John Kristoff

1,087 Followers
605 Following
2.3K Posts
UIC PhD candidate | https://Dataplane.org | Netscout. Internet infrastructure (#BGP, #DNS) and #infosec. Bit mechanic. Also: #Blues / tfr / #fedi22
Homepagehttps://dataplane.org/jtk

New blog post: Journeys in Hosting 2/x - OS template considerations

https://dataplane.org/jtk/blog/2026/03/hosting-stories-2/

John Kristoff - Journeys in Hosting 2/x - OS template considerations

"Security Vulnerabilities in RFC 8484 - DNS Queries over HTTPS (DoH)"

https://mailarchive.ietf.org/arch/msg/dnsop/cQ_mFaRYeOvpr4gWfIAoL1e5hDg/

#DNS

[DNSOP] Security Vulnerabilities in RFC 8484 - DNS Queries over HTTPS (DoH)

Search IETF mail list archives

New from the FIRST.org NETSEC SIG:

Characterizing Abusive IP Proxies

https://www.first.org/global/sigs/netsec/NETSEC.characterizing-abusive-IP-proxies.pdf

Many years ago Jim Warner started a page dedicated to documenting port buffers on network hardware, which has become the de facto source for much of this information. Since Jim's passing a few year ago this site has been taken down and restored a few times. In keeping with his tradition and to help the community, I have mirrored and expanded the site with significantly more platforms and chipsets. https://port-buffers.forwardingplane.net #neteng #networkengineering
Packet Buffer Reference

Packet buffer comparison table for networking switches, grouped by ASIC family

Packet Buffer Reference
It looks like a lot of prefix updates (mostly withdrawals for more specifics) for a number of US DoD (DNIC) ASNs, even more activity than what I saw when US/Israel attacks on Iran began. I'd caution not to read too much into this, but waiting to see if this foreshadows something.

You know you're an Internet old timer if you remember Gene Ray, self described "Cubic and Wisest Human"

That's right, the infamous Time Cube! Look it up and try to comprehend such simple math with your oneist brain noobs :-)

Weekend Reads

* DNS parser overflow in Zephyr
https://www.0xkato.xyz/CVE-2026-1678-DNS-Parser-Overflow-in-Zephyr/
* Telegram bots measurement survey
https://arxiv.org/abs/2603.24302
* AS-path prepending for anycast optimization
https://arxiv.org/abs/2603.21082
* Building the largest data center
https://spectrum.ieee.org/5gw-data-center
* OpenBSD init system and boot process
https://overeducated-redneck.net/blurgh/openbsd-init-system.html

#DNS #Telegram #BGP #AI #OpenBSD

CVE-2026-1678: DNS Parser Overflow in Zephyr

A walkthrough of CVE-2026-1678, a critical out-of-bounds write in Zephyr’s DNS name parser caused by a stale bounds check

0xkato

Ubuntu will be adopting ntpd-rs as the default time sync client/server if all goes according to plan for release 27.04 (~2027). For most this means replacing chrony.

https://discourse.ubuntu.com/t/ntpd-rs-its-about-time/79154/1

#NTP

Ntpd-rs: it's about time!

I am thrilled to announce the next target in our campaign to replace core system utilities with memory-safe Rust rewrites in Ubuntu. In upcoming releases, Ubuntu will be adopting ntpd-rs as the default time synchronization client and server, eventually replacing chrony, linuxptp and with any luck, gpsd for time syncing use-cases. ntpd-rs is a full-featured implementation of the Network Time Protocol (NTP), written entirely in Rust. Maintained by the Trifecta Tech Foundation as part of Project P...

Ubuntu Community Hub

I may regret this. You may regret this.

I've just put out a Linux forensics scenario for you all to play around with. There's a contest. You r submissions are due by 2026-04-15 23:59 UTC.

https://righteousit.com/2026/03/27/linux-forensic-scenario/

#DFIR #Linux

Linux Forensic Scenario

Introducing a contest based around a new Linux forensic scenario I created. Submissions for judging are due by 2026-04-15 23:59 UTC!

Righteous IT