#nginx

24 posts · Last used 5d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 28, 2026
A public PoC now details CVE-2026-42533, an NGINX heap overflow with an ASLR bypass and possible RCE. Upgrade to NGINX 1.31.3 or 1.30.4 now. #NGINX #CVE202642533 #RCE #HeapOverflow #ASLRBypass #NGINXPlus #PoC #Cybersecurity https://securityonline.info/nginx-heap-overflow-cve-2026-42533/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
IPng Networks @IPngNetworks@ublog.tech · Jul 27, 2026
The bots and botting. Lots of scanners and poking and prodding, mostly trying to deface wordpress and log4j that we do not run. Such a sad world, where the webserver gets 1M/day of useless requests. Think of the energy and logspace that could be saved! #nginx #counterabuse
6
4
4
Security Crawler Carl @security_crawler_carl@infosec.exchange · Jul 27, 2026
Replying to @security_crawler_carl@infosec.exchange
You do not get to respawn. The debuff is applied to all servers simultaneously. Enjoy your stay. Patch NGINX now to address CVE-2026-42945 before the PoC makes your threat landscape significantly more crowded. Reward: You've received the Mandatory Participation Trophy — it's just a heap of broken memory. #Nginx #RCE #CyberSecurity #ZeroDay #BufferOverflow #ExploitUnlocked (2/2)
0
0
0
securityaffairs @securityaffairs@infosec.exchange · Jul 20, 2026
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 20, 2026
🚨 15 years. Millions of servers. One hidden bug. CVE-2026-42533 is a critical NGINX heap buffer overflow lurking since 2011 that can crash worker processes and, under specific conditions, may enable Remote Code Execution (RCE) via specially crafted HTTP requests. Attackers don't just target software versions. They target vulnerable configurations. Upgrade now. 🔥 ✅ Deep technical breakdown: • Why the bug survived for 15 years • Heap buffer overflow explained • LEN vs VALUE script engine flaw • PCRE capture overwrite • Vulnerable nginx configurations • Affected versions • Patch analysis • Mitigations • RCE conditions 📖 Read the full analysis: https://thecybersecguru.com/news/cve-2026-42533-nginx-rce-vulnerability/ #CVE202642533 #NGINX #CyberSecurity #InfoSec #Linux #RCE #HeapOverflow #MemoryCorruption #WebSecurity #DevSecOps #CloudSecurity #Kubernetes #ReverseProxy #Vulnerability #ZeroDay #Exploit #AppSec #BlueTeam #RedTeam #F5
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 19, 2026
🤖 CVE-2026-42533: Critical heap buffer overflow in NGINX. Unauthenticated remote attacker can crash workers or achieve RCE via crafted HTTP requests. Patched in nginx 1.30.4 (stable) and 1.31.3 (mainline). 🔗 https://thehackernews.com/2026/07/critical-nginx-vulnerability-can-crash.html #CVE #NGINX #F5 #CyberSec
0
0
0
Jörg 🇩🇪🇬🇧🇪🇺 @AlienJay@burningboard.net · Jul 19, 2026

Ich habe heute endlich mein PiHole wieder aufgesetzt. Der war nun gut eine Woche weg. Und erst da habe ich so richtig gespürt, was der hier im Heimnetz leistet. Nun ist es wieder gut. Werbung ist weg.

Statt Portainer läuft hier nun der von mehreren Seiten empfohlene Dockhead. Gefällt mir sehr gut.

Ich habe dann auch mal für alle Docker Container einen Healthcheck aufgesetzt. Außer für Snowflake-Proxy. Da habe ich ihn nicht zum Laufen bekommen.

Was läuft hier jetzt alles auf dem #RaspberryPi im #Docker?

  1. #HomeAssistant (Smart Home)
  2. #PiHole (Werbeblocker)
  3. #Dockhead (Docker Containerverwaltung)
  4. #Mosquitto (MQTT-Server)
  5. #Snowflake (TOR Proxy)
  6. Watchtower (Autoupdater für Snowflake)

Was nun noch ansteht:

