home.social

#tcp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tcp, aggregated by home.social.

fetched live
  1. Что происходит, когда вы открываете сайт в браузере: путь одного запроса

    Вы вводите адрес в браузере и нажимаете Enter. Через долю секунды на экране появляется страница — настолько привычное действие, что мы не задумываемся, сколько всего происходит между нажатием клавиши и первым отрисованным пикселем. А происходит немало. Браузер превращает имя сайта в IP-адрес и договаривается с сервером о шифровании. Затем он отправляет запрос, дожидается ответа, разбирает полученный код и превращает его в картинку на экране. Все это укладывается в миллисекунды. Разбираться в этом пути полезно не только из любопытства. Когда сайт долго грузится, это понимание сразу подсказывает, где искать причину: в DNS, в медленном ответе сервера или в тяжелом JavaScript, который блокирует отрисовку. То же понимание помогает осознанно выбирать хостинг и настройки сервера. Дальше — весь путь по шагам: от разбора адреса до отрисованной страницы.

    habr.com/ru/companies/timeweb/

    #dns #http #tcp #ip #tls #браузеры #вебразработка #сети #timeweb_статьи

  2. Что происходит, когда вы открываете сайт в браузере: путь одного запроса

    Вы вводите адрес в браузере и нажимаете Enter. Через долю секунды на экране появляется страница — настолько привычное действие, что мы не задумываемся, сколько всего происходит между нажатием клавиши и первым отрисованным пикселем. А происходит немало. Браузер превращает имя сайта в IP-адрес и договаривается с сервером о шифровании. Затем он отправляет запрос, дожидается ответа, разбирает полученный код и превращает его в картинку на экране. Все это укладывается в миллисекунды. Разбираться в этом пути полезно не только из любопытства. Когда сайт долго грузится, это понимание сразу подсказывает, где искать причину: в DNS, в медленном ответе сервера или в тяжелом JavaScript, который блокирует отрисовку. То же понимание помогает осознанно выбирать хостинг и настройки сервера. Дальше — весь путь по шагам: от разбора адреса до отрисованной страницы.

    habr.com/ru/companies/timeweb/

    #dns #http #tcp #ip #tls #браузеры #вебразработка #сети #timeweb_статьи

  3. Что происходит, когда вы открываете сайт в браузере: путь одного запроса

    Вы вводите адрес в браузере и нажимаете Enter. Через долю секунды на экране появляется страница — настолько привычное действие, что мы не задумываемся, сколько всего происходит между нажатием клавиши и первым отрисованным пикселем. А происходит немало. Браузер превращает имя сайта в IP-адрес и договаривается с сервером о шифровании. Затем он отправляет запрос, дожидается ответа, разбирает полученный код и превращает его в картинку на экране. Все это укладывается в миллисекунды. Разбираться в этом пути полезно не только из любопытства. Когда сайт долго грузится, это понимание сразу подсказывает, где искать причину: в DNS, в медленном ответе сервера или в тяжелом JavaScript, который блокирует отрисовку. То же понимание помогает осознанно выбирать хостинг и настройки сервера. Дальше — весь путь по шагам: от разбора адреса до отрисованной страницы.

    habr.com/ru/companies/timeweb/

    #dns #http #tcp #ip #tls #браузеры #вебразработка #сети #timeweb_статьи

  4. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  5. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  6. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  7. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  8. Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign

    Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.

    Pulse ID: 6a86146ca27454b03a4cbe2d
    Pulse Link: otx.alienvault.com/pulse/6a861
    Pulse Author: AlienVault
    Created: 2026-08-19 20:39:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault

  9. I've been studying for the bscp sine the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this trasnport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec

  10. I've been studying for the bscp sine the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this trasnport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec

  11. I've been studying for the bscp sine the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this trasnport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec

  12. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.

    Pulse ID: 6a7b3ea2ac324259cbd21dc6
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault

  13. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.

    Pulse ID: 6a7b3ea2ac324259cbd21dc6
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault

  14. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.

    Pulse ID: 6a7b3ea2ac324259cbd21dc6
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault

  15. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.

    Pulse ID: 6a7b3ea2ac324259cbd21dc6
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault

  16. PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server

    The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.

    Pulse ID: 6a7b3ea2ac324259cbd21dc6
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault

  17. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  18. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  19. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  20. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  21. Abyssos: Technical Analysis of a New Modular RAT

    In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.

