This Week in Security: uClibc and DNS Poisoning, Encryption is Hard, and the Goat

DNS spoofing/poisoning is the attack discovered by [Dan Kaminski] back in 2008 that simply refuses to go away. This week a vulnerability was announced in the uClibc and uClibc-ng standard …read more Continue reading This Week in Security: uClibc and DNS Poisoning, Encryption is Hard, and the Goat

Is enabling software flow-offloading in OpenWRT’s firewall settings dangerous?

First of all, I did ask this on OpenWrt Forums already, I thought maybe someone here knows this.
I noticed that my internet speed gets limited when this feature is not enabled, this feature is also marked as experimental, any clue what it … Continue reading Is enabling software flow-offloading in OpenWRT’s firewall settings dangerous?

Is enabling software flow-offloading in OpenWRT’s firewall settings dangerous?

First of all, I did ask this on OpenWrt Forums already, I thought maybe someone here knows this.
I noticed that my internet speed gets limited when this feature is not enabled, this feature is also marked as experimental, any clue what it … Continue reading Is enabling software flow-offloading in OpenWRT’s firewall settings dangerous?

This Week in Security: Ghoscript in Imagemagick, Solarwinds, and DHCP Shenanigans

A PoC was just published for a potentially serious flaw in the Ghostscript interpreter. Ghostscript can load Postscript, PDF, and SVG, and it has a feature from Postscript that has …read more Continue reading This Week in Security: Ghoscript in Imagemagick, Solarwinds, and DHCP Shenanigans

Dnsmasq vulnerabilities open networking devices, Linux distros to DNS cache poisoning

Seven vulnerabilities affecting Dnsmasq, a caching DNS and DHCP server used in a variety of networking devices and Linux distributions, could be leveraged to mount DNS cache poisoning attack and/or to compromise vulnerable devices. “Some of the b… Continue reading Dnsmasq vulnerabilities open networking devices, Linux distros to DNS cache poisoning