home.social

#firewalls — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #firewalls, aggregated by home.social.

fetched live
  1. Modern "AI" firewalls are great except when dealing with Cloudflare.

    Vendor has blocked several legitimate websites at the firewall for their internal users because the sites share the same IP from Cloudflare as identified malicious websites.

    Tracking down the issue was challenging due to the vendor residing in a different geography than the IT MSP. IP addresses are regional from Cloudflare.

    #firewalls #cloudflare #ai

  2. Modern "AI" firewalls are great except when dealing with Cloudflare.

    Vendor has blocked several legitimate websites at the firewall for their internal users because the sites share the same IP from Cloudflare as identified malicious websites.

    Tracking down the issue was challenging due to the vendor residing in a different geography than the IT MSP. IP addresses are regional from Cloudflare.

    #firewalls #cloudflare #ai

  3. I have a few days off, will try to clarify and focus biz plan, get a site up that reflects objectives/mission, then get llc, start advertising, do the tech consulting but also develop some products

    opnsense
    debian
    malcolm
    enc persistent nvme in various flavors (debian blends style)

    that is basically the linecard plus add a sprinkling of pihole consulting, vps/vpn stuff

    #firewalls #workstations #servers #routers #openwrt #custom fw # ids/ips #pkt cap #dashboards

  4. I have a few days off, will try to clarify and focus biz plan, get a site up that reflects objectives/mission, then get llc, start advertising, do the tech consulting but also develop some products

    opnsense
    debian
    malcolm
    enc persistent nvme in various flavors (debian blends style)

    that is basically the linecard plus add a sprinkling of pihole consulting, vps/vpn stuff

    #firewalls #workstations #servers #routers #openwrt #custom fw # ids/ips #pkt cap #dashboards

  5. Massive #breach spills #credentials for thousands of sensitive networks

    Researchers have uncovered a massive breach of #Fortinet #firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including #Oracle , #Chevron , #Lenovo , #FederalExpress , a #NATO defense contractor, and Fortinet itself.

    Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext #credentials exposed online, Bob Diachenko, a #security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other #infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization.
    #russian #russia

    arstechnica.com/security/2026/

  6. Massive #breach spills #credentials for thousands of sensitive networks

    Researchers have uncovered a massive breach of #Fortinet #firewalls that has given Russian-speaking attackers near-unrestricted access to some of the world’s largest and most powerful organizations, including #Oracle , #Chevron , #Lenovo , #FederalExpress , a #NATO defense contractor, and Fortinet itself.

    Nearly 74,000 Fortinet devices from more than 21,000 IP addresses in 194 countries have been compromised and their plaintext #credentials exposed online, Bob Diachenko, a #security researcher and head of SecurityDiscovery.com, said online and in an interview. He said he found the data after gaining access to the attackers’ command-and-control server and other #infrastructure. The exposed data also included the industry, revenue, and employee count for each compromised organization.
    #russian #russia

    arstechnica.com/security/2026/

  7. Bleeping Computer: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.. “A newly discovered data leak dubbed ‘FortiBleed’ has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.”

    https://rbfirehose.com/2026/06/17/bleeping-computer-fortibleed-leak-exposes-fortinet-vpn-credentials-for-73000-devices/
  8. Bleeping Computer: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.. “A newly discovered data leak dubbed ‘FortiBleed’ has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.”

    https://rbfirehose.com/2026/06/17/bleeping-computer-fortibleed-leak-exposes-fortinet-vpn-credentials-for-73000-devices/
  9. 🚨 ALERT: The sky is falling! 🚨 The 2026 #midterms aren't about voting anymore; it's about needing more #firewalls than friends on social media. 🙄 Apparently, cyber threats are the new Kardashians, and everyone's just trying to keep up. 😅
    blog.checkpoint.com/exposure-m #cybersecurity #socialmedia #trends #HackerNews #ngated

