infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

[RSS] Linux >=5.6: cred refcount overflow at ~39 GiB memory usage via io_uring

https://bugs.chromium.org/p/project-zero/issues/detail?id=2506
this post | permalink
[SkelSec @ X] RT by @SkelSec: New blog post! 📰 Decompiling Hyper-V Manager to rebuild it from source 🔨 Help me convince Microsoft to save Hyper-V Manager by open sourcing it! Until then, here's how to patch it locally from decompiled code!

https://awakecoding.com/posts/decompiling-hyper-v-manager-to-rebuild-it-from-source/
this post | permalink
Is it possible in the browsers of 2024 to execute JavaScript from CSS?
this post | permalink
[RSS] The Second Wednesday Of The First Month Of Every Quarter: Juniper 0day Revisited

Despite these vulnerabilities being serious enough to require confidentiality during this extended period, Juniper didn’t view them as serious enough to warrant an out-of-cycle advisory or to consistently register CVE numbers (or even to mention them in the patch notes).

https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/
this post | permalink
[b1ack0wl @ X] RT by @b1ack0wl: I'm excited to announce that the technical analysis and the exploit of my CVE-2023-6546 (ZDI-24-020) Linux Kernel GSM Multiplexing Race Condition LPE is now available

https://github.com/Nassim-Asrir/ZDI-24-020/
this post | permalink
[DebugPrivilege @ X] RT by @DebugPrivilege: New LaurieWired Rant!

We discuss why security researchers need to understand software engineering, and how your skills would improve with development experience.

https://youtube.com/watch?v=bJk_NThPbyE
this post | permalink
[RSS] Breaking Videogames - Hunt for Serializers

https://banyaszvonat.github.io/breaking-videogames/2024/01/18/hunt-for-serializers.html
this post | permalink
@hn_discussions I hope it will end like this:

https://www.youtube.com/watch?v=TYsulVXpgYg
this post | permalink
this post | permalink
[Yarden Shafir @ X] RT by @yarden_shafir: Write up of the HVCI bypass vuln (CVE-2024-21305) with @aaall86

https://tandasat.github.io/blog/2024/01/15/CVE-2024-21305.html
this post | permalink
Next Page