Post details
The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose

The story of how I could steal credentials on Infosec Mastodon with a HTML injection vulnerability, without needing to bypass CSP. Everybody on our Twitter feed seemed to be jumping ship to the infose
Infosys has a lot to say about security You can check out their website for a lot of buzwords , but it’s clear from all the stock photos that they take security Very Seriously Indeed ™️. However, from what I’ve found recently, it seems that Infosys use the following Comprehensive Management-Endorsed Proficiently Driven Cybersecurity Strategy and Framework items: Don’t use AWS roles or temporary credentials for your developers Instead, use IAM user keys and give them all FullAdminAccess permissions Never rotate these keys and store them as plaintext in git Use these keys to protect what appears to be medical data about COVID patients Have someone publish those keys and the code in a public package to pypi Keep those keys active for days after leakage Make nonsensical pull requests to try and remove all references to the leak The Leak This morning I woke up to a very strange pull request on my pypi-data project.
Tweets were always short-lived. Turns out Twitter was too.
I am really disappointed to see prominent voices in our leadership at Salesforce promoting things that are the antithesis of our culture and our values. The fact that I can say so without expecting to get fired shows we're still different. Let's keep it that way.David Reed (@aoristdual)Sun, 20 Nov 2022 02:18 GMT
benioff retweeted this shit lmao
Post details
Show me another CEO that has more skin in the game at 1AM in the office. These young engineers are learning from the most innovative person of the twenty-first century.Vala Afshar (@ValaAfshar)Sat, 19 Nov 2022 14:51 GMT
Senior Oops Engineer (@ReinH)Sun, 20 Nov 2022 08:03 GMT
tesla has recalled around ~35-40% of cars they’ve sold twitter.com/nbcnews/status…Post details
Tesla is recalling more than 321,000 vehicles in the U.S. because tail lights may intermittently fail to illuminate, the company says. nbcnews.to/3geBVa4NBC News (@NBCNews)Sat, 19 Nov 2022 21:21 GMT
Marlow Stern (@MarlowNYC)Sun, 20 Nov 2022 07:43 GMT
Musk with Twitter is like one of those stories about a trust fund kid who buys a million dollar Ferrari but doesn't have a clue how to drive it and totals it the first night he takes it on the freeway.
RSchooley@socel.net (@Rschooley)Sun, 20 Nov 2022 04:03 GMT
as more people vote, the results change. this must mean fraud! election denying even for Twitter polls nowMatt Binder (@MattBinder)Sat, 19 Nov 2022 13:31 GMT
Some day we're going to look back at social media and say "what are you talking about, there's no way everyone on Twitter was all on one instance"
I was going to do so much today then my body was like *CRIPPLING CRAMPS * so yay for being a woman 🙃 hoping tomorrow is easierNot Pokket 😈 (@NotPokket)Sun, 20 Nov 2022 07:55 GMT
Since it's #InternationalMensDay, here's a thread of every part of the gynaecological anatomy that is named after a man, with a bit of trivia about each man. Some of the bits are very specific. Before you ask, there are no parts of the gynaecological anatomy named after women...Vagina Museum (@vagina_museum)Sat, 19 Nov 2022 15:33 GMT
I have a blog, on a domain that I own, with an rss feed. For a while it felt a little outdated, but now I'm happy I stuck with the thing I felt was right. lornajane.netPost details
and it warms my heart to see so many people (okay, four) linking to blogs on a domain! with an rss feed! :oAlex Chan (@alexwlchan)Sat, 19 Nov 2022 23:02 GMT
Lorna Mitchell (@lornajane)Sun, 20 Nov 2022 07:37 GMT
smash cut to 2023 and some water baron is using my skull as a bong
Amy-Leigh Gemstone (lolennui@mas.to) (@lolennui)Mon, 25 Apr 2022 19:56 +0000
lololol
Post details
my prediction is trump back on twitter and then the run up to 2024 is identical to 2016. for my part idk I’ll probably be on ketamine.
