BadBox in the Living Room: Forensic Analysis of a VSeeBox V3 Plus

A VSeeBox V3 Plus had been sitting on a quarantine VLAN in my living room since last year. I’d isolated it after suspecting a BadBox infection and hadn’t gotten around to pulling it apart. This weekend I finally did. The short version: the device is infected with BadBox 2.0 malware. The SOCKS5 proxy was live and accepting connections from residential IPs. The DNS blocklist was being bypassed with encrypted DNS. And one domain in the traffic trace points directly back to VSeeBox’s own infrastructure. ...

July 6, 2026 · 6 min · Adam Behn

Self-Service IP Registration for Family Jellyfin Access

After setting up Cloudflare Tunnel with Zero Trust Access for Jellyfin, I hit a new problem: family members with Rokus and Apple TVs outside my network couldn’t get through the email OTP gate. Streaming device apps can’t render a Cloudflare login page or enter an OTP code. The Problem Cloudflare Access works great for browsers. But Jellyfin client apps on Rokus, Apple TVs, and phones make direct API calls. They need to reach Jellyfin without a browser-based auth step in the middle. ...

April 19, 2026 · 4 min · Adam Behn

Exposing Jellyfin Through Cloudflare Tunnel with Zero Trust Access

I needed to access my Jellyfin media server from a managed work laptop where I can’t install Tailscale or any VPN client. Cloudflare Tunnel solved this: outbound-only connection from the LXC, no open firewall ports, and a Zero Trust email OTP gate before anyone can reach Jellyfin. The Problem My Jellyfin instance runs in an LXC container on Proxmox. It’s accessible over Tailscale from my personal devices, but some environments have endpoint protection that blocks VPN installs. I needed a way to access my media library over plain HTTPS without installing anything on the client. ...

April 18, 2026 · 4 min · Adam Behn