infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] It rather involved being on the other side of this airtight hatchway: Disabling anti-malware scanning

https://devblogs.microsoft.com/oldnewthing/20241210-00/?p=110626
this post | permalink
[RSS] The Ruby on Rails _json Juggling Attack

https://nastystereo.com/security/rails-_json-juggling-attack.html
this post | permalink
[RSS] Binary pointer alias analysis -- beating CodeQL's taint analysis without even having source code

https://attilaszia.github.io/pointerarticle/
this post | permalink
@wdormann ahh sry didn't spot that from mobile, just got the bookmark
this post | permalink
@wdormann maybe https://ssd-disclosure.com/ssd-advisory-common-log-file-system-clfs-driver-pe/ ? Vendor response is weird, but have to check affected systems in the advisory...
this post | permalink
[RSS] Attacking Cortex XDR from an unprivileged user perspective

https://blog.scrt.ch/2024/12/05/attacking-cortex-xdr-from-an-unprivileged-user-perspective/

Privileged file access by endpoint security strikes again ;)
this post | permalink
@april best: org specific tweaks on existing stuff
Worst: buy and forget
this post | permalink
@sjolsen try @kagihq
this post | permalink
[RSS] KVM: Out-Of-Bounds Read in nested_svm_get_tpd_pdptr

https://github.com/google/security-research/security/advisories/GHSA-h65x-r3mq-jr2v
this post | permalink
[RSS] Mitigating NTLM Relay Attacks by Default

https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/
this post | permalink
Next Page