Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
github.com/mas-bandwidth/udp/002
Second attempt.
Increase socket send and receive buffer sizes to 2MB.
https://medium.com/@CameronSparr/increase-os-udp-buffers-to-improve-performance-51d167bb1360
To run:
go run server.go
then in another terminal:
go run client.go
Results:
gaffer@batman 002 % go run client.go
starting 1000 clients
sent delta 99583, received delta 54445
sent delta 96432, received delta 57645
sent delta 98198, received delta 54189
sent delta 98059, received delta 56692
sent delta 98449, received delta 55664
sent delta 98163, received delta 54361
^C
received shutdown signal
shutting down
done.
No change. On MacOS it is not the socket buffer sizes. They're already big enough (at this small scale) by default.
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.