  10. 🚨 ALERT: The sky is falling! 🚨 The 2026 #midterms aren't about voting anymore; it's about needing more #firewalls than friends on social media. 🙄 Apparently, cyber threats are the new Kardashians, and everyone's just trying to keep up. 😅
    blog.checkpoint.com/exposure-m #cybersecurity #socialmedia #trends #HackerNews #ngated

  11. Palo Alto Firewalls Targeted in Active Exploitation

    Thousands of Palo Alto firewalls are at risk due to an actively exploited vulnerability, CVE-2026-0300, that allows hackers to execute arbitrary code with root privileges. This alarming flaw affects 5,821 internet-exposed VM-Series firewalls, leaving them open to potential cyber attacks.

    osintsights.com/palo-alto-fire

    #PaloAlto #Cve20260300 #Panos #Vmseries #Firewalls

  12. Palo Alto Networks Firewalls Targeted in Zero-Day Exploits

    Palo Alto Networks firewalls are under attack by zero-day exploits targeting a vulnerability in the User-ID Authentication Portal, allowing hackers to execute malicious code with root privileges. This buffer overflow flaw, tracked as CVE-2026-0300, poses a significant risk to organizations with Internet-exposed firewalls.

    osintsights.com/palo-alto-netw

    #ZeroDay #PaloAltoNetworks #Cve20260300 #Panos #Firewalls

  13. The dshield.org blocklist is probably one of the most useful IP blocklists I have used over the years. Digital Ocean and OVH IP ranges used to feature prominently. It seems that Google Cloud and Hurricane Electric have taken over lately.

    See isc.sans.edu/feeds/block.txt and also the Internet Storm Center isc.sans.edu/index.html

    #firewalls #blocklist #security #cybersecurity #sans

  14. Jugando con Kathará para emular redes TCP/IP! 🚀

    Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).

    Se ve muy interesante para incorporarla a las clases!

    Seguramente haga algo de contenido sobre esto 🙂

    youtu.be/CPYsuUeR6cE

    +Info: kathara.org/

    #uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables

  15. Jugando con Kathará para emular redes TCP/IP! 🚀

    Kathará es el sucesor "espiritual" del viejo Netkit / UML (User-Mode Linux)... recuerdo que lo usaba en una distro live llamada Knoppix (hoy con otro propósito).

    Se ve muy interesante para incorporarla a las clases!

    Seguramente haga algo de contenido sobre esto 🙂

    youtu.be/CPYsuUeR6cE

    +Info: kathara.org/

    #uml #netkit #gnu #linux #docker #networking #networkemulation #kathara #tcpip #firewalls #iptables #nftables

  16. Why a Locked Floppy Disk Could Be Safer Than a Modern Network

    Photo by CCDBarcodeScanner, licensed CC BY-SA 4.0 via Wikimedia Commons.

    Dear Cherubs, in the 1990s, office security had the elegance of a locked drawer and the threat model of a very determined coat thief. Floppy disks were the workhorses of the era, and Britannica notes they were popular from the 1970s until the late 1990s, made of flexible plastic coated with magnetic material. Before the internet became an everyday business utility, many workplaces were still mostly offline; Pew Research found that in 1995 only 14% of U.S. adults had internet access, and 42% had never heard of it.

    THE LOCKED-BOX LOGIC

    If your payroll files, drafts, and backups lived on removable media, the cleanest security move was physical control. Put the disks in a cabinet, lock the cabinet, and hope nobody on the third floor had a master key and a curious streak. It was a blunt system, but it worked because access was local, slow, and obvious. If someone needed a copy, they usually had to walk over, ask, sign something, and maybe endure a suspicious look from whoever guarded the supply room.

    That is the part people forget when they romanticize the old days. The security was not magical; the attack surface was just tiny. To steal the data, someone usually had to be in the building, or at least within arm’s reach of the media. Annoyingly low-tech, yes. Also annoyingly effective.

