Tag Archive

security

68 posts found

The Evolution of Web Application Firewalls: From RegEx Rules to AST Tokenizers and Wasm Filters

A technical timeline of how HTTP inspection evolved from brittle regular expressions and ReDoS traps to lexical tokenizers, WebAssembly filters, and streaming p…

Voltage Glitching and Side-Channel Leakage in Embedded Cryptographic Silicon

Hardware security modules and cold storage wallets isolate private keys inside microcontroller flash memory. When attackers obtain physical access, precision vo…

Defensive Sysctl Parameters for Production IP Stacks

Default Linux kernel settings leave servers exposed to route hijacking, spoofed packets, and connection floods. Here are ten sysctl directives to secure the net…

You’re Debugging DNS in the Wrong Namespace

Network namespaces isolate DNS resolvers from the host. A practical guide to finding which namespace your process lives in, dropping into it, and tracing the ac…

TCP Keepalive Does Not Keep Your Connection Alive

Linux defaults to a 2-hour keepalive time. Dead connections sit in your process table for hours before the kernel notices. Here is how to fix that and why appli…

Linux Systemd Sandboxing: Ten Security Directives for Production Daemons

Harden production Linux services using native systemd security directives including namespaces, seccomp syscall filters, and memory protection.

Why Read-Only Containers Do Not Stop Binary Execution

A read-only root filesystem prevents disk writes, but Linux kernels still permit staging and executing in-memory ELF binaries via memfd_create and unhardened tm…

Noise Handshakes for NAT Traversal: Rathole Multiplexing Architecture

An architectural look at how user-space Noise Protocol tunnels avoid TCP-over-TCP breakdown and solve CGNAT ingress bottlenecks.

How to Replace Static Authorized Keys with OpenSSH Cryptographic Certificates

Replace static authorized_keys with an OpenSSH Certificate Authority to issue time-limited certificates, eliminate known_hosts prompts, and enforce instant revo…

Your Localhost Server Is Listening on Every Interface

Running python http.server without --bind 127.0.0.1 opens every NIC to incoming connections. localhost in the URL bar does not equal loopback in the kernel.

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید