infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] What Are My OPTIONS? CyberPanel v2.3.6 pre-auth RCE

https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce
this post | permalink
[RSS] We Patched CVE-2024-38030, Found Another Windows Themes Spoofing Vulnerability (0day)

https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html
this post | permalink
@http https://infosec.place/notice/AnT3F4ZJnv3E2JfKng
this post | permalink
@infosecdj @RGB_Lights @dcoderlt Nobody says it's OK to abuse. I'm saying it's best to prevent abuse and that it's not OK to let the abuse to continue for years.
this post | permalink
@schrotthaufen @RGB_Lights That's not a reason for us to make (and reinforce) the same confusion.
this post | permalink
@schrotthaufen @RGB_Lights Cookie banners are not paywalls, let's not confuse the two issues...
this post | permalink
@dcoderlt @RGB_Lights This has been going on for years even before the UA war (a bit higher prio in all areas), and this is part of the reason why I can't accept the abuse argument: if this is abuse, why has nobody done anything about it?
this post | permalink
@RGB_Lights Proponents say that cookie banners are deliberate abuse of the regulation (to condition users to accept whatever, I think?). IMO if the regulation allows abuse of this extent it is not a good regulation.
this post | permalink
[RSS] Privilege escalation through TPM Sniffing when BitLocker PIN is enabled

https://blog.scrt.ch/2024/10/28/privilege-escalation-through-tpm-sniffing-when-bitlocker-pin-is-enabled/
this post | permalink
[RSS] Certificate Error Mishandling: Misuse and Abuse of the SslErrorHandler Class

https://bughunters.google.com/blog/4934724060839936/certificate-error-mishandling-misuse-and-abuse-of-the-sslerrorhandler-class
this post | permalink
Next Page