    MODERN SECURITY, NEW PROBLEMS

    Once files moved onto networks and cloud systems, the game changed. NIST defines intrusion detection as monitoring events in a system or network for signs of possible incidents, and says intrusion prevention systems can also try to stop them. CISA says firewalls shield computers and networks from malicious or unnecessary traffic, while NIST says cryptography is used to protect sensitive digitized information during transmission and while in storage. In other words: the modern office traded one locked box for a whole stack of digital locks, alarms, and panic buttons.

    Of course, the modern setup has its own virtues. Data can be backed up automatically, shared instantly, and protected with layered controls that the floppy-disk era never needed. NIST’s storage-encryption guidance still says organizations should physically secure devices and removable media, which is a polite way of saying: the box still matters, even when the box now lives in a server rack. Security did not become less important; it became more complicated, which is basically the same thing with extra meetings.

    So yes, a locked plastic box full of floppies could be safer than a badly configured internet-facing system. But that is not because the past was wiser. It is because the past had fewer doors, fewer windows, and fewer strangers trying every handle on the planet at once. Security has always been a trade-off between convenience and control; we just used to do the math with keys instead of passwords.

    Sources:
    Britannica — https://www.britannica.com/technology/floppy-disk
    Pew Research Center — https://www.pewresearch.org/internet/2014/02/27/part-1-how-the-internet-has-woven-itself-into-american-life/
    NIST SP 800-94 — https://csrc.nist.gov/pubs/sp/800/94/final
    CISA firewalls — https://www.cisa.gov/news-events/news/understanding-firewalls-home-and-small-office-use
    NIST SP 800-175B Rev. 1 — https://csrc.nist.gov/pubs/sp/800/175/b/r1/final
    NIST SP 800-111 — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-111.pdf
    Wikimedia Commons image page — https://commons.wikimedia.org/wiki/File:Floppy_Disk_HD.jpg

    The Thisclaimer logo blends a classic warning symbol with a brain icon to represent critical thinking, curiosity, and thoughtful disclaimers. #cybersecurity #dataSecurity #encryption #firewalls #floppyDisks #internet #internetHistory #intrusionDetection #officeHistory #openSource #physicalSecurity #techNostalgia #technology #ubuntu #wordpress
  17. Why a Locked Floppy Disk Could Be Safer Than a Modern Network

    Photo by CCDBarcodeScanner, licensed CC BY-SA 4.0 via Wikimedia Commons.

    Dear Cherubs, in the 1990s, office security had the elegance of a locked drawer and the threat model of a very determined coat thief. Floppy disks were the workhorses of the era, and Britannica notes they were popular from the 1970s until the late 1990s, made of flexible plastic coated with magnetic material. Before the internet became an everyday business utility, many workplaces were still mostly offline; Pew Research found that in 1995 only 14% of U.S. adults had internet access, and 42% had never heard of it.

    THE LOCKED-BOX LOGIC

    If your payroll files, drafts, and backups lived on removable media, the cleanest security move was physical control. Put the disks in a cabinet, lock the cabinet, and hope nobody on the third floor had a master key and a curious streak. It was a blunt system, but it worked because access was local, slow, and obvious. If someone needed a copy, they usually had to walk over, ask, sign something, and maybe endure a suspicious look from whoever guarded the supply room.

    That is the part people forget when they romanticize the old days. The security was not magical; the attack surface was just tiny. To steal the data, someone usually had to be in the building, or at least within arm’s reach of the media. Annoyingly low-tech, yes. Also annoyingly effective.

    MODERN SECURITY, NEW PROBLEMS

    Once files moved onto networks and cloud systems, the game changed. NIST defines intrusion detection as monitoring events in a system or network for signs of possible incidents, and says intrusion prevention systems can also try to stop them. CISA says firewalls shield computers and networks from malicious or unnecessary traffic, while NIST says cryptography is used to protect sensitive digitized information during transmission and while in storage. In other words: the modern office traded one locked box for a whole stack of digital locks, alarms, and panic buttons.

