Skip to main content



Thousands of Linux systems infected by "perfctl" malware since 2021


TLDR: perfctl is a crypto mining and proxy jacking malware that exploits about 20’000 common missconfigurations to install itself on Linux servers. Mostly using a 10/10 CVE on Apache RocketMQ.

It is very persistent and can reinstall itself even when you have deleted all the perfctl and perfcc files. It hides itself by removing logs, network packets, and stopping all activity once you login to the machine.

Monitoring cpu usage using tools (I use net data on my server) can help identify infections (100% cpu usage when « idle »).

in reply to SuperFola

Surely y'all have monitoring and alerts for excessive cpu load already?
in reply to DigitalDilemma

On my own server at home, yes. Because that’s important for me to know what’s going on and not discover something by chance weeks later.
in reply to SuperFola

I will never understand people using 3rdparty MQ and RPC implementations. What a a PR for rocketMQ right here.

You can and you should implement your communication protocols, most of the time 3rdparties are very wasteful and a security liability. I like ZeroMQ (zeromq.org/), they have amazing tech guides (zguide.zeromq.org/). I still mostly do my own code.

I may have trust issues but sockets are not THAT hard, they're just amzaingly frustrating to debug, not as much as debuging 3rdparty code.

This entry was edited (1 year ago)


I'm confused trying to get SCALE to work


Hi, I'm trying to get SCALE to work but I'm so confused by what they mean by PATH and I'm stuck.

github.com/spectral-compute/sc…

I'm at the CMAKE step.

This is the official guide I'm following. I do understand what they mean by SCALE_PATH though as that is clearly explained but PATH is just very vague to me or I'm just misunderstanding it completely.

in reply to WereCat

in reply to TheDarkQuark

Thanks. That's a good ELI5. Fortunately I managed to make sense of it before your reply but the link to environment variables is highly appreciated. As I already replied to someone else, I had no idea PATH was a global/environment variable and just assumed it's telling me to specify path so I had no idea I need to RTFM as it confused me greatly and on top of that I did another mistake which confused me even more when I finally managed to get it to do correctly which made me think I am doing it wrong.

I gave up at CMAKE finally as I really need to RTFM more on that as it started to throw many errors at me.



Vänsterpartiet vill se återhämtningsstöd. Bakom dagens kris i sjukvården och annan välfärd ligger många år av urholkade resurser. I sin skuggbudget föreslår Vänsterpartiet därför ett återhämtningsstöd till välfärden på 20 miljarder. Detta för att kompensera för nedskärningarna som gjorts i svensk välfärd under lång tid.

blog.zaramis.se/2024/10/04/van…

This entry was edited (1 year ago)




North Atlantic Fishing Co Ltd är den enskilt största innehavaren av pelagiska fiskerättigheter i England och en av de största i Storbritannien. Det är ett företag som helt ägs av den stora nederländska fiskerikoncernen Cornelis Vrolijk.

fiske.zaramis.se/2024/10/04/no…




Mycket allvarligt att Dadgostar hotar med uteslutning. Nooshi Dadgostar har uttalat sig i Göteborgs-Posten. Det är utifrån uttalandet uppenbart att hon har tappat kontakt med verkligheten i sin privilegierade tillvaro som partiledare och riksdagsledamot.

blog.zaramis.se/2024/10/04/myc…

This entry was edited (1 year ago)


Tre personer misstänkta för mordet på C. Gambino. Den 4 juni mördades rapparen C. Cambino i ett parkeringshus på Selma Lagerlöfs torg i Backa. Efter några dagra greps två män som senare blev häktade för medhjälp till mord.

blog.zaramis.se/2024/10/04/tre…

This entry was edited (6 months ago)




Notcurses ii - A different TUI library [demo video]


I've remembered this exists and there seems to be some very recent activity in the repo so if you didn't know what was possible with TUI graphics now you know! (recommended watching with sound :)

Official site: notcurses.com/
Repo: github.com/dankamongmen/notcur…

PS: dank (the guy behind it) is definitely one of a kind, just read the releases haha

PPS: here is a doom running through notcurses in the terminal:

This entry was edited (1 year ago)


Current state of Intel 13/14th gen CPUs?


