Tag Archive

security

68 posts found

Linux Nftables Flowtables: Netfilter Fastpath Connection State Gaps

Software flowtables cut CPU load on Linux routers by bypassing Netfilter chains. Here is why established connections ignore live firewall rule updates and how t…

Debugging WireGuard MTU Bottlenecks and TCP MSS Clamping

Why WireGuard connections drop large TCP payloads when ICMP Path MTU Discovery fails, and how to configure MSS clamping and interface MTU limits on Linux gatewa…

Android 17 Encrypted Client Hello Still Leaves Hostnames on the Wire

Android 17 turns ECH on by default, but RFC 9849 only hides SNI. Outer public names, dedicated origin IPs, and missing HTTPS ech= records still leak the destina…

How CLI Package Managers Bypass macOS Gatekeeper Execution Rules

CLI downloaders and package managers bypass macOS Gatekeeper by omitting quarantine extended attributes on fetched binaries.

Why SSH Agent Forwarding Exposes Infrastructure Across Jump Hosts

Using ForwardAgent yes exposes your SSH identity to compromised bastion hosts. Use ProxyJump and local signature confirmation to secure multi-hop SSH infrastruc…

SAML Key Rotation Failures: Certificate Fingerprints and Domain Matching

Key rotation in multi-tenant SAML SSO often breaks authentication due to split-brain domain routing and certificate fingerprint caching.

Hadolint vs Docker DX: Dockerfile Security Linting Compared

Compare Hadolint and Docker DX for Dockerfile security linting across rule depth, developer workflow, CI/CD integration, and custom policy enforcement.

Browser Extension Stores Are Not Security Boundaries

Official add-on marketplaces do not guarantee safety. Malicious Firefox and Chrome extensions slip past linters to harvest credentials and session tokens.

Adversary-in-the-Middle Phishing Proxies: How Modern Frameworks Hijack MFA Sessions

Deep technical breakdown of AiTM phishing proxies like Mirage2FA, how they intercept MFA sessions, and the architectural changes needed to neutralize session th…

Securing Inbound Webhooks: HMAC Verification and Replay Attack Defense

Inbound webhooks without cryptographic verification expose backend services to forgery, replay attacks, and resource exhaustion. Here is how to implement HMAC-S…

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید