Tag Archive

networking

28 posts found

Adversary-in-the-Middle Phishing Proxies: How Modern Frameworks Hijack MFA Sessions

Deep technical breakdown of AiTM phishing proxies like Mirage2FA, how they intercept MFA sessions, and the architectural changes needed to neutralize session th…

Securing Inbound Webhooks: HMAC Verification and Replay Attack Defense

Inbound webhooks without cryptographic verification expose backend services to forgery, replay attacks, and resource exhaustion. Here is how to implement HMAC-S…

Hardening Reverse Proxies Against WAF Bypass Vectors

Edge WAF inspection often fails when reverse proxies and backend servers parse HTTP requests differently. Here is a 10-point checklist to secure your edge layer…

Why Docker Bypasses UFW Rules (And How to Fix It)

Docker manipulates iptables FORWARD chains directly, bypassing UFW INPUT rules. Learn why container ports leak to the public internet and how to secure them.

Masscan vs bgscan: Raw Socket Speed vs Modular Protocol Inspection

Comparing raw socket throughput against modular banner extraction for network reconnaissance workflows.

Why Your OpenWrt Transparent Proxy Leaks Packets

A routing policy collision caused my OpenWrt proxy to leak traffic. The fix required explicit IP rule priorities and unreachable fallback rules to prevent unmar…

Zero-Trust Tunnels: Rathole Setup for Secure Edge Access

A technical guide to configuring Rathole Noise-protocol tunnels for NAT traversal without exposing incoming local ports.

Hardening Nginx Reverse Proxy: A Production Case Study

A case study of hardening an Nginx reverse proxy on a $6 VPS against constant internet-facing threats, covering TLS tuning, rate limiting, DNS audit, and the op…

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید