infosex.exchange <3

You are probably looking for the infosec.exchange Mastodon instance

This host is mostly for my random stuff, and in little part acts like a well-intentioned placeholder for the typosquatted domain.

Discoverability and Archiving

Currently I'm using this host for saving the items from my own feeds to the Wayback Machine and provide in-links for search engines. I hate that I have to do this, but the non-sense ideology of Mastodon pretty much ruined the search feature for Fediverse as a whole, and this wasn't changed by the fact that they owned their mistake and implemented search eventually.

Yes, I (or anyone else) could do similar things with other peoples published feeds, regardless of the tantrum. No, you can't defederate this, because the process doesn't rely on an instance.

Gluttony Section for Search Engines

@touloutoumou You're doing God's work!
this post | permalink
@infosecdj Don't brag about being the Chosen One

https://youtu.be/fSxVN4csfTI?si=hzKmtkqJcsBzbmHv&t=21
this post | permalink
I'm still looking for that brain activity sensor that someone used to make a propeller hat that spins faster when you think harder.
this post | permalink
Re: CVE-2025-0108

Can we agree that "X-Trust-Me-Bro: $boolean" headers set by reverse proxies are an anti-pattern?

If so, what is the best practice?
this post | permalink
[RSS] Hack That Broken Zipper!

https://hackaday.com/2025/02/09/hack-that-broken-zipper/
this post | permalink
[RSS] Nginx/Apache Path Confusion to Auth Bypass in PAN-OS (CVE-2025-0108)

https://www.assetnote.io/resources/research/nginx-apache-path-confusion-to-auth-bypass-in-pan-os

Full analysis
this post | permalink
Congrats to the IOActive marketing team for moving their blog to a platform with no RSS :P
this post | permalink
[RSS] The Key to COMpromise - Downloading a SYSTEM shell, Part 3

https://neodyme.io/en/blog/com_hijacking_3/
this post | permalink
@cR0w @silverwizard PR has to show their worth, I'm pretty sure this wasn't composed by the offensive team
this post | permalink
@silverwizard @cR0w To be fair, they could've pushed a silent patch...
this post | permalink
Next Page