    Of course, the modern setup has its own virtues. Data can be backed up automatically, shared instantly, and protected with layered controls that the floppy-disk era never needed. NIST’s storage-encryption guidance still says organizations should physically secure devices and removable media, which is a polite way of saying: the box still matters, even when the box now lives in a server rack. Security did not become less important; it became more complicated, which is basically the same thing with extra meetings.

    So yes, a locked plastic box full of floppies could be safer than a badly configured internet-facing system. But that is not because the past was wiser. It is because the past had fewer doors, fewer windows, and fewer strangers trying every handle on the planet at once. Security has always been a trade-off between convenience and control; we just used to do the math with keys instead of passwords.

    Sources:
    Britannica — https://www.britannica.com/technology/floppy-disk
    Pew Research Center — https://www.pewresearch.org/internet/2014/02/27/part-1-how-the-internet-has-woven-itself-into-american-life/
    NIST SP 800-94 — https://csrc.nist.gov/pubs/sp/800/94/final
    CISA firewalls — https://www.cisa.gov/news-events/news/understanding-firewalls-home-and-small-office-use
    NIST SP 800-175B Rev. 1 — https://csrc.nist.gov/pubs/sp/800/175/b/r1/final
    NIST SP 800-111 — https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-111.pdf
    Wikimedia Commons image page — https://commons.wikimedia.org/wiki/File:Floppy_Disk_HD.jpg

    The Thisclaimer logo blends a classic warning symbol with a brain icon to represent critical thinking, curiosity, and thoughtful disclaimers. #cybersecurity #dataSecurity #encryption #firewalls #floppyDisks #internet #internetHistory #intrusionDetection #officeHistory #openSource #physicalSecurity #techNostalgia #technology #ubuntu #wordpress
  18. Little Snitch, the macOS network tool, is now available on Linux

    “Little Snitch for Linux is written in Rust and uses eBPF for kernel-level traffic interception (this lets sandboxed code run inside the Linux kernel without modifying it). The tool shows processes on your machine making network connections, and giv ...continues

    See gadgeteer.co.za/little-snitch-

    #firewalls #linux #security #technology

  19. Little Snitch, the macOS network tool, is now available on Linux

    “Little Snitch for Linux is written in Rust and uses eBPF for kernel-level traffic interception (this lets sandboxed code run inside the Linux kernel without modifying it). The tool shows processes on your machine making network connections, and giv ...continues

    See gadgeteer.co.za/little-snitch-

    #firewalls #linux #security #technology

  20. #Google says half of all #zerodays it tracked in #2025 targeted buggy #enterprise tech
    Google said security and networking devices, #firewalls, #VPN and #virtualization platforms like Ivanti and VMware, were among targetes last year. All four of the companies said hackers have exploited their products on customer networks in recent months.
    The remaining 52% of #zeroday bugs were found in consumer and end-user products, such as those made by Microsoft, Google, and Apple
    techcrunch.com/2026/03/05/goog

  21. #Google says half of all #zerodays it tracked in #2025 targeted buggy #enterprise tech
    Google said security and networking devices, #firewalls, #VPN and #virtualization platforms like Ivanti and VMware, were among targetes last year. All four of the companies said hackers have exploited their products on customer networks in recent months.
    The remaining 52% of #zeroday bugs were found in consumer and end-user products, such as those made by Microsoft, Google, and Apple
    techcrunch.com/2026/03/05/goog

  22. ayuda #fediverso #redes #seguridad #firewalls

    estoy montando un #cluster #proxmox #hibrido un nodo en casa otro en la #nube

    tengo muy poca puta idea de firewalls. hasta la fecha, ponia uno en el edge, que bloqueara todo lo feo, y adentro, todo abierto. y aparte de eso, el concepto de un firewall cliente, un firewall servidor

    pero me estoy liando que flipas con proxmox. uno a nivel de datacenter. uno a nivel de nodo. uno a nivel de contenedor e incluso puedes activar desactivar por cada tarjeta de red? me estoy volviendo loco. tengo entendido, muy a grandes rasgos que: desde lo mas exterior, hay que bloquear todo salvo los puertos web y VPN. desde lo mas cercano: el contenedor, bloquear todo salvo la actividad de la aplicacion en si, sea la que sea. y en medio, capas inter nodo: la comunicacion entre nodo y contenedores. pero seguramente haya formas mas precisas y correctas de hacerlo. he estudiado esto... un par de horas ayer. no exagero.

