Category: Security

2026

13

Sep

Linux Snippets #13: Ask the Machine What Killed It

After a reboot, every Linux server develops temporary amnesia and insists that everything is running perfectly. Fortunately, the journal may remember the OOM killer, dying disk, or panicking service from five minutes earlier. Here is how to question the previous boot before log rotation provides it with legal representation.

Read more

11

Sep

Linux Snippets #12: tcpdump Without Capturing the Entire Internet

Capture everything and inspect it later’ sounds reassuringly forensic until the PCAP consumes the disk, records half the office, and still buries the failed handshake beneath six million irrelevant packets. Here is how to make tcpdump answer one question at a time – with limits established before optimism becomes an incident.

Read more

04

Aug

Linux Snippets #9: The Ephemeral Workspace (tmpfs)

Working with highly sensitive plaintext files or trying to stop your Raspberry Pi from burning through SD cards? Here is how to carve out a chunk of your system RAM and mount it as a physical, completely volatile hard drive.

Read more

18

May

How WordPress Attackers Get Their Dirty Fingers into your System

Most WordPress malware does not begin with a shadowy genius manually editing your theme at midnight. It begins with bots, bored plugins, sloppy permissions, and one unlucky functions.php file that became writable. This is the story of how attackers get the pen, why they keep writing, and why deleting one dirty file is rarely enough.

Read more

14

May

The WordPress Backdoor That Forgot to Be PHP

A WordPress backdoor hidden in functions.php is bad enough. One pasted after the closing ?> tag is almost poetic: malware that forgot to become PHP and instead printed its own confession. Here is a technical walk-through of a hidden admin account, query tampering, fake user counts, and the grim beauty of neglected WordPress hygiene.

Read more

04

May

Rclone: Zero-Trust Cloud Storage Without the Friction

Stop trusting cloud providers with your personal data. Here is how to use rclone to build a transparent, client-side encryption layer over Dropbox or pCloud

Read more

26

Apr

April 26: A 40-Year Anniversary of Meltdowns

April 26 marks the 40th anniversary of the Pripyat disaster. It also marks the detonation date of the most destructive virus of the 90s: the CIH space-filler

Read more

22

Apr

gh is watching you

Github is watching you

github has a nice and easy cli tool to use, but if you thought that it would let you keep your privacy – think again!

Read more

20

Apr

Meshtastic vs Reticulum: Why Reticulum Wins for Scalable Sovereign LoRa Networks

Meshtastic is currently dominating the off-grid communication hype cycle. But when we look under the hood at its managed flooding architecture and symmetric cryptography, does it actually hold up as a foundation for sovereign infrastructure? Here is a deep dive into why I am shifting my focus to the Reticulum Network Stack.

Read more

06

Apr

The Cryptographic Zombie: How Keybase Went from Privacy Darling to Zoom’s Cleanup Crew

Once the ultimate geek flex for cypherpunks, Keybase promised to make PGP cryptography accessible to mere mortals. Today, it hovers in the digital ether as a “zombie” app. Here is the story of how a revolutionary open-source identity platform was cannibalized to become Zoom’s corporate cleanup crew.

Read more