veganism.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Veganism Social is a welcoming space on the internet for vegans to connect and engage with the broader decentralized social media community.

Administered by:

Server stats:

297
active users

#nginx

8 posts7 participants0 posts today

Released: #swad v0.1 🥳

Looking for a simple way to add #authentication to your #nginx reverse proxy? Then swad *could* be for you!

swad is the "Simple Web Authentication Daemon", written in pure #C (+ #POSIX) with almost no external dependencies. #TLS support requires #OpenSSL (or #LibreSSL). It's designed to work with nginx' "auth_request" module and offers authentication using a #cookie and a login form.

Well, this is a first release and you can tell by the version number it isn't "complete" yet. Most notably, only one single credentials checker is implemented: #PAM. But as pam already allows pretty flexible configuration, I already consider this pretty useful 🙈

If you want to know more, read here:
github.com/Zirias/swad

🔍🚫 In today's riveting episode of "Science Mysteries," experts are flabbergasted to learn that protoplanetary disks are smaller than expected! 🌌🔬 But don't worry, you can't read the details because the article is locked—403 Forbidden! 🎉 Thanks, #nginx, for always keeping us on the edge of #ignorance. 📚❌
centauri-dreams.org/2025/04/04 #ScienceMysteries #ProtoplanetaryDisks #403Forbidden #SpaceExploration #HackerNews #ngated

www.centauri-dreams.orgProtoplanetary Disks Are Smaller Than Expected | Centauri Dreams

🤣🚴‍♂️ In the latest thrilling installment of "Please, Someone, Explain This", we are greeted with the ever-insightful commentary of "403 Forbidden" repeated twice for emphasis, courtesy of the oh-so-mysterious #nginx oracle. Apparently, tariffs have rendered bikes as off-limits as the secrets of Area 51—except with fewer aliens and more server errors. 🚫🛑
renehersecycles.com/bikes-in-t #HackerNews #403Forbidden #bikeTariffs #serverErrors #HackerNews #ngated

Rene Herse CyclesBikes in the Age of TariffsToday's post was going to be about a new product we're introducing—but we need to hold off while we recalculate our prices. You've probably seen the news: Virtually all imports into the United States will be subjected to additional, steep import taxes, also called tariffs. The…

After trolling through many tags and lists trying to see what folks enjoy for #smallweb site generators and frameworks seems like good old dusty #jekyll and #nginx is probably as good as bet as any. One constraint thats not implicitly met by Jekyll is no javascript, but that’s reliant on themes.

For hosting.. probably just find something reasonable through #lowendtalk since I’ve been unable to convince #linode my account from > 10 years ago is actually mine.

I've set up my new #inkscape website AI bot trap. It works by giving everyone a chance to not fall into it.

An anchor link that says "I am a bot" and links to /P3W-451/{datetime}/ it's got a fixed position at top -100px so should never be seen

The robots.txt says "Disallow: /P3W-451/" so if you were reading the robots, you'd know.

Then #nginx logs the requests to a log of their ip-addresses and browser strings and sends them a 301 redirect to google.com

#ai #Scraping

1/2

First "production test" successful 💪 ... after band-aid "deployment" (IOW, scp binaries to the prod jail).

#swad integrates with #nginx exactly as I planned it. And #PAM authentication using a child process running as root also just works (while the main process dropped privileges). 🥳

So, I guess I can say goodbye to #AI #bots hammering my poor DSL connection just to download poudriere build logs.

Still a lot to do for #swad: Make it nicer. So many ideas. Best start would probably be to implement more credentials checking modules besides PAM.

How to Setup a Reverse #Proxy with HTTPS Using #Nginx and #Certbot (5 Minute Quick-Start Guide)

This article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.
What is a Reverse Proxy?
A reverse proxy is a server that sits between client devices and a backend server, forwarding client requests to the backend server and returning the server's response to the clients. Unlike a forward proxy, ...
Continued 👉 blog.radwebhosting.com/how-to- #proxyserver #reverseproxy #letsencrypt

How to Setup a Reverse Proxy with HTTPS Using Nginx and Certbot
RadWeb, LLC · How To Setup A Reverse Proxy With HTTPS Using Nginx And Certbot (5 Minute Quick-Start Guide) - VPS Hosting Blog | Dedicated Servers | Reseller HostingThis article outlines how to setup a reverse proxy with HTTPS using Nginx and Certbot.

