infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] Achieving Persistent Client-Side Attacks with a Single WeChat Message

https://www.darknavy.org/blog/achieving_persistent_client_side_attacks_with_a_single_wechat_message/
this post | permalink
[oss-security] CVE-2025-48734: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default

https://www.openwall.com/lists/oss-security/2025/05/28/6

I wonder if the now restricted behavior is useful for #deserialization gadgets (I couldn't find references to declaredClass abuse, but haven't finished my coffee yet either...)?
this post | permalink
[oss-security]

CVE-2025-46701: Apache Tomcat: Security constraint bypass for CGI scripts

https://www.openwall.com/lists/oss-security/2025/05/29/4

I think "GCI" is a typo in the message (CGIServlet.java is patched), although found the same typo elsewhere in the documentation...
this post | permalink
@keenancrane I wanted to mention those piggies, glad this design was not lost in time (had think really hard where I saw a similar concept, and it was about 25 years ago) :)
this post | permalink
@mttaggart Also, write-only syntax choices that e.g. require counting different kinds of brackets with your fingers...
this post | permalink
[RSS] Cisco IOS XE WLC Arbitrary File Upload Vulnerability (CVE-2025-20188) Analysis

https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/
this post | permalink
[RSS] exploits.club Weekly Newsletter 73 - AI Finds Bugs, MTE Bypasses, Old Jailbreaks, and More

https://blog.exploits.club/exploits-club-weekly-newsletter-73-ai-finds-bugs-mte-bypasses-old-jailbreaks-and-more/
this post | permalink
"[Qualys] discovered a vulnerability in apport [...], and a similar vulnerability in systemd-coredump [...]: a race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump"

https://www.openwall.com/lists/oss-security/2025/05/29/3

CVE-2025-5054 CVE-2025-4598
this post | permalink
@mcc mathcore/math rock? E.g.: https://www.youtube.com/watch?v=D4-erceTpc8

Edit: or simply Tool...
this post | permalink
[RSS] Micropatches Released for Preauth DoS on Windows Deployment Service (CVE-2025-29957)

https://blog.0patch.com/2025/05/micropatches-released-for-preauth-dos.html
this post | permalink
Next Page