infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

The good news is:

It comes in pints!
this post | permalink
I decided to fix this really easy looking UI issue in the Carthographer #Ghidra ext, and now I'm at 1 open Issue and total confusion about how did this thing ever work with the sample that triggered me in the first place o.O

https://github.com/datalocaltmp/RECON-2024

#reconmtl #recon2024 #recon24
this post | permalink
[RSS] Nuvoton / Dell iDRAC: RootBlock

https://github.com/google/security-research/security/advisories/GHSA-v9gx-jrwm-3f78

"An attacker with physical access or root-level access on a system that uses the Nuvoton BootBlock first-stage bootloader can modify the u-boot image parsed by BootBlock such that it overwrites BootBlock in SRAM"
this post | permalink
[RSS] Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806)

https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/
this post | permalink
[RSS] Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties

https://github.blog/2024-06-26-attack-of-the-clones-getting-rce-in-chromes-renderer-with-duplicate-object-properties/
this post | permalink
[RSS] Exploiting Steam: Usual and Unusual Ways in the CEF Framework

https://www.darknavy.org/blog/exploiting_steam_usual_and_unusual_ways_in_the_cef_framework/
this post | permalink
[RSS] An unexpected journey into Microsoft Defender's signature World

https://retooling.io/blog/an-unexpected-journey-into-microsoft-defenders-signature-world
this post | permalink
PgC: Garbage collecting Patchguard away

http://blog.can.ac/2024/06/28/pgc-garbage-collecting-patchguard/?s=09
this post | permalink
Endpoint Security or End of Security?

https://github.com/TrapaSecurity/Presentations/blob/master/Endpoint_Security_or_End_of_Security.pdf
this post | permalink
Just arrived to #REcon24, come say hi! (Hint: I wear two watches :))
this post | permalink
Next Page