LibreTechni.ca
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
not_IO@lemmy.blahaj.zone to linuxmemes@lemmy.worldEnglish · 1 day ago

can someone explain this to me? 🫪

lemmy.blahaj.zone

message-square
20
fedilink
250

can someone explain this to me? 🫪

lemmy.blahaj.zone

not_IO@lemmy.blahaj.zone to linuxmemes@lemmy.worldEnglish · 1 day ago
message-square
20
fedilink
  • LastYearsIrritant@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    94
    ·
    1 day ago

    It’s called a Path Traversal attack.

    Basically, if you add a …/ in a query, you can start to work backwards in the directory tree to root, then go up again to someplace you shouldn’t go. The firewall doesn’t block this attack, cause it’s just doing a regular HTTP(s) request.

    https://owasp.org/www-community/attacks/Path_Traversal

    • NullPointerException@lemmy.ca
      link
      fedilink
      arrow-up
      31
      ·
      1 day ago

      How would a firewall be related to this? A firewall would block/allow the ports 80/443 from certain sources. That’s it. Whatever is happening here it’s related to OS permissions and web server configuration.

      • AudaciousArmadillo@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        8
        ·
        15 hours ago

        Because enterpise firewalls suck ass. If you follow some security researchers on fedi it is shockingly common. Like every week there is an unauth RCE to these things and usually its …/. Is it absurd that a companies expensive first line defense is less secure than your mum’s laptop? I’m sure it is “AI” ready though!

      • chamomile@piefed.blahaj.zone
        link
        fedilink
        English
        arrow-up
        50
        ·
        24 hours ago

        It’s referring to a Web Application Firewall.

        • AudaciousArmadillo@piefed.blahaj.zone
          link
          fedilink
          English
          arrow-up
          1
          ·
          15 hours ago

          Unlikely.

      • foggy@lemmy.world
        link
        fedilink
        arrow-up
        11
        ·
        20 hours ago

        Frankly to suggest that an enterprise firewall would be susceptible to a simple path traversal attack is insane. Unless there’s the most embarrassing news story of the decade im missing? That kind of input validation is baked into basically everything these days.

        Maybe you’ll land input validation using quadruple URL encoded ‘…/’ or something but even still I’d doubt that.

        So the person who replied to you is 100% correct in what it’s about, but it doesn’t really explain the comic. Unless it was made in like a decade ago.

        • Manny_Folf@pawb.social
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          10 hours ago

          See this comment https://feddit.org/comment/14642166 Plus https://www.sentinelone.com/vulnerability-database/cve-2026-34790/ Granted by no means trivial methods

        • helvetpuli@sopuli.xyz
          link
          fedilink
          arrow-up
          9
          ·
          18 hours ago

          It’s pretty common in a killchain following a server side request forgery since the traffic isn’t seem by the WAF.

          Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

          • foggy@lemmy.world
            link
            fedilink
            arrow-up
            2
            ·
            17 hours ago

            It really is not common in the common era.

            E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as “enterprise” to any required insurance, even then.

            Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday.

      • LastYearsIrritant@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        12
        ·
        21 hours ago

        The point of the comic is that people expect a firewall to protect them from attacks, but then the attack comes in as a path traversal and the firewall does nothing.

      • floquant@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        2
        ·
        15 hours ago

        Layer 7 firewalls are a thing

        • xavier666@lemmy.umucat.day
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 hours ago

          Layer 7 firewall sounds so wrong

          • floquant@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            1
            ·
            3 hours ago

            That’s why it’s usually called a WAF (Web Application Firewall), although you can also have L7 firewall for non-web applications (SMTP, SQL, whatever)

linuxmemes@lemmy.world

linuxmemes@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !linuxmemes@lemmy.world

Hint: :q!


Sister communities:
  • !tech_memes@lemmy.world
  • !memes@lemmy.world
  • !lemmyshitpost@lemmy.world
  • !risa@startrek.website

Community rules (click to expand)

1. Follow the site-wide rules
  • Instance-wide TOS: https://legal.lemmy.world/tos/
  • Lemmy code of conduct: https://join-lemmy.org/docs/code_of_conduct.html
2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like “every user of thing”.
  • Don’t get baited into back-and-forth insults. We are not animals.
  • Leave remarks of “peasantry” to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community – if that is a problem for you, you should leave.
3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • Don’t come looking for advice, this is not the right community.
4. No recent reposts
  • Everybody uses Arch btw, can’t quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
5. 🇬🇧 Language/язык/Sprache
  • This is primarily an English-speaking community. 🇬🇧🇦🇺🇺🇸
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
6. (NEW!) Regarding public figures

We all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.

  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.

 

Please report posts and comments that break these rules!


Important: never execute code or follow advice that you don’t understand or can’t verify, especially here. The word of the day is credibility. This is a meme community – even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don’t remove France.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1.58K users / day
  • 4.37K users / week
  • 8.07K users / month
  • 15.9K users / 6 months
  • 2 local subscribers
  • 32.6K subscribers
  • 2.12K Posts
  • 91K Comments
  • Modlog
  • mods:
  • Kevin@lemmy.world
  • zephyr@lemmy.world
  • Err(()).unwrap()@lemmy.world
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org