infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@bontchev @adamshostack My favorite example: programmers are taught to use prepared statements, so at first it seems their app doesn't have any SQLi's. Until they add a feature where the user controls result set ordering: you can't use bound variables for field names, so there's a vuln 90% of the time (IME, with wildly different dev teams).
this post | permalink
@pancake That's terrible and unfortunately far from unique. Sorry for your mom :(
this post | permalink
Fuck cancer (and bureaucrats) :(

https://bontchev.nlcv.bas.bg/bye.html

Get yourself checked!
this post | permalink
@LukaszOlejnik they are already using it in Hungary (elections next April), I can collect some articles if interested. But I think you are overestimating the sophistication: we just see the dumbest made up lies, not any form of political argument.
this post | permalink
@stf red team approves!
this post | permalink
@Leander This sparks joy.
this post | permalink
Some weekend updates to my homepage:

Added a little guide to debug recursive #CodeQL predicates:

https://scrapco.de/codeql-cheat-sheet/debugging/debugging-recursion/

#Ghidra documentation now reflects the state of 11.4.3:

https://scrapco.de/ghidra_docs/
this post | permalink
I updated my MC-NBFX serializer (of WCF's NetTcpBinding fame) for comatibility with the latest @kaitai release:

https://github.com/v-p-b/nbfx/commit/bb588dec57e0dfee6db389de70235d9693ea6d6a

It turned out that the release introduced mandatory consistency `_check()`s for serialization (see Release Notes) that force you to take additional hurdles during development, but unit tests paid dividends as I emphasized in the announcement post:

https://blog.silentsignal.eu/2024/10/28/wcf-net.tcp-pentest/

#pentest #UnitTesting
this post | permalink
I'm looking for a graphics person to turn a portrait into a single color vector image (and possibly a few other tweaks) for later open publication.

DM me if you are interested!

#FediHire #Inkscape #Illustrator #Graphics
this post | permalink
[RSS] Another AI slop story: ChatGPT vs. Human

https://joshua.hu/ai-slop-story-nginx-leaking-dns-chatgpt

This is actually a description of a neat infoleak involving Nginx DNS caching, blue team over-reliance on LLMs is bonus.
this post | permalink
Next Page