Skip to content

Webex Is Looking For Your Certificates On A Cisco Build Server

Webex 46.8.0.35631 on Fedora 44 sits behind a yellow banner reading “Offline - No internet connection” while every other program on the machine reaches the internet without complaint. It stopped the VoIP line dead. The network was never the problem: Cisco bundle their own fork of OpenSSL and built it with OPENSSLDIR set to /workspace/.conan2/p/b/cisco8ee8b59cf93de/p/ssl, a directory that exists on a build container and nowhere else, so it loads no trust anchors and every handshake fails. The post runs in order: what the broken state actually is, asking the shipped library where it thinks its certificates live, reproducing the exact error code outside Webex, why nothing warns you, the two fixes that do not work and why, and the one that does. Then the build process: they used $ORIGIN for the code and left three data paths absolute, the RPM header names a container ID so the container was already in the pipeline and never used to run the result, the package requires a glibc from 2018 because they will not link statically, 2.2 GB is shipped twice, and it carries no documentation and no file marked as configuration. Then how it should have been built, the six fixes and the one-line check that catches it. And finally the cross-check: Cisco hold 98 entries in CISA’s known-exploited catalogue, second only to Microsoft, and a trust path nobody checked and a bypass nobody checked are the same failure at different stakes.

15th September 2026 · 42 min · 9141 words · Damien Dye

A VPN Out of Parts: PPP, Tap Devices and Netcat

A VPN is two jobs: something that makes a virtual link, and something that carries the bytes. PPP has done the first since 1994 and does not care what the second is — which is why PPTP, L2TP and every dial-up line you ever used are the same protocol over different carriers. Netcat is a carrier. This builds it both ways. First pppd: the pty option and what it does with a pseudo-terminal, the TCP version everyone tries first, why running a stream protocol inside TCP melts under loss, the UDP version that is the one to use, the async HDLC framing and the ACCM that decides how much bandwidth goes on escaping control characters, addressing and routing and IPV6CP, and keeping the link up when the carrier dies without telling you. Then the same tunnel with no PPP at all — a tap device, one datagram per frame over UDP, the length prefix you have to invent yourself over TCP, tun against tap, and bridging. Then the part netcat has no answer for: wrapping the carrier in TLS with ncat, stunnel and openssl, and in DTLS with socat, which is the shape you actually want. It is never really the right tool, and that is the point: it shows how egress behaves once an attacker has root inside your network and outbound access was not blocked by default, and why default-deny at the border is the only control that was ever real.

14th September 2026 · 60 min · 13122 words · Damien Dye

Ping: The Diagnostic Tool That Opens a Whole Lot More

Ping, not the rest of ICMP, is the liability: echo is a channel every host must answer with your own bytes, so a network that ‘only allows ping’ already has a full VPN out. This walks the threat first — what it costs your egress, and how a visitor on your WiFi or an unlocked ethernet port can open one — then three working tunnels built on ping alone (Hans, icmptunnel, and a short Python one with AES-128), the MTU and IPv6 catches, and the rule that shuts it: drop echo, keep the errors, in nftables, pf, Cisco, Junos, MikroTik and Windows.

1st September 2026 · 36 min · 7657 words · Damien Dye

The Firewall Is Eleven Hops Away

“Port 445 is blocked somewhere” is not a diagnosis, and it is why firewall tickets bounce between you and your provider for a week. Every router on the path owes you an ICMP Time Exceeded when your hop budget runs out, and that turns a timeout into a distance. I walked the TTL up on my own line and found three faults I did not know I had: an SMB drop eleven hops out, forged SMTP resets one hop away, and an IPv4 rule with no IPv6 twin.

28th August 2026 · 38 min · 8038 words · Damien Dye