    me puede alguien ayudar por favor, en guiarme en lograr lo siguiente?

    quiero que el cluster pueda comunicar de forma interna (vpn) y externa, exponiendo por netbird.

    pensaba tener una vlan 10.0.10.1/24 para interno y 10.0.20.1/24 para exponer

    la idea es que la comunicacion interna sea mas laxa, y que al contrario la 20 sea full estricta

    en el nodo nube, solo tengo una tarjeta fisica de red con una ip publica.

    por ahora lo que tengo hecho es hacer un bridge vlan aware, y de ahi 3 vlans (quiero una para netbird y otra para tailscale. por si se cae una, no quedarme fuera)

    tengo forward NAT de la ip publica al bridge

    cuando literal, no tengo internet en los contenedores... en el mejor de los casos, no son accesibles los puertos que quiero, el 80 y 443, para desplegar netbird.

    y ahi estoy bloqueado.
    no hay puta forma de pasar de ese tercer pantallazo.

    @t3rr0rz0n3 @z3r0

    que estoy haciendo mal? seguramente de mucho a todo. como dije, hasta ahora mis redes eran muy.... libres. y es literal mi primer cluster hibrido y la primera vez que trasteo con vlans.

    se agradece mucho #boost

  23. ayuda #fediverso #redes #seguridad #firewalls

    estoy montando un #cluster #proxmox #hibrido un nodo en casa otro en la #nube

    tengo muy poca puta idea de firewalls. hasta la fecha, ponia uno en el edge, que bloqueara todo lo feo, y adentro, todo abierto. y aparte de eso, el concepto de un firewall cliente, un firewall servidor

    pero me estoy liando que flipas con proxmox. uno a nivel de datacenter. uno a nivel de nodo. uno a nivel de contenedor e incluso puedes activar desactivar por cada tarjeta de red? me estoy volviendo loco. tengo entendido, muy a grandes rasgos que: desde lo mas exterior, hay que bloquear todo salvo los puertos web y VPN. desde lo mas cercano: el contenedor, bloquear todo salvo la actividad de la aplicacion en si, sea la que sea. y en medio, capas inter nodo: la comunicacion entre nodo y contenedores. pero seguramente haya formas mas precisas y correctas de hacerlo. he estudiado esto... un par de horas ayer. no exagero.

    me puede alguien ayudar por favor, en guiarme en lograr lo siguiente?

    quiero que el cluster pueda comunicar de forma interna (vpn) y externa, exponiendo por netbird.

    pensaba tener una vlan 10.0.10.1/24 para interno y 10.0.20.1/24 para exponer

    la idea es que la comunicacion interna sea mas laxa, y que al contrario la 20 sea full estricta

    en el nodo nube, solo tengo una tarjeta fisica de red con una ip publica.

    por ahora lo que tengo hecho es hacer un bridge vlan aware, y de ahi 3 vlans (quiero una para netbird y otra para tailscale. por si se cae una, no quedarme fuera)

    tengo forward NAT de la ip publica al bridge

    cuando literal, no tengo internet en los contenedores... en el mejor de los casos, no son accesibles los puertos que quiero, el 80 y 443, para desplegar netbird.

    y ahi estoy bloqueado.
    no hay puta forma de pasar de ese tercer pantallazo.

