#tcp — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #tcp, aggregated by home.social.
-
Что происходит, когда вы открываете сайт в браузере: путь одного запроса
Вы вводите адрес в браузере и нажимаете Enter. Через долю секунды на экране появляется страница — настолько привычное действие, что мы не задумываемся, сколько всего происходит между нажатием клавиши и первым отрисованным пикселем. А происходит немало. Браузер превращает имя сайта в IP-адрес и договаривается с сервером о шифровании. Затем он отправляет запрос, дожидается ответа, разбирает полученный код и превращает его в картинку на экране. Все это укладывается в миллисекунды. Разбираться в этом пути полезно не только из любопытства. Когда сайт долго грузится, это понимание сразу подсказывает, где искать причину: в DNS, в медленном ответе сервера или в тяжелом JavaScript, который блокирует отрисовку. То же понимание помогает осознанно выбирать хостинг и настройки сервера. Дальше — весь путь по шагам: от разбора адреса до отрисованной страницы.
https://habr.com/ru/companies/timeweb/articles/1073860/
#dns #http #tcp #ip #tls #браузеры #вебразработка #сети #timeweb_статьи
-
Что происходит, когда вы открываете сайт в браузере: путь одного запроса
Вы вводите адрес в браузере и нажимаете Enter. Через долю секунды на экране появляется страница — настолько привычное действие, что мы не задумываемся, сколько всего происходит между нажатием клавиши и первым отрисованным пикселем. А происходит немало. Браузер превращает имя сайта в IP-адрес и договаривается с сервером о шифровании. Затем он отправляет запрос, дожидается ответа, разбирает полученный код и превращает его в картинку на экране. Все это укладывается в миллисекунды. Разбираться в этом пути полезно не только из любопытства. Когда сайт долго грузится, это понимание сразу подсказывает, где искать причину: в DNS, в медленном ответе сервера или в тяжелом JavaScript, который блокирует отрисовку. То же понимание помогает осознанно выбирать хостинг и настройки сервера. Дальше — весь путь по шагам: от разбора адреса до отрисованной страницы.
https://habr.com/ru/companies/timeweb/articles/1073860/
#dns #http #tcp #ip #tls #браузеры #вебразработка #сети #timeweb_статьи
-
Что происходит, когда вы открываете сайт в браузере: путь одного запроса
Вы вводите адрес в браузере и нажимаете Enter. Через долю секунды на экране появляется страница — настолько привычное действие, что мы не задумываемся, сколько всего происходит между нажатием клавиши и первым отрисованным пикселем. А происходит немало. Браузер превращает имя сайта в IP-адрес и договаривается с сервером о шифровании. Затем он отправляет запрос, дожидается ответа, разбирает полученный код и превращает его в картинку на экране. Все это укладывается в миллисекунды. Разбираться в этом пути полезно не только из любопытства. Когда сайт долго грузится, это понимание сразу подсказывает, где искать причину: в DNS, в медленном ответе сервера или в тяжелом JavaScript, который блокирует отрисовку. То же понимание помогает осознанно выбирать хостинг и настройки сервера. Дальше — весь путь по шагам: от разбора адреса до отрисованной страницы.
https://habr.com/ru/companies/timeweb/articles/1073860/
#dns #http #tcp #ip #tls #браузеры #вебразработка #сети #timeweb_статьи
-
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign
Grandoreiro, a notorious banking trojan active since 2016 across Latin America, continues operations despite major law enforcement disruption in 2024. Recent campaigns leverage DLL sideloading techniques, abusing the legitimate Duplicate Files Finder application to execute malicious code. The loader incorporates extensive anti-analysis mechanisms including sandbox detection, virtual machine artifact checks, process blacklisting, and environment profiling to evade automated analysis systems. These defensive checks occur before C2 contact, indicating high priority on avoiding detection. Telemetry from June 2026 shows activity concentrated in Latin America, primarily Mexico, with limited presence in Europe and North America. The malware uses custom string obfuscation combining proprietary decryption with Base64 encoding, and communicates with C2 infrastructure over TCP port 6432 using encrypted requests containing host-specific information.
