infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@pmorinerie Strongly related article:

Language Is a Poor Heuristic for Intelligence

https://buttondown.email/ninelives/archive/language-is-a-poor-heuristic-for-intelligence/
this post | permalink
You put Epilepsy Warning to your videos to avoid lawsuits
I put them to attract my target audience
We are not the same

https://www.youtube.com/watch?v=9rXNUnFuyfU
this post | permalink
@swapgs On an unrelated note we have to admire that #LangSec ppl apparently chose .txt as the presentation format just to be on the safe side! :D
this post | permalink
@swapgs Yeah that CVE *is* referenced in joernchen's post, but the issue shown on the photo doesn't reference a CVE or a GitLab release, so it's hard to map. I also think the quoted part is just wrong, as the photo also shows an excerpt about Devfile and Ruby...
this post | permalink

#LangSec Bugs of the Year Awards results are in (still from X :P)!

“The Most Impactful Parser Bug Of The Year Award is given to the WebP 0day” - awarded to @benhawkes

“The hardest to fix parser bug goes to the http://Binarly.io team for the LogoFAIL bugs.”

“The Best Parser Differential Awards goes to the inconsistent interpretation of YAML foods between Go and Rust.” - There is a link on the captured slide, and I’m pretty sure it’s @joern ‘s bug, but I can’t find a proper CVE anywhere…seriously people, references!

“The Weirdest Machine Award goes to Ian Beer @i41nbeer @benhawkes and @saelo@chaos.social”

Full thread with runner ups:

https://x.com/jvanegue/status/1793801911650676915

this post | permalink
Glider plug?? o.O
this post | permalink
[RSS] Fuzzing the FreeBSD Kernel with Syzkaller and Nested Virtualization on a Linux Host

https://secfault-security.com/blog.htmlblog/fuzzing_freebsd.html
this post | permalink
[RSS] Samsung WB850F Firmware Reverse-Engineering

https://op-co.de/blog/posts/samsung_wb850f_firmware/
this post | permalink

@cryptax @j2inet This is the VT result of Tiny PE, which literally does nothing:

https://www.virustotal.com/gui/file/f5943702ab658ce3b2231392de04a832f21d32c89b6dcfa0bd6e6e8e6a1ffe10

this post | permalink
@bontchev author is doing God's work here, these is incredibly useful to run test environments (unrelated to security)
this post | permalink
Next Page