.ICU TLD - I See You Spammer

ICANN’s decision to cash in and allow an unlimited number of new gTLDs has provided us with several new TLDs used predominantly for criminal purposes by malicious actors. My inbound mail servers have been flooded with spam from thousands of .icu domains for the better part of 2019.

The Slackware Linux Patreon page is officially confirmed

Patrick Volkerding has finally confirmed the authenticity of the Slackware Linux Patreon page in a post over at LinuxQuestions.org.

After the Slackware Patreon page was initially discovered in mid-June 2019, it has been the source of quite a bit of debate regarding its authenticity. Anyhow, with that question out of the way, the bigger question now is whether there is still enough interest in Slackware Linux to make it a sustainable business for Mr. Volkerding.

Migrating from WordPress to Hugo

In preparation for my move from WordPress to Hugo, I read a few blog posts on the subject to make sure I wouldn’t run into a brick wall. After all, Google had already indexed over 3000 posts covering the subject in detail so what could possibly go wrong?

Everything's bigger in Texas

I was spending an evening window shopping for a future BSD hosting provider when I came across ARP Networks and its list of VPS plans. What caught my attention was not the technical specifications, but rather the naming scheme that I found to be simply astounding.

A digital ocean of bots

Last week I noticed yet another ongoing brute-force attack against our managed WordPress hosting. The botnet is very low key and each bot connects on average only once per day. Up until now, I’ve collected in the ballpark of 3100 unique bots.

Njalla adds DNSSEC support

Your favorite privacy-aware domain registration service now supports DNSSEC with the click of a button. I’m not exactly sure when this got added, but DNSSEC is now available for selected TLDs.

How to enable TLS 1.3 on Gentoo Linux

I figured it was about time for this Gentoo powered blog to enjoy the security and performance enhancements provided by TLSv1.3. However, that meant leaving “Gentoo stable” behind and travel on a journey of discovery into the land of the unmasked and dangerous.

Email service providers should kill off the bitcoin extortion scam

Like everyone else with an email address, I’ve been receiving these bitcoin extortion messages for months. I’ve also observed with ever greater dissatisfaction as scammers raked in tens of bitcoins within a week. What especially annoys me is not so much that people are falling for this scam, but that email service providers are simply looking the other way.

An insignificant WordPress brute-force attack

Earlier this week I noticed a minor brute-force attack against our managed WordPress hosting. The attack lasted for 72 hours and deployed around 2000 unique bots. The botnet attempted on average 100 logins per hour while rotating bots to avoid triggering our automatic defense systems.

How to subscribe to a Slackware Linux mailing list

A while back I lost access to the email address with which I had subscribed to the slackware-security mailing list. This does not please Bob, so today I logged into my webmail account and sent along a new request to join slackware-security and slackware-announce. The response I got in return gave me a good laugh and a swift feel of nostalgia.

Abandoning the Gutenberg ship

Even though I really enjoy the new Gutenberg experience from a content creator’s point of view, I’ve come to the conclusion that it’s not the right editor for me. My dear Gutenberg, it’s not you, it’s me.

Migrating from LastPass to KeePassXC

I’ve never really felt all that good about storing my passwords on the public cloud, but after we started using LastPass at work I somehow got lulled into adopting it for personal use as well.