infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@screaminggoat @ntkramer Yeah the payload definitely doesn't match.
this post | permalink
@screaminggoat @ntkramer Sooo, deserialization, IIS... have they left their ViewState key exposed? /speculation
this post | permalink
@munin Their mother was a hamster and their father smelt of elderberries!
this post | permalink
@mttaggart @GossiTheDog Some recurring themes in these repos are 1) abandonware 2) test/training code

Also, TIL you can use boolean expressions, e.g. you can filter for autogenerated keys:

https://github.com/search?q=%3CmachineKey+validationkey+path%3Aweb.config+NOT+autogenerate&type=code
this post | permalink
@GossiTheDog Yeah, edits are weird around here, thanks for the clarification! I can only see npm being used for frontend stuff in .NET projects, could you perhaps link an affected repo/npm page?
this post | permalink
@GossiTheDog Thanks! Now I'm more confused: npm does .NET these days? Or we're talking NuGet?
this post | permalink
[RSS] Micropatches Released for Windows OLE Remote Code Execution (CVE-2025-21298)

https://blog.0patch.com/2025/02/micropatches-released-for-windows-ole.html
this post | permalink
@screaminggoat @zeljkazorz @GossiTheDog "However, due to inadequate server configurations, attacks become possible if *the serialized data is not verified* (CWE-642)" - this sounds more like disabled MAC than leaked key to me
this post | permalink
@GossiTheDog Forgive my ignorance, what is nom?
this post | permalink
@cynicalsecurity @jeroen "I don't understand what exactly happened last night on LinkedIn, but I know it is dark and sad and reeks of unfulfilled wants. The executive sat before me has been marketed to."

https://ludic.mataroa.blog/blog/brainwash-an-executive-today/
this post | permalink
Next Page