Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
is a simple server monitoring web dashboard with a couple of management features.
pip install server-manager
git clone https://gitlab.com/serverman-group/serverman
cd serverman
python -m build
pip install .
To run the dashboard you have to use gunicorn (installed as a dependency)
run syntax:
python -m gunicorn -b host:port servermanager.wsgi:app
if you have gunicorn installed as a system-wide package you can simply use gunicorn
removing python -m
run command example:
python -m gunicorn -b 0.0.0.0:8080 servermanager.wsgi:app
python -m
runs a python package, in this case gunicorn
, the -b
flag specifies bind, --bind can also be used
, this binds the wsgi
server to a certain host and port, in this case 0.0.0.0
and port 8080
.
The host 0.0.0.0
is used so the server can be accessible network wide.
The port really can be specified to anything except ports like 80
or 443
, that require escalated
privileges. For the server to be accessible on port 80
or 443
both the flask and gunicorn documentations
recommend using a reverse proxy like apache httpd and nginx.
To see the webpage simply go to ip address of the device the dashboard is running on.
example: localhost:8080
or 192.168.xx.xx:8080
. If you are using a reverse proxy setup as mentioned before
you can access the dashboard from the reverse proxy server ip and port (this can be the same machine running the dashboard)
, make sure that if the reverse proxy server and the dashboard are running on the same machine, they are not running on the same port.
Once you open the webpage you will see this:
This is the start page of the serverman dashboard.
Once you navigate to one of the links you will be prompted to log in:
In this login page you are required to log in as one of the system users with their username and password
to proceed with the server's monitoring and management.
After the login the links do not redirect you to login anymore and you can start monitoring. The login system is session based and made with flask-login.
This app features a
page.
The dashboard page provides the ability to view system metrics like cpu clock speed, memory and swap usage.
The dashboard settings page or just settings
allows you to make simple adjustments to what the dashboard page displays.
The page also allows the the interval at witch the information to be updated.
This can really help lower end systems like older raspberry pi's.
The processes tab shows the currently running processes and also kill them.
The update interval of the processes table can also be adjusted in the settings page.
FAQs
Simple server usage monitor writen with flask
We found that server-manager demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.