Tag Archive

networking

28 posts found

The Evolution of Web Application Firewalls: From RegEx Rules to AST Tokenizers and Wasm Filters

A technical timeline of how HTTP inspection evolved from brittle regular expressions and ReDoS traps to lexical tokenizers, WebAssembly filters, and streaming p…

Defensive Sysctl Parameters for Production IP Stacks

Default Linux kernel settings leave servers exposed to route hijacking, spoofed packets, and connection floods. Here are ten sysctl directives to secure the net…

You’re Debugging DNS in the Wrong Namespace

Network namespaces isolate DNS resolvers from the host. A practical guide to finding which namespace your process lives in, dropping into it, and tracing the ac…

TCP Keepalive Does Not Keep Your Connection Alive

Linux defaults to a 2-hour keepalive time. Dead connections sit in your process table for hours before the kernel notices. Here is how to fix that and why appli…

Noise Handshakes for NAT Traversal: Rathole Multiplexing Architecture

An architectural look at how user-space Noise Protocol tunnels avoid TCP-over-TCP breakdown and solve CGNAT ingress bottlenecks.

Your Localhost Server Is Listening on Every Interface

Running python http.server without --bind 127.0.0.1 opens every NIC to incoming connections. localhost in the URL bar does not equal loopback in the kernel.

Linux Nftables Flowtables: Netfilter Fastpath Connection State Gaps

Software flowtables cut CPU load on Linux routers by bypassing Netfilter chains. Here is why established connections ignore live firewall rule updates and how t…

Debugging WireGuard MTU Bottlenecks and TCP MSS Clamping

Why WireGuard connections drop large TCP payloads when ICMP Path MTU Discovery fails, and how to configure MSS clamping and interface MTU limits on Linux gatewa…

Android 17 Encrypted Client Hello Still Leaves Hostnames on the Wire

Android 17 turns ECH on by default, but RFC 9849 only hides SNI. Outer public names, dedicated origin IPs, and missing HTTPS ech= records still leak the destina…

Why SSH Agent Forwarding Exposes Infrastructure Across Jump Hosts

Using ForwardAgent yes exposes your SSH identity to compromised bastion hosts. Use ProxyJump and local signature confirmation to secure multi-hop SSH infrastruc…

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید