infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@sassdawe well, it's Discord, so I don't think Defender is wrong...
this post | permalink
Time-travel Testing of Android Apps

https://mboehme.github.io/paper/ICSE20.TTT.pdf
this post | permalink
Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap – BlackHat USA 2024 Whitepaper [PDF]

https://www.nccgroup.com/media/uzbp3ttw/bhus24_sonos_whitepaper.pdf
this post | permalink
@G33KatWork https://tenor.com/6Zuq.gif
this post | permalink
@joxean Final Cut is a movie made entirely cut from other movie classics, they can only distribute it as educational material
this post | permalink

Tech Analysis: CrowdStrike’s Kernel Access and Security Architecture

https://www.crowdstrike.com/blog/tech-analysis-kernel-access-security-architecture/

Interesting explainer about the architectural design decisions of #CrowdStrike, focusing mainly on the reasons for moving code to the kernel.

I find it curious that they talk about “User-Mode-Only Security Products” in the context of tamper protection: AV’s tend to have kernel components and if my observations at the time were correct they provided protection for user processes even before PPL. I’m not Ionescu enough to know if such protections would work with KPP&co though…

this post | permalink
@qwertyoruiop too much hacking...
this post | permalink
"an amazing 325 page google strategy document quietly unsealed buried in google antitrust docket. It's gonna take a long thread but I have pulled out the gems. It's from 2017 planning, no doubt Google will just say these were only ideas but many will look very familiar." #adtech

https://threadreaderapp.com/thread/1821554841786683554.html
this post | permalink
A deep dive into CVE-2023-2163: How we found and fixed an eBPF Linux Kernel Vulnerability

https://bughunters.google.com/blog/6303226026131456/a-deep-dive-into-cve-2023-2163-how-we-found-and-fixed-an-ebpf-linux-kernel-vulnerability
this post | permalink
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!

https://blog.orange.tw/2024/08/confusion-attacks-en.html?m=1&s=09

Latest by Orange Tsai!
this post | permalink
Next Page