slink: WAF: Wrong Approach Firewall
https://media.ccc.de/v/gpn24-385-waf-... Web Application Firewalls (WAFs) for filtering based on HTTP and payload are omnipresent. In this talk an argument will be made that, in many cases, the wrong approach for implementing WAFs is chosen: They are implemented as "deny firewalls" which specifically forbid "bad" traffic based on pattern rules, while for network security (layers 3/4) professionals would only ever follow an "allow firewall" approach, which explicitly lets "good" traffic pass and denies everything else. "deny WAFs" are oftentimes marketed as simple, easy to use, out-of-the-box solutions, but, by design, they can only prevent known exploits. Also, practical aspects limit their potential, when rulesets breaking functionality have to be disabled. While the "allow WAF" approach presented here implies more effort, its main advantage is protection against new attack vectors ("zero days") and it comes with a lot of side benefits, such as improved performance and resilience through caching. Concepts will be introduced: HTTP Basics Signed URLs / signed requests Regular Expressions HTTP Caching Practical examples with Vinyl Cache will be presented: Rules based on HTTP method and URL Header filtering Regular Expressions on body data slink https://cfp.gulas.ch/gpn24/talk/9TSLFQ/ #gpn24 #CyberSecurity Licensed to the public under https://creativecommons.org/licenses/...

Pwning Bossware for Fun and Ethics
![Die drei Klammern [] {} () und die BASH](https://i.ytimg.com/vi/-mK-pSTLXMM/hq720.jpg?sqp=-oaymwEbCNAFEJQDSFryq4qpAw0IARUAAIhCGAG4AvcY&rs=AOn4CLDPFFLAwxIhkqzwXZF_6XBEzKWbnA&usqp=CCc)
Die drei Klammern [] {} () und die BASH

Microsoft Just Released Their Own Linux Distro: Should You Be Worried?

RE//verse 2026: Thinking Like a Compiler: Obfuscation from the Other Side by Laurie Kirk
![[DCTF23] q3k: Breaking iPod Nano security for fun and Linux](https://i.ytimg.com/vi/WQtt7O5OXe0/hq720.jpg?sqp=-oaymwEbCNAFEJQDSFryq4qpAw0IARUAAIhCGAG4AvcY&rs=AOn4CLAJP-Q-H8TBk6cvlhTZAwgeK5G62A&usqp=CCc)
[DCTF23] q3k: Breaking iPod Nano security for fun and Linux

Tony Wasserka: Breaking architecture barriers: Running x86 games and apps on ARM

Reinventing Entropy | Compression is Intelligence Part 1

I Don't Think I Can Go Back To Windows...

giulioz: MMO-CHIP: From Microscope to Verilog in an hour

Trump Preps for 80th Birthday, Threatens to Hit Iran, Knicks Historic Win & Elon Musk Trillionaire!?

Something is jamming GPS over Europe. Here's what we found

Linus Torvalds: AI Is Changing Linux Fast

This is not the AI we were promised | The Royal Society

How Passkeys Work - Computerphile

Threads vs Coroutines — Why C++ Has Two Concurrency Models - Conor Spilsbury - CppCon 2025

I Bought the Trump Phone

Three decades of curl - Daniel Stenberg - NDC Security 2026

I Hacked This Temu Router. What I Found Should Be Illegal.

Harald: strace -- mein schweizer Taschenmesser zum analysieren, debuggen, monitoren

