infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@da_667 context? o.O
this post | permalink
Multiple Eclipse ThreadX NetX Duo HTTP server vulnerabilities by Talos:

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2104
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2105
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2098

CVE-2025-0728, CVE-2025-2258, CVE-2025-0727, CVE-2025-2259, CVE-2025-0726, CVE-2025-2260

/via @talosvulns
this post | permalink
[Full-Disclosure] [CVE-2025-32102, CVE-2025-32103] SSRF and Directory Traversal in CrushFTP 10.7.1 and 11.1.0 (as well as legacy 9.x)

https://seclists.org/fulldisclosure/2025/Apr/17
this post | permalink

Why 40,000 People Die for Every 1% Increase in Unemployment - The Big Short

https://www.youtube.com/watch?v=_XgU6ZT1QDk

this post | permalink
@codecolorist broken link :(
this post | permalink
@csepp If you say so :) it was just strange to find this code in that repo.
this post | permalink

DECORE posted some ADCS magic but I couldn’t yet figure out how to switch language o.O

https://devco.re/blog/2025/04/10/taking-over-the-entire-domain-in-minutes-what-have-you-overlooked-in-active-directory/

Edit: This doesn’t seem like anything Earth-shattering, but a nice summary of state of ADCS security (spoiler: it is bad)

this post | permalink

TIL PHP OpCache has a Lua interpreter embedded o.O

https://github.com/php/php-src/blob/master/ext/opcache/jit/ir/dynasm/minilua.c

this post | permalink
@cR0w Sure, but serious users tend to configure custom error pages with funny mascots etc.
this post | permalink
@cR0w As it is a framework fingerprinting is tricky. I def know about some larger services that use it.
this post | permalink
Next Page