infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] PostgreSQL: Privilege Escalation Vulnerability via pg_cron

https://github.com/google/security-research/security/advisories/GHSA-j8p5-79jf-g575
this post | permalink
I got badly nerd sniped by Qualys:

Dreams in #CodeQL - Quest for the Perfect GOTO

https://scrapco.de/blog/dreams-in-codeql-quest-for-the-perfect-goto.html
this post | permalink
@TarkabarkaHolgy A related classic: https://www.youtube.com/watch?v=sBffNiUOeiA
this post | permalink
@revng Did you get your approval? I can't seem to find the channel, could you please post the link?
this post | permalink
God how I hate CSS
this post | permalink
[RSS] Sitecore: Unsafe Deserialisation Again! (CVE-2025-27218)

https://slcyber.io/blog/sitecore-unsafe-deserialization-again-cve-2025-27218/
this post | permalink
@TarkabarkaHolgy I don't think this is gender-specific. My understanding is that vendors were not properly educated about units of measurement and write numbers on cloths to comply with regulations, but still use the limb sizes of anyone who happens to work on a piece to actually measure stuff.
this post | permalink
@singe I also wonder - considering the lack of information about the target system and its non-deterministic nature - at what point turns "engineering" into "messing around based on gut feeling"
this post | permalink
[RSS] New Method to Leverage Unsafe Reflection and Deserialisation to RCE on Rails

https://www.elttam.com/blog/rails-sqlite-gadget-rce/
this post | permalink
[RSS] Case Study: Traditional CVSS scoring missed this actively exploited vulnerability (CVE-2024-50302)

https://old.reddit.com/r/netsec/comments/1j3tvof/case_study_traditional_cvss_scoring_missed_this/
this post | permalink
Next Page