Cc0wkinginblogs.night-wolf.io·3d ago · 10 min readA Certificate Name That Runs as Root: Five Bugs in Sophos Firewall, Found with CodexA firewall appliance is one of those boxes where the job description and the threat model are the same sentence. It sits at the edge of the network, it terminates the VPN, it holds the credentials for00
MVMegha Varshiniinmegha-blogs.hashnode.dev·Sep 14 · 8 min readWhat Is a Firewall? How It Protects Your NetworkWhenever we connect a computer or phone to the internet, we are communicating with other devices and servers around the world. While this connection gives us access to websites, applications, and onli00
SSshadow Senseiinshadowsensei-sec.hashnode.dev·Sep 7 · 10 min readVesperAegis: My Journey of Building a Linux-Based FirewallVesperAegis Firewall — Adaptive Network Security & Traffic Intelligence Over the past few days, I have been working on something different from my usual penetration-testing labs. Instead of only test00
HHugoinhugovalters.hashnode.dev·Jul 27 · 3 min readNetwork Segmentation: VLANs and Firewall Rules for ProductionIntroduction: Why Your Flat Network is a Liability I once walked into a post-mortem where a single compromised WordPress plugin led to an attacker pivoting from a public web server to a PCI-compliant 00
HHugoinhugovalters.hashnode.dev·Jul 27 · 3 min readMikroTik FastTrack: The Performance Miracle That Breaks Your FirewallI’ve been working with MikroTik since the days when the “RB” in RB450 stood for a board you had to manually case, and RouterOS was still struggling to figure out how to handle multi-core CPUs. If ther00
HHugoinhugovalters.hashnode.dev·Jul 27 · 3 min readFirewall 101: The 'Drop Everything by Default' ManifestoI once audited a “secure” government-contractor network where the lead admin proudly showed me their $25,000 Next-Gen Firewall. It had every subscription active: AI-powered threat detection, SSL inspe00
HHugoinhugovalters.hashnode.dev·Jul 27 · 3 min readNetwork Segmentation: VLANs and Firewall Rules for Service IsolationI’ve spent 15 years cleaning up the aftermath of flat networks. The worst was a 2020 incident where a Redis instance, left exposed on the default VLAN, became an attacker’s highway. Within four hours,00
Rrathsarainrr-cyber.hashnode.dev·Jul 22 · 9 min readEverything Passed. Then the End-to-End Ping Failed.I dedicated my final year project to an unsung hero. Stanislav Petrov, the Soviet lieutenant colonel who prevented nuclear war by deciding not to trust a system that told him it was certain. My superv10
JJJozzieTechinjjozzietech.hashnode.dev·Jul 16 · 12 min readOPNsense on bare metal — 18 months as the only perimeterFor most of the homelab's life, there wasn't a firewall. The ISP router did what ISP routers do — NAT out, block unsolicited inbound, don't ask hard questions. That's not zero security. It's just not 00
4F404 Foundersin404-founders.com·Jun 24 · 3 min readFortiBleed: 86,000 Firewalls Compromised by Default PasswordsSomeone built a database of working usernames and passwords for 86,000 Fortinet firewalls. Half of the internet-facing FortiGate devices on the planet are in it. The Campaign Security researchers hav00