Amy-Leigh Gemstone (lolennui@mas.to) (@lolennui)Mon, 25 Apr 2022 19:14 +0000
Amy-Leigh Gemstone (lolennui@mas.to) (@lolennui)Sun, 20 Nov 2022 07:41 GMT
When someone writes "thought leader" in their own bio, then copies your work, word for word, without attribution, and gets a thousand responses on social media... Flattery feels awesome.Alex Yates (Probably) (@_AlexYates_)Sun, 20 Nov 2022 00:41 GMT
A quick reminder as folks are glorifying absurd hours again: 1. Sustained crunch mode leads to net negative productivity vs. 40 hr/wk 2. Working sleep deprived leaves you as mentally impaired as being drunk Working longer *feels* productive but it makes you worse at your job.Jason Lengstorf ⚡️ (@jlengstorf)Sun, 20 Nov 2022 02:06 GMT
I tweeted that I prefer cosycore to hardcore and someone called me lazy 🙃 I don’t know why some folks feel like work isn’t work unless it’s miserable and you’re stressed.Cassie Evans (@cassiecodes)Sun, 20 Nov 2022 07:47 GMT
Bird watching is so perverted. You blow a little noisemaker that shouts “Wanna fuck?! Wanna fuck?!” And then when a bird shows up wanting to fuck you are like “Aha, I see you through my binoculars!” Sick behavior. Twisted behavior.
Gabe Delahaye (@gabedelahaye)Sat, 31 Jul 2021 16:42 +0000
On behalf of doctors and nurses everywhere - DONT EVEN THINK ABOUT IT!
Post details
It’s beginning to look a lot like Christmassssss
Rustin (@rustincharles)Fri, 18 Nov 2022 17:22 GMT
Dr Vancbromycin 🇺🇸🇺🇦 (@Vancbromycin)Sat, 19 Nov 2022 00:48 GMT
everyone keeps saying “go to therapy” no 💯
first-mate prance (@bocxtop)Sun, 20 Nov 2022 04:42 GMT
TWITTER HAS BEEN A VEHICLE OF AMPLIFICATION FOR WRITERS AND ARTISTS AND WITH ITS DEMISE YOU'RE SEEING A PANICKED GROUP OF CREATORS TRYING TO REESTABLISH AUDIENCES - WHICH TOOK YEARS TO BUILD - ON OTHER PLATFORMS IN A MATTER OF DAYS, ANYWAY HAVE YOU SIGNED UP FOR MY NEWSLETTER
Geraldine @everywhereist@mastodon.social (@everywhereist)Sat, 19 Nov 2022 15:52 GMT
Molly White | @molly0xfff@hachyderm.io (@molly0xFFF)Sun, 20 Nov 2022 04:52 GMT
sega presents situation bondage
qdot (@qDot)Sun, 20 Nov 2022 04:59 GMT
I've had to reassure a bunch of different people that Mastodon has absolutely nothing to do with blockchains or crypto
Simon Willison (@simonw)Sun, 20 Nov 2022 05:04 GMT
TRUMP JUST RESPONDED TO ELON’S POLL AND SAID “NO THANKS” LMAOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOOO
Best of Dying Twiter (@bestofdyingtwit)Sat, 19 Nov 2022 22:25 GMT
You've defined an elitist form of narcissism that you used to justify the abuse of the very workers who enable the wealth of people like Elon. Stop justifying abusive behaviors. Stop celebrating failure.23rdCenturySouth (@south_23rd)Fri, 18 Nov 2022 12:39 GMT
Screenshots are bad for accessibility and circumvent mute and block filters.
