infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@azonenberg video.infosec.exchange?
this post | permalink
[RSS] Dubious security vulnerability: Program allows its output to be exfiltrated

https://devblogs.microsoft.com/oldnewthing/20240416-00/?p=109668

Kids these days really should learn about threat modeling...
this post | permalink
[RSS] “All Your Secrets Are Belong To Us” — A Delinea Secret Server AuthN/AuthZ Bypass

https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3
this post | permalink
@zhuowei /cc @TarkabarkaHolgy
this post | permalink
[RSS] Dangerous Import: SourceForge Patches Critical Code Vulnerability

https://www.sonarsource.com/blog/dangerous-import-sourceforge-patches-critical-code-vulnerability
this post | permalink
@gsuberland Same Thing But Different
this post | permalink
@cR0w @reverseics Unrelated to the current vuln but this just got stuck in my head
this post | permalink
[RSS] CVE-2024-2448: Authenticated Command Injection In Progress Kemp LoadMaster

https://rhinosecuritylabs.com/research/cve-2024-2448-kemp-loadmaster/
this post | permalink
[RSS] Exploiting American Conquest

https://www.synacktiv.com/en/publications/exploiting-american-conquest

by Synacktiv
this post | permalink
[RSS] Telegram Arbitrary Code Execution via InstantView | TeleSec

https://www.telesec.top/telesec/telegram-desktop/arbitrary-code-execution-via-instantview
this post | permalink
Next Page