The Wolf's Blog
Stories from 25 years of solving tech problems. Pattern recognition in action.
Subscribe via RSSAlmost every Exchange shop with an outbound security gateway has a DMARC blind spot on auto-replies. The RFC-compliant behavior is the thing that breaks authentication.
Before I found my first vulnerability in a recent client engagement, I found evidence that someone else was already looking. Here's what a passive recon assessment surfaces, and why the results are usually more alarming than expected.
What happens when you bet on GraphQL, React Native Web, and a three-person team to rebuild a platform from ColdFusion? Six years later, it's still running.
Sometimes the scariest code to challenge isn't the broken mess - it's the legacy code that's been "working fine" for years.