XSS Attempts via E-Mail, (Thu, Jan 23rd)

One of the hardest applications to create securely is webmail. E-mail is a complex standard, and almost all e-mail sent today uses HTML. Displaying complex HTML received in an e-mail within a web application is dangerous and often leads to XSS vulnerabilities. Typical solutions include the use of iframe sandboxes and HTML sanitizers. But still, XSS vulnerabilities sneak into applications even if they try hard to get it right. One of my “favorite” examples of how subtle mistakes can cause vulnerabilities was a recent Protonmail vulnerability [1]. Even if you are not using webmail to read email, you may still be exploited as some native email clients have allowed HTML content to leak credentials or have been subject to other HTML-related problems, often related to including content from third-party websites dynamically.

Continue reading XSS Attempts via E-Mail, (Thu, Jan 23rd)

Posted in Uncategorized

Catching CARP: Fishing for Firewall States in PFSync Traffic, (Wed, Jan 22nd)

Legend has it that in the Middle Ages, monchs raised carp to be as “round” as possible. The reason was that during Lent, one could only eat as much as fit on a plate, and the round shape of a carp gave them the most “fish per plate”. But we are not here to exchange recipes. I want to talk about CARP and the network failover feature.

Continue reading Catching CARP: Fishing for Firewall States in PFSync Traffic, (Wed, Jan 22nd)

Posted in Uncategorized

Geolocation and Starlink, (Tue, Jan 21st)

Until now, satellite internet access has been more of a niche solution for internet access. But with the wide availability of Starlink, this is changing. Starlink&#39&#x3b;s performance and price are competitive for many rural users to forgo solutions like cellular or slower DSL speeds if they are available at all.

Continue reading Geolocation and Starlink, (Tue, Jan 21st)

Posted in Uncategorized