Pulse ID: 6a86146ca27454b03a4cbe2d
Pulse Link: https://otx.alienvault.com/pulse/6a86146ca27454b03a4cbe2d
Pulse Author: AlienVault
Created: 2026-08-19 20:39:08Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Bank #BankingTrojan #Brazil #CyberSecurity #Europe #InfoSec #LatinAmerica #LawEnforcement #Mac #Malware #Mexico #NorthAmerica #OTX #OpenThreatExchange #RAT #RCE #SMS #SideLoading #TCP #Trojan #bot #AlienVault
-
I've been studying for the bscp sine the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this trasnport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec
-
I've been studying for the bscp sine the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this trasnport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec
-
I've been studying for the bscp sine the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this trasnport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
PhantomCore and PhantomGraph backdoors delivered via an unpatched TrueConf server
The Head Mare APT group exploited a chain of vulnerabilities in TrueConf video conferencing servers to deploy PhantomCore and PhantomGraph backdoors. Attackers connected to unpatched TrueConf servers via port 4307/TCP without authorization, using vulnerabilities KLCERT-26-057 and KLCERT-26-058 to execute arbitrary code with NT AUTHORITY\SYSTEM privileges. They replaced legitimate TrueConf client installers with infected versions containing PhantomCore, and deployed a web shell for persistent access. The PhantomGraph backdoor utilized Microsoft OneDrive as command-and-control infrastructure. Affected TrueConf versions included 5.3.X through 5.3.9, 5.4.X through 5.4.9, and 5.5.X through 5.5.5. Multiple Russian organizations across various industries were targeted, including instrument manufacturing, electronics, transportation, energy, IT, and software development. The vulnerabilities were patched in June 2026.
Pulse ID: 6a7b3ea2ac324259cbd21dc6
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea2ac324259cbd21dc6
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #EDR #ICS #InfoSec #Manufacturing #Microsoft #OTX #OpenThreatExchange #Russia #TCP #bot #AlienVault
-
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.
Pulse ID: 6a7a12d3522ba6e36cd8b6c3
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d3522ba6e36cd8b6c3
Pulse Author: AlienVault
Created: 2026-08-10 18:05:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault
-
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.
Pulse ID: 6a7a12d3522ba6e36cd8b6c3
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d3522ba6e36cd8b6c3
Pulse Author: AlienVault
Created: 2026-08-10 18:05:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault
-
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.
Pulse ID: 6a7a12d3522ba6e36cd8b6c3
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d3522ba6e36cd8b6c3
Pulse Author: AlienVault
Created: 2026-08-10 18:05:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault
-
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.
Pulse ID: 6a7a12d3522ba6e36cd8b6c3
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d3522ba6e36cd8b6c3
Pulse Author: AlienVault
Created: 2026-08-10 18:05:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault
-
Abyssos: Technical Analysis of a New Modular RAT
In late June 2026, a new malware family named Abyssos was identified, representing a modular remote administration tool written in C++ with diverse capabilities including credential theft, file exfiltration, and remote access via VNC. The malware employs LLVM-based obfuscation techniques such as control flow flattening and string encryption to evade security products and complicate analysis. Abyssos uses a custom TCP protocol with AES-GCM encryption for network communication and supports numerous commands for system manipulation, data collection, and module deployment. It features anti-analysis mechanisms detecting hypervisors and security tools, though recent versions lack these checks. The malware demonstrates active development with multiple versions implementing different obfuscation passes, suggesting continued evolution of its capabilities and evasion techniques.
