infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] A particularly 'sus' sysctl in the XNU Kernel

https://jprx.io/cve-2024-54507/

CVE-2024-54507
this post | permalink
@PavelASamsonov I had to pick up kid at the swimming pool. Went to their website, because I only got the name of the place. Their address is not there.
this post | permalink
TIL @tubetime has live streams on Twitch!
https://m.twitch.tv/tubetimeus
this post | permalink
[RSS] CVE-2024-26230: Windows Telephony Service - It's Got Some Call-ing Issues (Elevation of Privilege)

https://starlabs.sg/blog/2025/cve-2024-26230-windows-telephony-service-its-got-some-call-ing-issues/
this post | permalink
@wolf480pl As a first step I'd have filters for low-risk vuln classes for client and server side. E.g. I see a large chunk of effort being spent on theoretical XSS scenarios that will likely never be exploited:

https://github.com/v-p-b/xss-reflections
this post | permalink
@bagder This somehow made the situation seem even worse?
this post | permalink
This is new: CISA KEV adds an XSS vulnerability!

https://www.cisa.gov/news-events/alerts/2025/01/23/cisa-adds-one-known-exploited-vulnerability-catalog

The KEV page quotes (emphasis mine): "JQuery contains a *persistent* cross-site scripting (XSS) vulnerability" so this still doesn't seem to meet the bar for my XSS Reflections list:

https://github.com/v-p-b/xss-reflections

If anybody has more info about the related incident please lmk!
this post | permalink
[RSS] Memory corruption from outside the process looks like space aliens

https://devblogs.microsoft.com/oldnewthing/20250123-00/?p=110800

Full system instrumentation ftw :)
this post | permalink
@sneak https://alfg.dev/ffmpeg-commander/ ?
this post | permalink
Nvm, I'm outta here until the daily rage minutes end...
this post | permalink
Next Page