. Нельзя просто взять ванильный стек Linux, воткнуть в него 400Gb Ethernet+IP и получить рабочее решение. Почему? Потому что общее решение на масштабе в большинстве случаев проигрывает специализированным как в скорости, так и в стоимости. Как бы странно последнее ни звучало.
https://habr.com/ru/companies/yandex/articles/1047072/
#rdma #gpudirect_rdma #infiniband #tcp #ethernet #zero_copy #roce #nvlink #nvidia #gpu
-
Heb nu ook een extra RNS service opgezet, eens kijken of dat wat is.
Op deze RNS service een aantal rns backbones van europa in de config gezet om zo te kijken of europese mesh werkt.
1539d0796e85a3a71130c7d38c396d62:/page/rnestats.mu
-
The Lack of the Ack, Sixteen Years On
In February of 2010, I wrote about a small but symptomatic failure in our digital manners. Young people, then aged eighteen to twenty, would send you a message, receive your reply, and disappear. No acknowledgement, no "Ok," no "Got it," just the digital equivalent of someone slamming the door after asking you a question through the mail slot. The piece was called "How to Ack Back," and the argument was that the etiquette of the early internet, the discipline of acknowledging every transmission, had been lost on a generation that grew up assuming delivery was guaranteed and silence was a defensible reply. […]https://bolesblogs.com/2026/05/29/the-lack-of-the-ack-sixteen-years-on/
-
Почему порты стали «дверями» в сервер, и кто решил, что SSH будет 22
В 1995 году Тату Илонен написал письмо длиной с пост на Хабре и бесплатно получил номер ssh -p 22 user@host, который теперь знает каждый сисадмин. Но до этого порты были однонаправленными, чётные номера считались ненужными, а половина слотов вообще пустовала. О том, как порты стали «дверями» в сервер и что останется от них через десять лет, рассказал в статье. Читать
https://habr.com/ru/companies/ruvds/articles/1038826/
#SSH #Linux_kernel #NAT #Nmap #BSD #RFC #DevOps #сетевые_технологии #tcp #ruvds_статьи
-
BBR рулит, но есть нюанс, когда алгоритмы из нулевых понимают ваш Wi-Fi лучше
BBR принято считать современным стандартом TCP congestion control. Google разработал его в 2016 году, он работает в production крупнейших CDN, его хвалят в каждой второй статье о сетевой оптимизации. И всё это заслуженно — но с существенной оговоркой, о которой обычно не пишут. Вперёд в прошлое…
-
New #TCP public peer is now available by thanks to @neilalexander
```
tcp://yggdrasil.neilalexander.dev:64649
```it's CPU-friendly and could be especially useful in the #Yggdrasil #TLS-less #NTP context https://yggdrasil-network.github.io/services.html#ntp
-
Por si alguien se ha instalado @forgejo y utiliza #Pangolin para acceder al servicio, si además quieres hacer un “git push” por #SSH en vez de #HTTPS, aquí hay un artículo que explica muy bien cómo crear un recurso #TCP: https://digitalquint.click/posts/accessing-forgejo-pangolin/. Pero es importante, que si en vuestro #Hosting tenéis un #Firewall (cortafuegos), abráis el puerto asignado al acceso SSH. (1/2)