Pulse ID: 6a7a12d3522ba6e36cd8b6c3
Pulse Link: https://otx.alienvault.com/pulse/6a7a12d3522ba6e36cd8b6c3
Pulse Author: AlienVault
Created: 2026-08-10 18:05:07Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Encryption #InfoSec #Malware #OTX #OpenThreatExchange #RAT #SMS #TCP #VNC #bot #AlienVault
-
Канал свободен, а пинг под нагрузкой скачет до секунды: разбираемся с bufferbloat и очередями
Гигабитный канал может быть загружен лишь наполовину, а пинг под нагрузкой всё равно взлетает до сотен миллисекунд. Разбираемся, где копятся очереди, как распознать bufferbloat и какие механизмы действительно удерживают задержку под контролем.
https://habr.com/ru/companies/otus/articles/1065670/
#bufferbloat #задержка_сети #управление_очередями #TCP #AQM #FQCoDel #CAKE #ECN #L4S #BBR
-
Канал свободен, а пинг под нагрузкой скачет до секунды: разбираемся с bufferbloat и очередями
Гигабитный канал может быть загружен лишь наполовину, а пинг под нагрузкой всё равно взлетает до сотен миллисекунд. Разбираемся, где копятся очереди, как распознать bufferbloat и какие механизмы действительно удерживают задержку под контролем.
https://habr.com/ru/companies/otus/articles/1065670/
#bufferbloat #задержка_сети #управление_очередями #TCP #AQM #FQCoDel #CAKE #ECN #L4S #BBR
-
Канал свободен, а пинг под нагрузкой скачет до секунды: разбираемся с bufferbloat и очередями
Гигабитный канал может быть загружен лишь наполовину, а пинг под нагрузкой всё равно взлетает до сотен миллисекунд. Разбираемся, где копятся очереди, как распознать bufferbloat и какие механизмы действительно удерживают задержку под контролем.
https://habr.com/ru/companies/otus/articles/1065670/
#bufferbloat #задержка_сети #управление_очередями #TCP #AQM #FQCoDel #CAKE #ECN #L4S #BBR
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
A China-Nexus Campaign Against Government Infrastructure
China-nexus threat actors have deployed a highly opportunistic automated spray-and-check campaign to compromise global government and commercial infrastructure across more than 100 countries. The operation utilizes centralized multi-platform attack infrastructure featuring cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem. Attackers leverage primary infrastructure at 130.94.17.180 for scanning, exploitation, command-and-control, and payload hosting. The campaign employs stage-2 and stage-3 payloads delivered through architecture-specific loaders targeting both Linux and Windows systems. Transport variants include TCP, WebSocket, and KCP protocols. The SNOWLIGHT loader panel manages payload delivery through multiple endpoints. Organizations face persistent threats requiring immediate patching of exposed services, implementation of strong multi-factor authentication, and continuous monitoring for compromise indicators.
Pulse ID: 6a706203d3aa16bfed001a51
Pulse Link: https://otx.alienvault.com/pulse/6a706203d3aa16bfed001a51
Pulse Author: AlienVault
Created: 2026-08-03 09:40:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#China #CyberSecurity #Endpoint #Government #InfoSec #Linux #OTX #OpenThreatExchange #RAT #TCP #Windows #bot #AlienVault
-
Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
https://wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated -
Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
https://wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated -
Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
https://wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated -
Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
https://wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated -
Ah, the old "let's shove #WireGuard into #TCP because why not?" trick 🤦♂️. This groundbreaking #experiment promises more "performance" on "selected" paths, though it's still as clear as mud 🥴. Meanwhile, actual #networking #experts are rolling their eyes so hard they're seeing their own brains 🧠🙄.
