Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
enrico204
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
enrico204
2y ago
Actually, that is not a bad idea. @xena maybe Anubis v2 could make the client participate in some sort of SETI@HOME project, creating the biggest distributed cluster ever created :-D
2.
▲
by
enrico204
2y ago
Isn't that the MCAS warning? /s
3.
▲
by
enrico204
2y ago
Yes, because there are specific exceptions in the GDPR that allow data processing and storage in many of these cases. However, managers are pissed off by the law, or just ignorant, and they make you sign a document that has no legal value.
4.
▲
You copy-pasted the output of a scanning tool. That's disrespectful
(github.com)
5 points
by
enrico204
2y ago
|
0 comments
5.
▲
by
enrico204
2y ago
Actually, my idea was to delay e-mails because I don't want to read them during weekends, while I still want to read other e-mails (e.g., newsletters, login alerts). I still open my inbox once per day :-)
6.
▲
Delay email delivery with Postfix for a relaxing weekend
(enricobassetti.it)
20 points
by
enrico204
2y ago
|
6 comments
7.
▲
by
enrico204
3y ago
Yes, it works on forwarded packets. In the example ruleset in the blog post, `em1` and `em2` are two network interfaces (victim and attacker, think them as LAN and WAN respectively), and the FreeBSD machine is configured as router/fire
8.
▲
by
enrico204
3y ago
Fragmentation is a nightmare in a nightmare: we also discovered that IPv6 fragments reassembly (as implemented by major operating systems) is still plagued by the problem of overlapping fragments. Potentially, you can still bypass IDS/
9.
▲
by
enrico204
3y ago
Actually, if the router supports RDNSS (DNS info in RA), SLAAC is sufficient for household users -- no need for DHCPv6.
10.
▲
by
enrico204
3y ago
Author here. The ruleset in the blog post is correct. The rationale of the example ruleset is the following: we want to block TCP, UDP and ICMPv6 traffic from the attacker, while allowing other protocols. Note that IPv6 packets are matched
11.
▲
by
enrico204
3y ago
Author here. I confirm that OPNSense was vulnerable. It has been fixed in v23.7.1 (August 8, 2023): https://forum.opnsense.org/index.php?topic=35298.0 We haven't tested pfSense, but I suppose that they are vulnerable t
12.
▲
by
enrico204
3y ago
Ooops! Clearly a typo :-) I've fixed it, the cached version should expire shortly.
13.
▲
by
enrico204
3y ago
Author here. No, OpenBSD's `pf` is not affected.