infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

Glad to report that binaryninja-docker still works with Binary Ninja 5.x in case you are on older glibc (or other dependency):

https://github.com/v-p-b/binaryninja-docker
this post | permalink
@singe I get it, just another data point
this post | permalink
This weeks statistics:
- Random shitpost: 25 repeats, 61 favs
- Original technical content: 3 repeats, 3 favs

#social
this post | permalink
Why the UK's IBM Failed by Asianometry

https://www.youtube.com/watch?v=EkTHDgYTh64
this post | permalink
[RSS] Fixing Decompilation of Stack Clash Protected Binaries

https://intrigus.org/research/2025/04/15/fixing-decompilation-of-stack-clash-protected-binaries/

#Ghidra #BinaryNinja #ReverseEngineering
this post | permalink
[RSS] Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages

https://googleprojectzero.blogspot.com/2025/05/breaking-sound-barrier-part-i-fuzzing.html
this post | permalink
@wdormann @GossiTheDog @deepthoughts10 Tamper Protection usually implements anti-debugging so you won't be able to attach a debugger even to the low-priv UI process of the AV. This is not normally a security boundary so there are of course bypasses, what you just showed basically goes back to having a UAC bypass + admin account.
this post | permalink
@vulnbot @cR0w this is fake or at least incomplete
this post | permalink
To join the recent series of great Windows Defender content (defendnot, EvilentCoerce) I published a status report on mpclient development:

Fuzzing Windows Defender with loadlibrary in 2025

https://scrapco.de/blog/fuzzing-windows-defender-with-loadlibrary-in-2025.html

#Fuzzing #ReverseEngineering #Antivirus
this post | permalink
@jpmens @bagder Well, if your backups can be restored using a web API, curl can actually help!
this post | permalink
Next Page