mstdn.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general-purpose Mastodon server with a 500 character limit. All languages are welcome.

Administered by:

Server stats:

11K
active users

#InternetOfShit

14 posts7 participants0 posts today
Stefan Gast<p><span class="h-card" translate="no"><a href="https://infosec.exchange/@lcamtuf" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>lcamtuf</span></a></span> Which manufacturer? I feel like they deserve to have their name mentioned for this.</p><p><a href="https://infosec.exchange/tags/internetofshit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>internetofshit</span></a></p>
cR0w 🦃<p>Tenda</p><p><a href="https://www.cve.org/CVERecord?id=CVE-2025-63454" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">cve.org/CVERecord?id=CVE-2025-</span><span class="invisible">63454</span></a></p><p><a href="https://www.cve.org/CVERecord?id=CVE-2025-63458" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">cve.org/CVERecord?id=CVE-2025-</span><span class="invisible">63458</span></a></p><p>cc: <span class="h-card" translate="no"><a href="https://haunted.computer/@Dio9sys" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Dio9sys</span></a></span> <span class="h-card" translate="no"><a href="https://infosec.exchange/@da_667" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>da_667</span></a></span> </p><p><a href="https://infosec.exchange/tags/internetOfShit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>internetOfShit</span></a></p>

github.com/5ulfur/security-adv

The /login.htm and /pass.htm pages in the Web management interface contain the administrator credentials.

The session cookie contains a base64-encoded "username:password" and is stored/transmitted without any protection.

All the traffic is HTTP, so an attacker can easily intercept it.

My security advisories. Contribute to 5ulfur/security-advisories development by creating an account on GitHub.
GitHubsecurity-advisories/CVE-2025-63423 at main · 5ulfur/security-advisoriesMy security advisories. Contribute to 5ulfur/security-advisories development by creating an account on GitHub.

Imagine that, in a moment of madness, you spend $3,500 (about €3.000 at the current exchange rate) on a smart refrigerator. Now imagine that every time you approach it, you see an advertisement but they are not personalized because "trust me bro", says Samsung. Well, you don't need to imagine.

arstechnica.com/gadgets/2025/1

A Samsung Family Hub fridge.
Ars Technica · Samsung makes ads on $3,499 smart fridges official with upcoming software updateBy Scharon Harding