infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@qwertyoruiop To be fair in Idiocracy there was also a whole apparatus of idiots under the president who worked against the smart guy (not very efficiently though) including ministers, the judical system and the police.
this post | permalink
[RSS] The case of a program that crashed on its first instruction

https://devblogs.microsoft.com/oldnewthing/20241108-00/?p=110490
this post | permalink
[RSS] Pishi: Coverage guided macOS KEXT fuzzing.

https://r00tkitsmm.github.io/fuzzing/2024/11/08/Pishi.html
this post | permalink
@codecolorist I'd need kurwa wodka for that stuff...
this post | permalink
@codecolorist Let me recommend some excellent learning material (as a Hungarian I consider myself qualified in this topic):

https://www.youtube.com/watch?v=OHHpYXQyQO4
https://www.youtube.com/watch?v=iL1HvAu8V1w
this post | permalink
@GossiTheDog @reverseics @cR0w Thank you for the clarification!
this post | permalink
@GossiTheDog @reverseics @cR0w But could *non-admin* users access the DB of *other* users? SQLite or not, this should not be possible (in general...). If it was possible back then (as it was suggested by you and articles based on your comments), then now would be the best time for all to see what the problem was to check if the same or similar problem is present in the implementation that is to be released.
this post | permalink
@GossiTheDog @reverseics @cR0w Great you chime in! Any plans to release that x-user Recall exploit you talked about?

https://infosec.place/notice/AieinAN5CpyKNShdvE
this post | permalink
@cR0w @reverseics My theory is that a) URL's are the new filesystems and b) abstracting away control ("..") from data ("etc") would have an unacceptable overhead compared to SQL (ORMs) or even HTML (DOM sanitizers), so the memes are here to stay :)
this post | permalink
#directoryTraversalMemes seem to become a classic, but I wonder if anyone has a list of specific payloads that trigger the different vulnerabilities of recent memory?

/cc @reverseics @cR0w
this post | permalink
Next Page