infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

Here's the tool I use to keep up with security research on Twitter:

https://github.com/v-p-b/nitter-rss-proxy

It relies on Nitter, which is about to die AFAICT, but the script is still working fine, use it while you can!
this post | permalink
@0xamit I use this script to keep up with the accounts that didn't make the move: https://github.com/v-p-b/nitter-rss-proxy
this post | permalink
[Yarden Shafir @ X] appid.sys receives 2 function pointers from a user and blindly calls them. 0 validations are done. The most interesting part of this bug to me is that this very trivial bug isn't an ancient one that hasn't been discovered for decades -- it was introduced in Windows 10.

https://twitter.com/yarden_shafir/status/1763248032043147288
this post | permalink
[Alex Plaskett @ X] RT by @alexjplaskett: #Lazarus exploited a flaw in the Windows AppLocker driver (appid.sys) as a zero-day to gain kernel-level access and turn off security tools.

https://decoded.avast.io/janvojtesek/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day/

This is CVE-2024-21338
this post | permalink
[RSS] BGE Attack on AES White-Boxes: Extending Blue Galaxy Energy for Decryption and Shuffled States

http://blog.quarkslab.com/bge-attack-on-aes-white-boxes-extending-blue-galaxy-energy-for-decryption-and-shuffled-states.html
this post | permalink
Is it me or Firefox Focus cares so much about my mental health that the keyboard just won't come up when the address bar is active?
this post | permalink
"China’s largest #antivirus firm, Qihoo360, is an investor of offensive capabilities firms and may be selling PII of individual antivirus customers to an offensive company it funds that does intelligence work for government clients."

https://margin.re/2024/02/same-same-but-different/
this post | permalink
[RSS] SMM isolation - SMI deprivileging (ISRD)

https://tandasat.github.io/blog/2024/02/29/ISRD.html

%27This two-post series details the inner workings of System Management Mode (SMM) isolation on the Intel platform and interaction with Windows."
this post | permalink
If Metasploit is where 0-days go to die, then having Metasploit as a dependency for your project is like botulism?
this post | permalink
@tmr232 Choosing non-standard colors for chat bubbles (at least Signal supports this) helped me with this.
this post | permalink
Next Page