    Pulse ID: 6a7a12d3522ba6e36cd8b6c3
    Pulse Link: otx.alienvault.com/pulse/6a7a1
    Pulse Author: AlienVault
    Created: 2026-08-10 18:05:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault

  22. Канал свободен, а пинг под нагрузкой скачет до секунды: разбираемся с bufferbloat и очередями

    Гигабитный канал может быть загружен лишь наполовину, а пинг под нагрузкой всё равно взлетает до сотен миллисекунд. Разбираемся, где копятся очереди, как распознать bufferbloat и какие механизмы действительно удерживают задержку под контролем.

    habr.com/ru/companies/otus/art

    #bufferbloat #задержка_сети #управление_очередями #TCP #AQM #FQCoDel #CAKE #ECN #L4S #BBR

  23. Канал свободен, а пинг под нагрузкой скачет до секунды: разбираемся с bufferbloat и очередями

    Гигабитный канал может быть загружен лишь наполовину, а пинг под нагрузкой всё равно взлетает до сотен миллисекунд. Разбираемся, где копятся очереди, как распознать bufferbloat и какие механизмы действительно удерживают задержку под контролем.

    habr.com/ru/companies/otus/art

    #bufferbloat #задержка_сети #управление_очередями #TCP #AQM #FQCoDel #CAKE #ECN #L4S #BBR

  24. Канал свободен, а пинг под нагрузкой скачет до секунды: разбираемся с bufferbloat и очередями

    Гигабитный канал может быть загружен лишь наполовину, а пинг под нагрузкой всё равно взлетает до сотен миллисекунд. Разбираемся, где копятся очереди, как распознать bufferbloat и какие механизмы действительно удерживают задержку под контролем.

    habr.com/ru/companies/otus/art

    #bufferbloat #задержка_сети #управление_очередями #TCP #AQM #FQCoDel #CAKE #ECN #L4S #BBR

  25. A China-Nexus Campaign Against Government Infrastructure

    China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.

    Pulse ID: 6a706203d3aa16bfed001a51
    Pulse Link: otx.alienvault.com/pulse/6a706
    Pulse Author: AlienVault
    Created: 2026-08-03 09:40:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault

  26. A China-Nexus Campaign Against Government Infrastructure

    China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.

    Pulse ID: 6a706203d3aa16bfed001a51
    Pulse Link: otx.alienvault.com/pulse/6a706
    Pulse Author: AlienVault
    Created: 2026-08-03 09:40:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault

  27. A China-Nexus Campaign Against Government Infrastructure

    China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.

    Pulse ID: 6a706203d3aa16bfed001a51
    Pulse Link: otx.alienvault.com/pulse/6a706
    Pulse Author: AlienVault
    Created: 2026-08-03 09:40:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault

  28. A China-Nexus Campaign Against Government Infrastructure

    China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.

    Pulse ID: 6a706203d3aa16bfed001a51
    Pulse Link: otx.alienvault.com/pulse/6a706
    Pulse Author: AlienVault
    Created: 2026-08-03 09:40:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault

  29. A China-Nexus Campaign Against Government Infrastructure

    China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.

    Pulse ID: 6a706203d3aa16bfed001a51
    Pulse Link: otx.alienvault.com/pulse/6a706
    Pulse Author: AlienVault
    Created: 2026-08-03 09:40:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault

  30. Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦‍♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
    wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated

  31. Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦‍♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
    wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated

  32. Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦‍♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
    wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated

  33. Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦‍♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
    wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated

  34. Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦‍♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
    wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated

  35. Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.

    TCP knocks, waits for an answer, then hands over every box in order and gets a signature.

    UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.

    Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.

    #TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts

  36. Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.

    TCP knocks, waits for an answer, then hands over every box in order and gets a signature.

    UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.

    Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.

    #TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts

  37. Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.

    TCP knocks, waits for an answer, then hands over every box in order and gets a signature.

    UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.

    Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.

    #TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts

  38. Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.

    TCP knocks, waits for an answer, then hands over every box in order and gets a signature.

    UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.

    Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.

    #TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts

  39. Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.

    TCP knocks, waits for an answer, then hands over every box in order and gets a signature.

    UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.

    Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.

    #TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts

  40. Приложение открывается только с VPN. Разбирался почему

    Пользователи из регионов начали писать в поддержку одно и то же: приложение не открывается. Симптомы у всех разные. У кого-то вечная загрузка, у кого-то белый экран, у кого-то заходит, только если включить VPN. На своём компьютере всё летает. С зарубежного сервера проверяю, тоже без проблем. Сижу, чешу затылок. Сначала списал на случайные глюки у провайдеров. Мало ли, бывает. Но обращений становилось больше, а не меньше, и в какой-то момент стало ясно: это не совпадение, это системная штука. Пришлось лезть в сетевой дебаг с головой. В этой статье расскажу, как искал причину таймаутов, что в итоге поменял в инфраструктуре и почему обычная сборка Vite с разбивкой на чанки превратилась в проблему, а не в оптимизацию.

    habr.com/ru/articles/1065126/

    #cdn #nginx #vite #selectel #tcp #сетевая_доступность #frontend #отказоустойчивость #spa #сервер

