infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] An SSRF to LFI Payload for PDF Generators (CVE-2024-34112 and beyond)

https://www.hoyahaxa.com/2025/01/an-ssrf-to-lfi-payload-for-pdf.html
this post | permalink
"Even if I wanted to improve the app, I really didn't understand how to achieve the increasingly difficult goal I was aiming for. So, rather than writing an automation script that helped me skip over /the hard details/ I focused on learning the science I was trying to ignore."

https://seclists.org/dailydave/2025/q1/3

#fuzzing #llm
this post | permalink
@adamshostack Or you are very strong
this post | permalink
@cfgbot looks like a well behaving function, classmates must hate him
this post | permalink
[RSS] Why does inadvertently passing a std::string instead of a char const* to a variadic function crash on x86-32 but not x86-64?

https://devblogs.microsoft.com/oldnewthing/20250110-00/?p=110744
this post | permalink
"There were changes made to file name rules in Windows 11 24H2 that have caused IFS access problems for customers" #IBMi

https://www.ibm.com/support/pages/node/7180720?myns=swgother&mynp=OCSWG60&mync=A&cm_sp=swgother-_-OCSWG60-_-A

I wonder if this has to do with DEVCORE's Worst Fit vulnerabilities: https://devco.re/blog/2025/01/09/worstfit-unveiling-hidden-transformers-in-windows-ansi/
this post | permalink
[RSS] Windows 11 24H2 update causes issues connecting to IBM i

https://www.ibm.com/support/pages/node/7180720?myns=swgother&mynp=OCSWG60&mync=A&cm_sp=swgother-_-OCSWG60-_-A

"IBM ACS Application Package *WINLOGON support [...] is incompatible with LSA Protection." what the Hell is ACS doing in my LSASS?! #IBMi
this post | permalink
[RSS] Static Keys, Shattered Security Dreams: A CVE-2024-5764 Story

https://medium.com/maverislabs/static-keys-shattered-security-dreams-a-cve-2024-5764-story-c76ee594adc2?source

(Sonatype Nexus Repository 3 exploitation walkthrough)
this post | permalink
@Tesseks I guess you can get pretty precise model data from EXIF metadata too?
this post | permalink
@krypt3ia But talking about analog, I take the opportunity to share my favorite photo blog that aimed to find a completely black accidental analog photo and collected a bunch of gems along the way (also found a winner, see the latest pic):

https://bestofsemmi.blog.hu/ (Best of Nothing)
this post | permalink
Next Page