infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

CVE-2024-9956 - PassKey Account Takeover in All Mobile Browsers

https://mastersplinter.work/research/passkey/
this post | permalink
[RSS] SAML roulette: the hacker always wins

https://portswigger.net/research/saml-roulette-the-hacker-always-wins

GitLab CVE-2025-25291 + CVE-2025-25292
this post | permalink
Dropkick Murphys kicks ass as always:

https://www.youtube.com/watch?v=Tl4ggwyWEMI

#uspol #punk
this post | permalink
@cbleslie Congratulations!
this post | permalink
shellify allows generating shell.nix from ad-hoc #Nix environments:

https://github.com/danielrolls/shellify

Why isn't this a core feature??
this post | permalink
@cR0w No, I mean the other way around: someone created a shit-ass frontend for the OpenAI API and very cleverly branded it as "chatgpt".
this post | permalink
@cR0w Also, I don't think it's OpenAI's code...
this post | permalink
@cR0w This is even a plain SSRF, but a local file read (where PHP is also kind enough to resolve remote URL's)!
this post | permalink
C++ macro for x64 programs that breaks ida hex-rays decompiler tool.

https://github.com/android1337/brkida

"This project exploits the fact that IDA decompiler fails when it encounters a stack access on a pointer that's too big."

#IDA #IDAPro #HexRays
this post | permalink
@infosecdj no idea, but I'm sure it's documented by cf somewhere...
this post | permalink
Next Page