Cher Scarlett (@cherthedev)Mon, 02 Mar 2020 12:15 GMT
I'm so glad Elon Musk allows accounts with no profile pictures and only a handful of followers to pay $8 to be "verified" and post this crap. What is this guy "verified" as other than an asshole? No wonder so many of us are looking at alternatives.Post details
Marc Elias is George Soros, enemy of the American People
Keith Strange (@KeithStrange6)Sun, 20 Nov 2022 05:11 GMT
Marc E. Elias (@marceelias)Sun, 20 Nov 2022 05:27 GMT
No Context Humans (@HumansNoContext)Sat, 19 Nov 2022 15:30 GMT
refuse to lose the tweets from the best poster ever just because the worst poster ever shit his pants after a divorce. here it is: every @dril tweet in chronological order, up & free forever. please share. will continue to build it out for ease of use docs.google.com/spreadsheets/d…Nick Farruggia (@nickfarruggia)Sun, 20 Nov 2022 00:13 GMT
Not looking forward to being irrelevant again if @Twitter ends on Monday.James Blunt (@JamesBlunt)Sat, 19 Nov 2022 16:37 GMT
How many times are we gonna be subjected to this man’s takes fr
SUBSCRIBE TO MY SUBSTACK (@TaylorLorenz)Sun, 20 Nov 2022 06:14 GMT
Why does anyone in tech listen to this man
Post details
Men just want the freedom to crack racist jokes without some girl in HR freaking out.
Justin Murphy (@jmrphy)Sat, 19 Nov 2022 23:06 GMT
SUBSCRIBE TO MY SUBSTACK (@TaylorLorenz)Sun, 20 Nov 2022 06:13 GMT
Alex (@A1exTimmons)Sun, 20 Nov 2022 06:26 GMT
What the fuck did I say!!! NO NEWS!!!!
Kylie Robison (@kyliebytes)Sun, 20 Nov 2022 05:24 GMT
Ok I’m gonna delete the Twitter app for the weekend, don’t do any news thx
Kylie Robison (@kyliebytes)Sat, 19 Nov 2022 03:04 GMT
images that MIGHT be cursed (@mightbecursed)Sun, 20 Nov 2022 06:28 GMT
“Just bring me your best code,” I say with a dismissive hand wave, hoping my strategy for dealing with wine menus I don’t understand also works on engineers.
trash, but make it fashion 🦝✨ (@ElleArmageddon)Sun, 20 Nov 2022 01:37 GMT
In one day, Elon Musk did more to endanger Jews and other minorities than any celebrity could ever do. It won’t be seen that way. Won’t be reported that way. But those are the facts.Elad Nehorai (@EladNehorai)Sun, 20 Nov 2022 06:28 GMT
Officially 3 years as a Software Engineer woo! ✨
blank (@kefimochi)Sat, 19 Nov 2022 00:24 GMT
IF THE ZOO BANS ME FOR HOLLERING AT THE ANIMALS I WILL FACE GOD AND WALK BACKWARDS INTO HELL
wint (@dril)Tue, 22 May 2012 21:46 +0000
just amazing that the man tried to overturn a presidential election and so far his harshest punishment is a temporary loss of a social media account
Matthew Segal (@segalmr)Sun, 20 Nov 2022 01:31 GMT
wait til british ppl realise qatar own canary wharf, harrods, the shard and half the expensive property in London
Ruqaiya (@ruqaiya_h)Sat, 19 Nov 2022 13:40 GMT
christmas in london
✨ (@PRADAXBBY)Tue, 01 Nov 2022 16:09 GMT
During my trip in London I had room 418. Only Developers will understand this HTTP joke.Francesco - francescociulla.lens (@FrancescoCiull4)Sat, 19 Nov 2022 13:20 GMT
btw I didn't actually write the whole thing in a couple hours. The basic story & treatment WAS literally a few hours, but then it took me a few more days to put the whole thing together. Vol 3, on the other hand, took an entire year or more of writing. You never know.
Post details
James Gunn Talks Writing ‘The Guardians of the Galaxy Holiday Special’ in Just a Few Hours and the Latest on His Final ‘Guardians’ Film hollywoodreporter.com/movies/movie-f…The Hollywood Reporter (@THR)Fri, 18 Nov 2022 23:07 GMT
James Gunn (@JamesGunn)Sat, 19 Nov 2022 01:35 GMT