infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@ulldma that, or something from asciiartfarts.com
this post | permalink
@ancientjames Michael Knight used this during his FLAG debriefings
this post | permalink
@ulldma or you could pipe fortune or cowsay? :)
this post | permalink
[RSS] EvilVM: Forth shellcode (2019)

https://web.archive.org/web/20250418124519/http://evilvm.ninja/
this post | permalink
[RSS] ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE

https://www.elttam.com/blog/att-cking-tacacs-to-pwn-your-network-via-a-pre-auth-rce
this post | permalink
My panic!() messages start to degrade to the quality of my commit messages
this post | permalink
@dymaxion @kaoudis You are right, and now I think here lies the solution: with pentests you want priorities based on how an external party sees your system. Does this make sense?

(having to think about these things shows how much time passed since I started doing pentesting...)
this post | permalink
@dymaxion @kaoudis I guess back in the day this was about workforce distribution? People with pentest skills usually didn't work at places that required them + project distribution didn't justify hiring? There is also a conflict of interest if a person with pentest skills also works on the system under test.
this post | permalink
[RSS] CVE-2026-78902: XSS to RCE in pfSense with one DNS request

https://www.netspi.com/blog/technical-blog/web-application-pentesting/cve-2026-78902-xss-to-rce-in-pfsense-with-one-dns-request/
this post | permalink
[RSS] How One Twitch Chat Message Became Code Execution on a Streamer's PC

https://blog.scrt.ch/2026/09/22/how-one-twitch-chat-message-became-code-execution-on-a-streamers-pc/
this post | permalink
Next Page