infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] Digging Through Six Old Sandbox Escapes in ColdFusion (ca. 2001 through 2012)

https://www.hoyahaxa.com/2025/12/digging-through-six-old-sandbox-escapes.html
this post | permalink
[RSS] [Joshuas] 2025 Bug Bounty Stories

https://joshua.hu/2025-bug-bounty-stories-fail
this post | permalink
@Viss @schrotthaufen We experienced that a lot but I always thought about it as a desperate attempt to signal competence (pbbly as a result of BS phishing simulations) rather distrust. But yeah, that's also a reasonable way to look at it.
this post | permalink
[RSS] All the other cool languages have try...finally. C++ says "We have try...finally at home."

https://devblogs.microsoft.com/oldnewthing/20251222-00/?p=111890
this post | permalink
@quarkslab Thanks for the confirmation!

@cR0w
this post | permalink
@cR0w This one by @quarkslab may cover the details, although the CVE is not mentioned: https://blog.quarkslab.com/k7-antivirus-named-pipe-abuse-registry-manipulation-and-privilege-escalation.html
this post | permalink
[RSS] From UART to Root: Breaking Into the Xiaomi C200 via U-Boot

https://github.com/h3xDum/Xiaomi-C200-Firmware-Analysis
this post | permalink
@swapgs Maybe LLM assisted? The vuln is pretty funny and IMO the "philosophical" question it discusses is valid.
this post | permalink
CVE-2025-29970 Microsoft Brokering File System Elevation of Privilege Vulnerability writeup

https://www.pixiepointsecurity.com/blog/nday-cve-2025-29970/
this post | permalink
[RSS] When OAuth Becomes a Weapon: Lessons from CVE-2025-6514

https://amlalabs.com/blog/oauth-cve-2025-6514/
this post | permalink
Next Page