https://wireguardtcp.net/ #performance #eye-roll #HackerNews #ngated -
WireguardTCP: WireGuard over TCP
-
WireguardTCP: WireGuard over TCP
-
WireguardTCP: WireGuard over TCP
-
WireguardTCP: WireGuard over TCP
-
WireguardTCP: WireGuard over TCP
-
#Development #Launches
Global TCP Traceroute · Run TCP traceroutes from around the world https://ilo.im/16euqu_____
#Traceroute #Connections #Network #Latency #Domains #IP #TCP #Host #DevOps #WebDev #Backend -
#Development #Launches
Global TCP Traceroute · Run TCP traceroutes from around the world https://ilo.im/16euqu_____
#Traceroute #Connections #Network #Latency #Domains #IP #TCP #Host #DevOps #WebDev #Backend -
#Development #Launches
Global TCP Traceroute · Run TCP traceroutes from around the world https://ilo.im/16euqu_____
#Traceroute #Connections #Network #Latency #Domains #IP #TCP #Host #DevOps #WebDev #Backend -
#Development #Launches
Global TCP Traceroute · Run TCP traceroutes from around the world https://ilo.im/16euqu_____
#Traceroute #Connections #Network #Latency #Domains #IP #TCP #Host #DevOps #WebDev #Backend -
Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.
TCP knocks, waits for an answer, then hands over every box in order and gets a signature.
UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.
Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.
#TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts
-
Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.
TCP knocks, waits for an answer, then hands over every box in order and gets a signature.
UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.
Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.
#TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts
-
Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.
TCP knocks, waits for an answer, then hands over every box in order and gets a signature.
UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.
Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.
#TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts
-
Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.
TCP knocks, waits for an answer, then hands over every box in order and gets a signature.
UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.
Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.
#TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts
-
Saw the classic TCP vs UDP meme again, buried under a content farm watermark. So I redrew it. My version, my brand, my boxes.
TCP knocks, waits for an answer, then hands over every box in order and gets a signature.
UDP throws all three and walks away. Number 3 arrives first, number 2 does not arrive at all, number 1 is still airborne somewhere past the receiver.
Both are correct engineering. Video calls and DNS would be miserable if every packet needed a signature.
#TCP #UDP #Networking #DevOps #SysAdmin #Programming #Blog #Thoughts
-
Приложение открывается только с VPN. Разбирался почему
Пользователи из регионов начали писать в поддержку одно и то же: приложение не открывается. Симптомы у всех разные. У кого-то вечная загрузка, у кого-то белый экран, у кого-то заходит, только если включить VPN. На своём компьютере всё летает. С зарубежного сервера проверяю, тоже без проблем. Сижу, чешу затылок. Сначала списал на случайные глюки у провайдеров. Мало ли, бывает. Но обращений становилось больше, а не меньше, и в какой-то момент стало ясно: это не совпадение, это системная штука. Пришлось лезть в сетевой дебаг с головой. В этой статье расскажу, как искал причину таймаутов, что в итоге поменял в инфраструктуре и почему обычная сборка Vite с разбивкой на чанки превратилась в проблему, а не в оптимизацию.
https://habr.com/ru/articles/1065126/
#cdn #nginx #vite #selectel #tcp #сетевая_доступность #frontend #отказоустойчивость #spa #сервер
-
Приложение открывается только с VPN. Разбирался почему
Пользователи из регионов начали писать в поддержку одно и то же: приложение не открывается. Симптомы у всех разные. У кого-то вечная загрузка, у кого-то белый экран, у кого-то заходит, только если включить VPN. На своём компьютере всё летает. С зарубежного сервера проверяю, тоже без проблем. Сижу, чешу затылок. Сначала списал на случайные глюки у провайдеров. Мало ли, бывает. Но обращений становилось больше, а не меньше, и в какой-то момент стало ясно: это не совпадение, это системная штука. Пришлось лезть в сетевой дебаг с головой. В этой статье расскажу, как искал причину таймаутов, что в итоге поменял в инфраструктуре и почему обычная сборка Vite с разбивкой на чанки превратилась в проблему, а не в оптимизацию.