Hello,

I think everyone here is already aware of the current problems regarding Intels 13/14th generation CPU-chips.
If not this
article
should explain your questions.

Since Intels new ucode update came and went,
I was looking for an update on the situation and wanted to ask you (the users) for your experience using an Intel 13/14th gen CPU.

Are you still facing issues regarding degradation or are there any other issues potential users should be aware of?

Thanks in advance :)

This entry was edited (1 year ago)

reshared this

in reply to B0g3nNutz3r

0x129 (plus turning off XMP) was enough to stabilize my 13700KF for now, and hopefully 0x12B will be the final nail in the coffin for continued degradation.

However, polling users here for experiences isnt going to give a good perspective on how the CPUs are actually doing. Until it's pretty far gone users may not even notice, and the small sample size of folks who'll reply here is probably not going to accurately reflect the actual state of the CPUs.

Level1techs has done some really good work investigating this at large scale on datacenters, and the takeaway there is that these problems are going to take a while to show, so its generally not a good idea to buy these CPUs til 0x12B has been out for a few months and we know the effects, at which point Arrow Lake will probably be a better option.

tl;dr if you're going to buy right now, buy AMD 7000, but if you're willing to wait til February or so, it'll be a decision between the new gen of Intel CPUs and current AMD CPUs (only 9000 series will probably be available by then).

in reply to B0g3nNutz3r

I anticipate the used value for those gens is going to drop quicker than a Mercedes CL65AMG


Congressman Hank Johnson: It’s time to shut down BioLab


From Decaturish:

DeKalb County, GA — U.S. Rep. Hank Johnson is calling for the closure of BioLab, a chemical plant in Rockdale County that recently caught fire. The fire triggered a sprinkler system. The sprinkler water mixed with chlorine, a water-reactive chemical, allegedly creating a plume over the plant, WABE reported. Rep. Johnson said it’s time for BioLab to […]

https://decaturish.com/2024/10/congressman-hank-johnson-its-time-to-shut-down-biolab/



Who owns your shiny new Pixel 9 phone? You can’t say no to Google’s surveillance


https://cybernews.com/security/google-pixel-9-phone-beams-data-and-awaits-commands/




feddit.online will live on as a PieFed instance


This entry was edited (1 year ago)
in reply to Andromxda 🇺🇦🇵🇸🇹🇼

Whoa... !FloatingIsFun@fedia.io looks really good in PieFed's tile views! It's kind of what I was going for with my CSS. I think PieFed has a ton of potential, and I want to mess around with it more.

@Jerry@hear-me.social, if you just saw a spike of like 1GB of data getting federated in, that was me manually retrieving my first few hundred posts.

Edit: Oops, I tagged the wrong instance admin named Jerry!



Gänguppgörelse i Hellerup? Vid middagstid på onsdag denna vecka grep vakter på Köpenhamns järnvägsstation två svenska ungdomar, 16 och 19 år gamla De var på väg till Tyskland. När de greps hade de några handgranater i sitt bagage.

blog.zaramis.se/2024/10/03/gan…



Nederländare med fiskeriföretag i England. Det finns flera stora nederländska fiskeriföretag som har dotterbolage och verksamheter i England och Skottland. Ibland även på andra håll i Storbritannien. 3 av dem sysslar främst med pelagiskt fiske.

fiske.zaramis.se/2024/10/03/ne…



How did we move from forums to Reddit, Facebook groups, and Discord?


cross-posted from: lemmy.dbzer0.com/post/28930199

A bit of an effortpost :)

Please do crosspost in more fitting communities if you think of any

in reply to sep

in reply to toastal

Terribly sorry. This is probably my norwegian shining thru. Where concatination of words are very common.