I finally poked at my nginx logs, because generally nothing happens on my servers

202.155.137.157 - - [30/Mar/2025:00:53:00 +0100] "GET /mirrors-JapanMapTranslate-github/patch/bin/kanaconv/HiraganaConverterImpl.class?id=c1c09efe21a09ecbd6f95641c8a0086ec538ae39 HTTP/1.1" 200 663 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-us) AppleWebKit/312.5 (KHTML, like Gecko) Safari/312.3"

yeah... yeah... ok... this bitch is accessing ONE specific file as Power PC Mac OS X ???

get the fuck outta here.

% Information related to '202.155.137.0/24AS212238'

route: 202.155.137.0/24
origin: AS212238
descr: CV. Rumahweb Indonesia
Jl. Arimbi No. 482
Kel. Banguntapan, Kec. Banguntapan
mnt-by: MAINT-CRI-ID
last-modified: 2025-02-25T00:03:14Z
source: APNIC

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #13/2025 is out!

It includes the following and much more:

➝ DNA of 15 Million People for Sale in #23andMe Bankruptcy,

#Trump administration accidentally texted a journalist its war plans,

➝ Critical Ingress #NGINX controller vulnerability allows RCE without authentication,

#Cyberattack hits Ukraine's state railway,

➝ Troy Hunt's Mailchimp account was successfully phished,

#OpenAI Offering $100K Bounties for Critical #Vulnerabilities,

#Meta AI is now available in #WhatsApp for users in 41 European countries... and cannot be turned off

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

X’s InfoSec Newsletter🕵🏻‍♂️ [InfoSec MASHUP] 13/2025DNA of 15 Million People for Sale in 23andMe Bankruptcy, Trump administration accidentally texted a journalist its war plans, Critical Ingress NGINX controller vulnerability allows RCE without authentication, Cyberattack hits Ukraine's state railway, Troy Hunt's Mailchimp account was successfully phished, OpenAI Offering $100K Bounties for Critical Vulnerabilities, Meta AI is now available in WhatsApp for users in 41 European countries... and cannot be turned off

@bagder Wow. For a few months, I was wondering why I suddenly have bandwidth issues when activating my camera in MS Teams meetings, so others can't understand me any more.

A look into my #nginx logs seems to clarify. Bots are eagerly fetching my (partially pretty large) #poudriere build logs. 🧐 (#AI "watching shit scroll by"?)

I see GPTBot at least occassionally requests robots.txt, which I don't have so far. Other bots don't seem to be interested. Especially PetalBot is hammering my server. And there are others (bytedance, google, ...)

Now what? Robots.txt would actually *help* well-behaved bots here (I assume build logs aren't valuable for anything). The most pragmatic thing here would be to add some http basic auth in the reverse proxy for all poudriere stuff. It's currently only public because there's no reason to keep it private....

Have to admit I feel inclined to try one of the tarpitting/poisoning approaches, too. 😏

After a lot of tinkering, we finally made it to the latest release of the #nginx ingress controller on the mstdn.dk cluster. The latest release addresses no less than FOUR #CVE records. Critical configuration areas had changed, the GeoIP database had to be cached to avoid rate limiting and the #LUA engine needed some tweaks before it could handle the relative large number of TLS certificates we're using in the cluster, but we finally made it. Sorry about the hick-ups. We're trying to keep expenses from going through the roof, so we've skipped the test setup in favor of gently tweaking things in production. Usually that goes well, but there is the rare exception.

Somewhat related, the #KubeCon / #KubeConEU #Kubernetes conference is next week, which means I'll be in #London for the first time for an entire week. Any suggestions for things worth visiting for a bunch of #nerds? :D

Mastodon hosted on mstdn.dkmstdn.dkJust your average friendly Danish Mastodon server. New users tooting in Danish/English welcome. Administered from Denmark. Hosted on bare-metal Kubernetes in the EU.

🛫✈️ Oh no! Airline demand has plummeted faster than a lead balloon 🎈💥 between Canada and the US. But don't worry, the article's got all the details... except it's behind a 403 Forbidden wall. 🛑🙈 Thanks, #nginx, for keeping us blissfully ignorant!
onemileatatime.com/news/airlin #AirlineDemand #AirlineNews #403Forbidden #CanadaUSTravel #HackerNews #ngated

One Mile at a Time · Airline Demand Between Canada & United States Collapses, Down 70%+By Ben Schlappig