infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] Leveraging An Order of Operations Bug to Achieve RCE in Sitecore 8.x - 10.x

https://www.assetnote.io/resources/research/leveraging-an-order-of-operations-bug-to-achieve-rce-in-sitecore-8-x---10-x
this post | permalink
Extremely vulnerable blinky boxes are viable business because shit like this:

If you want debug logs from Squid you are expected to supply *pairs of numbers* in the config for debug section and level. The manual says:

"We take great pains to keep debug sections consistent across releases." -> meaning they aren't...

https://wiki.squid-cache.org/KnowledgeBase/DebugSections

#FOSS
this post | permalink
Yeah this should be totally obvious... /s

https://discuss.kotlinlang.org/t/kotlin-sublass-constructors-do-not-inherit-default-parameter-values/27936

#kotlin
this post | permalink
@rtfmkiesel finally some old infosec twitter vibes <3
this post | permalink
@bean See also: https://www.nccgroup.com/us/research-blog/shell-arithmetic-expansion-and-evaluation-abuse/
this post | permalink
@weddige @catsalad A much more fun way to test this is at the local playground with a toy truck
this post | permalink
[RSS] Finding Bugs in Chrome with CodeQL

https://bughunters.google.com/blog/5085111480877056/finding-bugs-in-chrome-with-codeql
this post | permalink
@ryanc See also Hannibal Lecter: https://video.infosec.exchange/w/7oDpz9V3mDnrLziH82Copv :)
this post | permalink
@joxean This looks like a good opportunity to convince mgmt to change their minds
this post | permalink
Attackers are hijacking Jupyter notebooks to host illegal Champions League streams

https://cyberscoop.com/misconfigured-jupyter-notebooks-uefa-champions-league-streaming/
this post | permalink
Next Page