  41. Приложение открывается только с VPN. Разбирался почему

    Пользователи из регионов начали писать в поддержку одно и то же: приложение не открывается. Симптомы у всех разные. У кого-то вечная загрузка, у кого-то белый экран, у кого-то заходит, только если включить VPN. На своём компьютере всё летает. С зарубежного сервера проверяю, тоже без проблем. Сижу, чешу затылок. Сначала списал на случайные глюки у провайдеров. Мало ли, бывает. Но обращений становилось больше, а не меньше, и в какой-то момент стало ясно: это не совпадение, это системная штука. Пришлось лезть в сетевой дебаг с головой. В этой статье расскажу, как искал причину таймаутов, что в итоге поменял в инфраструктуре и почему обычная сборка Vite с разбивкой на чанки превратилась в проблему, а не в оптимизацию.

    habr.com/ru/articles/1065126/

    #cdn #nginx #vite #selectel #tcp #сетевая_доступность #frontend #отказоустойчивость #spa #сервер

  42. Приложение открывается только с VPN. Разбирался почему

    Пользователи из регионов начали писать в поддержку одно и то же: приложение не открывается. Симптомы у всех разные. У кого-то вечная загрузка, у кого-то белый экран, у кого-то заходит, только если включить VPN. На своём компьютере всё летает. С зарубежного сервера проверяю, тоже без проблем. Сижу, чешу затылок. Сначала списал на случайные глюки у провайдеров. Мало ли, бывает. Но обращений становилось больше, а не меньше, и в какой-то момент стало ясно: это не совпадение, это системная штука. Пришлось лезть в сетевой дебаг с головой. В этой статье расскажу, как искал причину таймаутов, что в итоге поменял в инфраструктуре и почему обычная сборка Vite с разбивкой на чанки превратилась в проблему, а не в оптимизацию.

    habr.com/ru/articles/1065126/

    #cdn #nginx #vite #selectel #tcp #сетевая_доступность #frontend #отказоустойчивость #spa #сервер

  43. Как интернет ушёл от hosts.txt и почему это было неизбежно

    Откройте терминал и выполните cat /etc/hosts. Скорее всего, там лежит пара строк про localhost и, может быть, несколько ваших локальных записей… А когда‑то этот файл содержал адреса всех компьютеров интернета и обновлялся по телефонному звонку. Под катом расскажу, как весь интернет работал через один текстовый файл, кто его обновлял и куда он в итоге делся. Читать

    habr.com/ru/companies/ruvds/ar

    #hosts #dns #arpanet #история_it #bind #файл_hosts #linux #tcp #системное_администрирование #ruvds_статьи

  44. Как интернет ушёл от hosts.txt и почему это было неизбежно

    Откройте терминал и выполните cat /etc/hosts. Скорее всего, там лежит пара строк про localhost и, может быть, несколько ваших локальных записей… А когда‑то этот файл содержал адреса всех компьютеров интернета и обновлялся по телефонному звонку. Под катом расскажу, как весь интернет работал через один текстовый файл, кто его обновлял и куда он в итоге делся. Читать

    habr.com/ru/companies/ruvds/ar

    #hosts #dns #arpanet #история_it #bind #файл_hosts #linux #tcp #системное_администрирование #ruvds_статьи

  45. Как интернет ушёл от hosts.txt и почему это было неизбежно

    Откройте терминал и выполните cat /etc/hosts. Скорее всего, там лежит пара строк про localhost и, может быть, несколько ваших локальных записей… А когда‑то этот файл содержал адреса всех компьютеров интернета и обновлялся по телефонному звонку. Под катом расскажу, как весь интернет работал через один текстовый файл, кто его обновлял и куда он в итоге делся. Читать

    habr.com/ru/companies/ruvds/ar

    #hosts #dns #arpanet #история_it #bind #файл_hosts #linux #tcp #системное_администрирование #ruvds_статьи

  46. TCP/IP-Stack: AmiTCP_NG 4.1.3a

    AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.

    amiga-news.de/en/news/AN-2026-

    #Amiga #retrocomputing #TCP

  47. TCP/IP-Stack: AmiTCP_NG 4.1.3a

    AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.

    amiga-news.de/en/news/AN-2026-

  48. TCP/IP-Stack: AmiTCP_NG 4.1.3a

    AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.

    amiga-news.de/en/news/AN-2026-

    #Amiga #retrocomputing #TCP

  49. TCP/IP-Stack: AmiTCP_NG 4.1.3a

    AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.

    amiga-news.de/en/news/AN-2026-

    #Amiga #retrocomputing #TCP

  50. TCP/IP-Stack: AmiTCP_NG 4.1.3a

    AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.

    amiga-news.de/en/news/AN-2026-

    #Amiga #retrocomputing #TCP