infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@simontsui @floyd Tell me about it :)

https://blog.silentsignal.eu/wp-content/uploads/2018/01/S2_BareKnuckledAVBreaking_180108.pdf

https://github.com/v-p-b/avpwn/blob/master/README.md
this post | permalink
Historically, hackers have been progressive and encouraged policies like BYOC (Bring Your Own Cryptography) and BYOPK (Bring Your Own Private Key).

(inspired by @simontsui )
this post | permalink
CVE-2024-20328 - ClamAV Not So Calm (via @floyd)

https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/
this post | permalink
go sports!
this post | permalink
@swapgs Oh I didn't know they ship ClamAV, but it makes sense!

At least in their case I see good chance that there will be a check and public announcement in case they run a vulnerable config. Not so much in case of appliances...
this post | permalink
@tychotithonus I don't think so

Edit: I actually know of a product that is advertised like "so much more than an AV", but in fact is just two AV's in a trench-coat - I don't think they would be happy to be listed as reference...
this post | permalink
I wonder how many blinky boxes embedding ClamAV are affected by CVE-2024-20328...
this post | permalink
@joxean This actually sounds cool!
this post | permalink
@joxean You've got it?? Post some TikTok videos or something!!
this post | permalink
ClamAV fixes critical vulnerabilities:

- CVE-2024-20328: Fixed a possible command injection vulnerability in the VirusEvent feature of ClamAV's ClamD service.
- CVE-2024-20290 is a DoS

https://github.com/Cisco-Talos/clamav/releases/tag/clamav-1.2.2
this post | permalink
Next Page