  1. Herausfinden, wie ich mitbekommen kann, wenn ein neues Image einer Software im Docker vorliegt.
  2. Herausfinden wie ich mitbekomme wenn Updates der Sperrlisten im PiHole vorliegen
  3. #Nginx aufsetzen als Reverse Proxy
  4. #ESPhome Devices für HomeAssistant aufsetzen
0
5
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 16, 2026
F5 patched the NGINX code execution flaw CVE-2026-42533, along with CVE-2026-60005 and CVE-2026-56434. Update NGINX Plus and Open Source builds now. #NGINX #CVE202642533 #CodeExecution #F5 #Vulnerability https://securityonline.info/nginx-code-execution-cve-2026-42533/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Dennis - DeKayy @DeKayy@defcon.social · Jul 06, 2026
Boosted by Welcoming committee @welcome@friends.deko.cloud
Hello again, Fediverse, time for my #introduction First off, this account exists mainly to hopefully get #fedihired hopefully so set expectations accordingly. Boosts are appreciated. With that out of the way, I am Dennis also known as DeKayy. I am an OSS enthusiast currently living in the area around #Frankfurt , being fluent in both English and German. Outside of technology, my passions lie with equality, equity, independence, generally making the world a better and more fair place. A homelab and ever increasingly independent tech-stack is also what I call my own. On the career side, I have been a System and Network-Administrator for nearly 4½ years and counting. And as mentioned, currently on the lookout for new opportunities, preferable completely remote. I manage around 20 #Proxmox nodes professionally and 3 in my personal deployments, the amount of #Debian VM's and containers (including #Docker) sits somewhere in the hundreds. With #Ansible slowly getting established in every nook and cranny to help with the whole process. Monitoring is done on both sides with #Zabbix and serving web-requests with either #Nginx and #Apache, though I prefer the former. I use Let's Encrypt and Cloudflare quite a lot, also having built a certificate distribution framework to deploy those internally behind metaphorical split-brain DNS lines. Windows Server and Puppet are also not unfamiliar to me, they are currently not frequent acquaintances. In the direction of #DevOps experience, I use Git daily, I either setup, helped with or run Jenkins buildsystems, Gitlab instances, Gitlab-runners and more. Development-wise I created applications, tools and helpers in C#, Java, Bash, Powershell, Lua and Python, in order of proficiency. I bring enough social skills, experience, passion and conviction to help build and run an entire independent tech stack if one wishes for it and brings enough patience, time and budget. What I am looking for is primarily a remote position, 60% work-from-home is my minimum. This introduction post is getting kinda long so I will leave it here for now, reach out if you are interested. Later, DeKayy #sysadmin #fedihire #fedihire_de #fedihire_eu
0
0
1
Larvitz :fedora: @Larvitz@burningboard.net · Jul 05, 2026
New on the blog: patching FreeBSD machines inside DN42 without giving them a clearnet route. A small dual-homed VM lazily caches pkg.freebsd.org, update.freebsd.org and ftp.freebsd.org with nginx proxy_store, chases CDN redirects server-side, and serves it all over IPv6 into the mesh. pf default-denies both directions, and clients keep verifying signatures against the official FreeBSD keys. It is also a public DN42 service: point freebsd-update, pkg or bastille at bsdmirror.chofstede.dn42 and go from empty jail host to fully patched without touching the clearnet. https://blog.hofstede.it/a-caching-freebsd-mirror-for-dn42-nginx-proxy_store-pf-and-a-dual-homed-vm/ #FreeBSD #DN42 #nginx #RunBSD #SelfHosting
12
0
14
zeitrafferin @zeitrafferin@infosec.exchange · Jul 03, 2026
Hier schon mal mein neues -slop- Vibecoding-Projekt: eine Bildergalerie auf Basis des #Linux-Dateisystems. Mit Suchtstrings und - später - Ordnern, mit dem Webserver in einer schöne URL zum Verlinken für Freunde ausgeliefert. Am Beispiel des Ouessant-Schafes aus dieser Kolumne: https://taz.de/Kolumne-Bio/!5106072/ Pic explorer https://seeliger.cc/explorer/schaf #php #nginx #kisklop #taz #ouessant
0
1
0
Elena Brescacin @elettrona@poliversity.it · Jun 10, 2026
Self-hosting journey update, and WordPress: latest development from a super-newbie @selfhosted I must recap as I set my instance to delete 2-weeks-old posts. Months ago, I talked about my very first journey with self-hosting my digital services, including my website. As I'm not very skilled with sysadmin stuff, I use a YunoHost installation with all its pros and cons. Having severe accessibility needs (I'm totally blind) I have limited choices for what concerns CMS software with related extensions if any. So after months of exploration and test, I've come back home. To WordPress. Last time I updated Fediverse about my experience, I was struggling with multisite network giving an unpleasant error in the non-main site, such as "too_many_redirects" Making it short, I discovered that YunoHost doesn't let me run a multisite properly when installed in a subdomain such as blog.domain.tld So I had forcefully to install it in the main domain, and a subdirectory such as domain.tld/wp Now I'm concentrating on my theme, I will clone it with the plugin "CreateBlockTheme" then activate it network-wide. I need a multisite for multilingual, as all current multilingual plugins have poor accessibility support, and are mostly paid. Then I may need a new taxonomy registered to organize stories, the glossary plugin, SEO plugin, ActivityPub, and I should be all set! The last, hard, challenge I have, is the fact that now my site runs into "domain.tld/permalink-post" for Italian, and "domain.tld/english" for English The new one should run "domain.tld/wp/post" and "domain.tld/wp/english/post" YunoHost doesn't let me build a WordPress site in the root directory with multisite installed, so I must find the way to tell nginx I want the product to be physically on /wp/ but browser can point to domain.tld/post or domain.tld/english/post... And if possible, this change to be in a file on its own, in order to be able to delete it without damaging the whole nginx conf. Last detail, I'm on hostinger, kvm2 package. vps. #experience #multisite #nginx #SelfHosting #WordPress #YunoHost
0
2
11
Jason Weatherly @jamesthebard@social.linux.pizza · Apr 18, 2026

After fixing two AUR PKGBUILD files and a bit of patching, the initial rough Arch repo is online. Even made the package list look good with some fancy indexing. The compile takes a long time, but since it's in a VM I'm not too bothered about it. I will probably make an actual build system, but for now the crontab will suffice.

#archlinux #nginx #svtav1 #handbrake #vapoursynth

1
0
0
stux⚡️ @stux@mstdn.social · Apr 15, 2026
#Laravel has something handy, it's called "Herd" "One click PHP development environment. Zero dependencies. Zero headaches." https://herd.laravel.com #PHP #Nginx
5
2
5
Larvitz :fedora: :redhat: @Larvitz__dup_34529@burningboard.net · Feb 21, 2026
Spent way too long getting HTTP/3 working on FreeBSD with nginx, so I wrote it all up. The highlights: stock OpenSSL silently breaks QUIC at the HTTP/3 framing layer (the TLS handshake succeeds, so openssl s_client lies to you). eBPF worker routing doesn't exist on FreeBSD. And if nginx is in a jail with IPv4 NAT, a pass rule for UDP 443 is useless without a matching rdr. New post: https://blog.hofstede.it/http3-on-freebsd-getting-quic-working-with-nginx-in-a-bastille-jail/ #FreeBSD #nginx #HTTP3 #QUIC #Networking
26
5
16