https://habr.com/ru/articles/1065126/
#cdn #nginx #vite #selectel #tcp #сетевая_доступность #frontend #отказоустойчивость #spa #сервер
-
Приложение открывается только с VPN. Разбирался почему
Пользователи из регионов начали писать в поддержку одно и то же: приложение не открывается. Симптомы у всех разные. У кого-то вечная загрузка, у кого-то белый экран, у кого-то заходит, только если включить VPN. На своём компьютере всё летает. С зарубежного сервера проверяю, тоже без проблем. Сижу, чешу затылок. Сначала списал на случайные глюки у провайдеров. Мало ли, бывает. Но обращений становилось больше, а не меньше, и в какой-то момент стало ясно: это не совпадение, это системная штука. Пришлось лезть в сетевой дебаг с головой. В этой статье расскажу, как искал причину таймаутов, что в итоге поменял в инфраструктуре и почему обычная сборка Vite с разбивкой на чанки превратилась в проблему, а не в оптимизацию.
https://habr.com/ru/articles/1065126/
#cdn #nginx #vite #selectel #tcp #сетевая_доступность #frontend #отказоустойчивость #spa #сервер
-
Как интернет ушёл от hosts.txt и почему это было неизбежно
Откройте терминал и выполните cat /etc/hosts. Скорее всего, там лежит пара строк про localhost и, может быть, несколько ваших локальных записей… А когда‑то этот файл содержал адреса всех компьютеров интернета и обновлялся по телефонному звонку. Под катом расскажу, как весь интернет работал через один текстовый файл, кто его обновлял и куда он в итоге делся. Читать
https://habr.com/ru/companies/ruvds/articles/1063488/
#hosts #dns #arpanet #история_it #bind #файл_hosts #linux #tcp #системное_администрирование #ruvds_статьи
-
Как интернет ушёл от hosts.txt и почему это было неизбежно
Откройте терминал и выполните cat /etc/hosts. Скорее всего, там лежит пара строк про localhost и, может быть, несколько ваших локальных записей… А когда‑то этот файл содержал адреса всех компьютеров интернета и обновлялся по телефонному звонку. Под катом расскажу, как весь интернет работал через один текстовый файл, кто его обновлял и куда он в итоге делся. Читать
https://habr.com/ru/companies/ruvds/articles/1063488/
#hosts #dns #arpanet #история_it #bind #файл_hosts #linux #tcp #системное_администрирование #ruvds_статьи
-
Как интернет ушёл от hosts.txt и почему это было неизбежно
Откройте терминал и выполните cat /etc/hosts. Скорее всего, там лежит пара строк про localhost и, может быть, несколько ваших локальных записей… А когда‑то этот файл содержал адреса всех компьютеров интернета и обновлялся по телефонному звонку. Под катом расскажу, как весь интернет работал через один текстовый файл, кто его обновлял и куда он в итоге делся. Читать
https://habr.com/ru/companies/ruvds/articles/1063488/
#hosts #dns #arpanet #история_it #bind #файл_hosts #linux #tcp #системное_администрирование #ruvds_статьи
-
TCP/IP-Stack: AmiTCP_NG 4.1.3a
AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.
-
TCP/IP-Stack: AmiTCP_NG 4.1.3a
AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.
-
TCP/IP-Stack: AmiTCP_NG 4.1.3a
AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.
-
TCP/IP-Stack: AmiTCP_NG 4.1.3a
AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.
-
TCP/IP-Stack: AmiTCP_NG 4.1.3a
AmiTCP_NG is an open-source TCP/IP stack for 68k AmigaOS, based on a GPL fork of AmiTCP/IP 3.0b2. It provides a Roadshow-compatible bsdsocket.library ABI (version 4.1) and thus is a drop-in replacement for existing Roadshow installations. Existing applications, scripts, and configuration tools continue to run without modification.
-
#Development #Visualizations
200ms in the life of an HTTP request · Scroll down and the clock advances https://ilo.im/16elev_____
#HTTP #DNS #TLS #TCP #Nodejs #Network #Database #Server #WebDev #Frontend #Backend