infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] A 64-bit x86 Bootloader from Scratch

https://hackaday.com/2024/07/14/a-64-bit-x86-bootloader-from-scratch/
this post | permalink
[RSS] [Internet Bug Bounty] high - important: Apache HTTP Server on WIndows UNC SSRF (CVE-2024-38472) (4920.00USD)

https://hackerone.com/reports/2585385
this post | permalink
[RSS] [Internet Bug Bounty] high - important: Apache HTTP Server weakness with encoded question marks in backreferences (CVE-2024-38474) (4920.00USD)

https://hackerone.com/reports/2585381

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
this post | permalink
[RSS] Resurrecting a dead Dune RTS game

https://wheybags.com/blog/emperor.html
this post | permalink
I almost felt guilty finding out the guy accidentally gave me two of these "original palestinian" scarves instead of one
this post | permalink
@wdormann mark my words: we will see proper LPEs based on this

https://infosec.place/notice/AjUKJkZXdnrozbuXAW
this post | permalink
[RSS] Announcing AES-GEM (AES with Galois Extended Mode)

https://blog.trailofbits.com/2024/07/12/announcing-aes-gem-aes-with-galois-extended-mode/
this post | permalink
[RSS] MongoDB NoSQL Injection with Aggregation Pipelines

https://soroush.me/blog/2024/06/mongodb-nosql-injection-with-aggregation-pipelines/
this post | permalink
[RSS] SSD Advisory – SonicWall SMA100 Stored XSS to RCE

https://ssd-disclosure.com/ssd-advisory-sonicwall-sma100-stored-xss-to-rce/
this post | permalink
@freddy IME calendar protocols are multiple dumpster fires, so they probably want to reduce customer frustration by allowing only implementations with known quirks.
this post | permalink
Next Page