infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@GossiTheDog @reverseics @cR0w But could *non-admin* users access the DB of *other* users? SQLite or not, this should not be possible (in general...). If it was possible back then (as it was suggested by you and articles based on your comments), then now would be the best time for all to see what the problem was to check if the same or similar problem is present in the implementation that is to be released.
this post | permalink
@GossiTheDog @reverseics @cR0w Great you chime in! Any plans to release that x-user Recall exploit you talked about?

https://infosec.place/notice/AieinAN5CpyKNShdvE
this post | permalink
@cR0w @reverseics My theory is that a) URL's are the new filesystems and b) abstracting away control ("..") from data ("etc") would have an unacceptable overhead compared to SQL (ORMs) or even HTML (DOM sanitizers), so the memes are here to stay :)
this post | permalink
#directoryTraversalMemes seem to become a classic, but I wonder if anyone has a list of specific payloads that trigger the different vulnerabilities of recent memory?

/cc @reverseics @cR0w
this post | permalink
@sassdawe Not in this one...
this post | permalink
I published my analysis of the Series 9000 Brainalyzer exploit by Rick Sanchez:

https://video.infosec.exchange/w/jtR1V9N5ghHES5oayeBrrd

#NoCVE
this post | permalink
@sassdawe I hope(?) they are just clueless, already wrote them a mail :P
this post | permalink
If you support any independent news organization you may want to consider if they also accept money from companies that launder money for war criminals while also ruining the atmosphere:

https://blog.mollywhite.net/binance-script/
this post | permalink
Why the Soviet Computer Failed

https://www.youtube.com/watch?v=dnHdqPBrtH8

Again, it's all about incentives...
this post | permalink
@Proteas Note that in case of dogs numbers can be much higher.
this post | permalink
Next Page