    @t3rr0rz0n3 @z3r0

    que estoy haciendo mal? seguramente de mucho a todo. como dije, hasta ahora mis redes eran muy.... libres. y es literal mi primer cluster hibrido y la primera vez que trasteo con vlans.

    se agradece mucho #boost

  24. @distrowatch I faced ddos from all sorts of bots couple of months back when I started with a search engine. I ended up blocking 10K or so bots. If you want you can use it for your blocking/iptables/firewall: git.flossboxin.org.in/vdbhb59/

    There maybe few false positives which I can delete if I am made aware of.
    Hope it will help. #botsblocking #hosts #firewalls

  25. @distrowatch I faced ddos from all sorts of bots couple of months back when I started with a search engine. I ended up blocking 10K or so bots. If you want you can use it for your blocking/iptables/firewall: git.flossboxin.org.in/vdbhb59/

    There maybe few false positives which I can delete if I am made aware of.
    Hope it will help. #botsblocking #hosts #firewalls

  26. FreeBSD's networking is incredibly powerful.
    Today I found out about pfil and pfilctl and thought “sweet, now I can run ipfw and pf at the same time” but the experts say don’t do that.
    It seems the idea is that you can e.g. hook the firewall directly on the network interface to speed up dropping packets or to e.g. hook only the firewall input into the network stack if you only want to filter on input.
    Right now I don’t have a use for this, but it’s good to know

    #FreeBSD #networking #firewalls

  27. FreeBSD's networking is incredibly powerful.
    Today I found out about pfil and pfilctl and thought “sweet, now I can run ipfw and pf at the same time” but the experts say don’t do that.
    It seems the idea is that you can e.g. hook the firewall directly on the network interface to speed up dropping packets or to e.g. hook only the firewall input into the network stack if you only want to filter on input.
    Right now I don’t have a use for this, but it’s good to know

    #FreeBSD #networking #firewalls

  28. Oh, look! 😲 Yet another "innovative" solution to trick your way past #firewalls by dressing up your traffic in a fedora and trench coat of SMTP emails. Because clearly, the best way to sneak past #security is to pretend you're still living in the '90s when #email was the ultimate cloak of invisibility. 🕵️‍♂️📧
    github.com/x011/smtp-tunnel-pr #innovative #solutions #bypassing #vintage #tech #cloakofinvisibility #HackerNews #ngated

  29. Oh, look! 😲 Yet another "innovative" solution to trick your way past #firewalls by dressing up your traffic in a fedora and trench coat of SMTP emails. Because clearly, the best way to sneak past #security is to pretend you're still living in the '90s when #email was the ultimate cloak of invisibility. 🕵️‍♂️📧
    github.com/x011/smtp-tunnel-pr #innovative #solutions #bypassing #vintage #tech #cloakofinvisibility #HackerNews #ngated

  30. Is there an emerging market for small home #firewalls that automatically detect and block communications from "smart" TVs and fridges and toasters etc? #FreeBusinessIdeas

  31. Is there an emerging market for small home #firewalls that automatically detect and block communications from "smart" TVs and fridges and toasters etc? #FreeBusinessIdeas

  32. 🔥 Keep attackers out before they get in.
    🛡️ Use firewalls—hardware or software—to block unwanted traffic and protect your network.
    👉 zurl.co/if8l8

    #CyberSecurity #Firewalls #NetworkSecurity #Zevonix

  33. The President of the Central Association of German Crafts, Jörg Dittrich, has cautioned against allowing the burgeoning debate surrounding a "firewall" against... news.osna.fm/?p=24851 | #news #amid #concerns #crafts #firewalls

  34. 🚫 Oh, the irony! In a riveting twist, our tech wizards decided to jump ship from #OpenBSD to #FreeBSD for firewalls—only to lock themselves out of their own blog post. 🔒 Maybe next time, consider #permissions before making grand announcements? 🤦‍♂️
    utcc.utoronto.ca/~cks/space/bl #firewalls #techhumor #irony #HackerNews #ngated

  35. 🚫 Oh, the irony! In a riveting twist, our tech wizards decided to jump ship from #OpenBSD to #FreeBSD for firewalls—only to lock themselves out of their own blog post. 🔒 Maybe next time, consider #permissions before making grand announcements? 🤦‍♂️
    utcc.utoronto.ca/~cks/space/bl #firewalls #techhumor #irony #HackerNews #ngated