this post was submitted on 25 Aug 2026
291 points (98.3% liked)

linuxmemes

32849 readers
736 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry of any kind will not be tolerated. This is an LGBTQ+-friendly community -- if that is a problem for you, you should leave.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • Don't come looking for advice, this is not the right community.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves / tolerates / hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. πŸ‡¬πŸ‡§ Language/язык/Sprache
  • This is primarily an English-speaking community. πŸ‡¬πŸ‡§πŸ‡¦πŸ‡ΊπŸ‡ΊπŸ‡Έ
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  • 6. (NEW!) Regarding public figuresWe all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.
  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.
  • Β 

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 3 years ago
    MODERATORS
     
    top 22 comments
    sorted by: hot top controversial new old
    [–] LastYearsIrritant@sopuli.xyz 113 points 3 weeks ago (1 children)

    It's called a Path Traversal attack.

    Basically, if you add a ../ in a query, you can start to work backwards in the directory tree to root, then go up again to someplace you shouldn't go. The firewall doesn't block this attack, cause it's just doing a regular HTTP(s) request.

    https://owasp.org/www-community/attacks/Path_Traversal

    [–] NullPointerException@lemmy.ca 37 points 3 weeks ago (5 children)

    How would a firewall be related to this? A firewall would block/allow the ports 80/443 from certain sources. That’s it. Whatever is happening here it’s related to OS permissions and web server configuration.

    [–] chamomile@piefed.blahaj.zone 57 points 3 weeks ago (1 children)
    [–] LastYearsIrritant@sopuli.xyz 14 points 3 weeks ago

    The point of the comic is that people expect a firewall to protect them from attacks, but then the attack comes in as a path traversal and the firewall does nothing.

    Because enterpise firewalls suck ass. If you follow some security researchers on fedi it is shockingly common. Like every week there is an unauth RCE to these things and usually its ../. Is it absurd that a companies expensive first line defense is less secure than your mum's laptop? I'm sure it is "AI" ready though!

    [–] foggy@lemmy.world 10 points 3 weeks ago (2 children)

    Frankly to suggest that an enterprise firewall would be susceptible to a simple path traversal attack is insane. Unless there's the most embarrassing news story of the decade im missing? That kind of input validation is baked into basically everything these days.

    Maybe you'll land input validation using quadruple URL encoded '../' or something but even still I'd doubt that.

    So the person who replied to you is 100% correct in what it's about, but it doesn't really explain the comic. Unless it was made in like a decade ago.

    [–] helvetpuli@sopuli.xyz 10 points 3 weeks ago (1 children)

    It's pretty common in a killchain following a server side request forgery since the traffic isn't seem by the WAF.

    Example: https://github.com/watchtowrlabs/watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

    [–] foggy@lemmy.world 2 points 3 weeks ago (1 children)

    It really is not common in the common era.

    E-business suite is not a firewall. Anyone that was using it as one when this cve hit about a year ago wouldnt have qualified as "enterprise" to any required insurance, even then.

    Anyone who was using it as such was/is drowning in so much tech debt that, like, if you work there, leave. Yesterday.

    [–] helvetpuli@sopuli.xyz 1 points 3 weeks ago

    Of course it isn't.

    It was behind a WAF. But that didn't matter for the path traversal in this attack.

    [–] Manny_Folf@pawb.social 3 points 3 weeks ago* (last edited 3 weeks ago)
    [–] floquant@lemmy.dbzer0.com 2 points 3 weeks ago (1 children)

    Layer 7 firewalls are a thing

    [–] xavier666@lemmy.umucat.day 3 points 3 weeks ago (1 children)

    Layer 7 firewall sounds so wrong

    [–] floquant@lemmy.dbzer0.com 1 points 3 weeks ago

    That's why it's usually called a WAF (Web Application Firewall), although you can also have L7 firewall for non-web applications (SMTP, SQL, whatever)

    [–] comador@lemmy.world 46 points 3 weeks ago (1 children)

    MOOPSY!!!

    That's all you need to know ...

    [–] breakcore@discuss.tchncs.de 10 points 3 weeks ago

    I JUST watched that episode! Pretty nuts to see moopsy here.

    Like ten minutes ago just!

    [–] EggInDisguise@lemmy.blahaj.zone 45 points 3 weeks ago* (last edited 3 weeks ago) (1 children)

    That is a moopsy.

    It drinks bones.

    The thing cowering and having it's bones drunk is a Pyrithean swamp gobbler. Don't worry about them, they only gobble you.

    It's the moopsy you have to watch out for.

    Oh, you mean the programming type humor superimposed? No idea.

    [–] NeatNit@discuss.tchncs.de 2 points 3 weeks ago (1 children)

    Thanks, I needed that clarification. But I'm still not super sure what I'm looking at... is the skin in the second panel supposed to belong to the huge dragon in the first panel? It doesn't make sense. Presumably there's a huge body attached to that head, the shapes just don't make sense.

    Correct.

    The moopsy has drunk the swamp gobbler's bones, and now with nothing to support the squishy insides, the flesh bag drops and it's unable to move.

    Presumably they die when their bones are drunk, otherwise it's a painful few minutes or hours as your system shuts down from not having the skeletal support for organs and stuff.

    It's from a TV show called Star Trek: Lower Decks as the "oh no scary monster is chasing us" plot, and it's cuteness compared to the swamp gobble is just supposed to be funny. In order to demonstrate it's actually the real monster the fovvler cowers away from it before the moopsy jumps on it and basically it deflates like a balloon.

    [–] groet@feddit.org 29 points 3 weeks ago

    I think this is a reference to how giant security products often have very basic security vulnerabilities themselves.

    Fortinet firewall path traversal: https://www.sentinelone.com/vulnerability-database/cve-2026-59839/

    Cisco firewall path traversal: https://www.sentinelone.com/vulnerability-database/cve-2026-20018/

    Big IP firewall path traversal: https://cvefeed.io/vuln/detail/CVE-2025-26427

    All discovered in the last year

    [–] Sinthesis@lemmy.today 22 points 3 weeks ago* (last edited 3 weeks ago)

    There's other good posts here about path traversal recently but I don't think anyone has touched on...this (paths matter) has been happening for decades.

    Story time. In the early aughts (year 2000 πŸ‘΄ ) Microsoft IIS had a bug due to backwards compatibility with MSDOS πŸ’Ύ . The effect was you could find an, ummm, open FTP server, create a LPT1 or COM1 directory, then a subdirectory and this path would be invisible to the system admin. If you knew the path, you could ummm store things in it such as the latest movie, game, etc. Arrgh πŸ΄β€β˜ οΈ

    /edit Ooops, forgot this is a Linux community. Some terms:

    IIS - Microsoft's server. It had a bunch of things in one package; web server, file server, email server, etc.

    MSDOS - Oldass Microsoft operating system. I forget if its the first one. Only supports 8.3 filenames (8 characters plus 3 for file extension).

    FTP - File transfer protocol. We were sending bits over the wire without encryption, YOLO

    LPT1/COM1 - special devices in MSDOS, printer port and serial port