HNHacker News
TopNewBestAskShowJobs

m4y0u

9 karma · joined September 20, 2025

Just another hacker. I specialize in Offensive Forensics against APT implants.
submissionscomments
m4y0u··on Turning GLM-5.3-Flash into a Jev-like decision model
My question is why not use Jev instead? It's faster and cheaper.
m4y0u··on A security website that is a filesystem
There are 63 tutorials in 4 tiers. The web was better when it was a filesystem. I need your opinions. Thanks!
m4y0u··on A security website that is a filesystem
A security site where the pages are files, and a real shell at the bottom walks the same tree the browser does.

Sixty three lessons in four tiers, each receipted on a lab you build. Every number a lesson prints carries the command that produced it, and the deploy refuses to publish when the two disagree. Flags are hidden in the filesystem rather than behind an account, and nothing on the site is gated.

Tell me where a lesson is wrong. That is the review I am actually after.

m4y0u··on Detect live APT with this network monitoring tool
www.github.com/m10ust/nethtop.git What you do from the tool 1. Enumerate all ghost sockets and see where they are connected and status 2. Can start a pcap capture or any single connection 3. Can trace and resolve any single connection 4. Can dump entire session and export. 5. Auto pf rule creation from the ghost sockets overlay 6. Kill process associated with any connection 7. Bypass system hooks by APTs, monitoring at the kernel level
m4y0u··on NetHtop++ – Real-time network socket tracker that catches ghost sockets
Hey HN

I built NetHtop++, a network inspection tool for Linux/macOS that goes far beyond netstat or ss. It’s like htop but for sockets — with extra powers.

From a single terminal screen, you can: • See all live sockets and ghost connections (phantom listeners, zombie ports) • r to resolve hosts • x to close sockets • p to kill by PID • t to capture • c to switch interface • o to view ghost sockets • d to dump • e to export • q to quit

Dive deeper into ghost socket inspection and you’ll find: • f to add a pf rule (firewall integration coming for iptables, ufw, etc.) • s snapshot • h hard kill • r restart • o close ghost • d dump socket

The goal is to make this your go-to weapon when debugging strange network behavior, malware implants, ghost listeners, or when you just want full control of the stack.

I’m actively adding more features — including kernel-space tracing, flow tracking, and in-memory socket inspection.

GitHub: https://github.com/m10ust/nethtop

Feedback, ideas, and wild use cases welcome!

m4y0u··on NetHtop++
I wonder how many Ghost Sockets the average user got. I am under an advanced APT (that I am reverse-engineering) and I got around 49 ghost sockets. Which is a lot. Press "o" in the tool to view ghost sockets or refer at the bottom there is a warning showing you the ghost sockets count.
m4y0u··on NetHtop++
This is definitely going in the roadmap. Or if you want you can make a PR request and I will integrate the update. Thanks for the poweruser comment. Really appreciated!
m4y0u··on NetHtop++
The ultimate network monitoring army knife. If you are tired of switching between lsof, tcpdump, traceroute, netstat, ifconfig etc. this tool has it all. It even detect ghost sockets and has counter-measures baked in. This of it like a htop for networking on steroids.