• Hive Five
  • Posts
  • 🐝 Hive Five #10 - “If you want to go quickly, go alone. If you want to go far, go together.” — Proverb

🐝 Hive Five #10 - “If you want to go quickly, go alone. If you want to go far, go together.” — Proverb

Hi friends,

Greetings from the hive!

Happy Monday, I hope you had a great weekend. Mine was chock-full of awesomeness.

I revealed some exciting news, I joined Nathanial (d0nutptr) to work on resync! We celebrated it with the launch of the website. Resync is a massively scale-able and easily extensible recon solution, that focuses on high accuracy, scale, and speed.

On Sunday it was time for the second edition of NahamCon! It'd grown substantially since last time. It's always hectic, and even moreso with additional moving parts, but the mods handled it wonderfully. It's always awesome to be able to help people, watch awesome talks, compete in the CTF, and meme in the chat. Kudos to everyone involved!

For the occasion I've added a special NahamCon section with videos, slides, and repos. Let's goooo!

🐝 The Bee's Knees

NahamCon 2021 Recap

CTF

Talks

Amassive leap in host discovery - ITSecurityGuard - slides repoLearn to hack, choose a target, ???, get a bounty - Katie (InsiderPhD) - slidesIIS hacking - Shubs (@infosec_au) - slides

Recon Village

rez0 - ffuf scripts and tricks - videod0nutptr - Building Faster-than-light Reconnaissance - video slideshonoki - BBRF: Kickstart your recon - video slides repopry0cc - Introduction to Axiom - The Dynamic Infrastructure Framework for Everybody! videocodingo - Dooked - monitoring of DNS for Green, Blue and Red Teams video

Red Team Village

🔥 Buzzworthy

Upcoming

  • Women’s History Month: In honor of Women’s History Month, the CARE Lab is doing a spotlight feature series that will showcase phenomenal women in the cyber/STEM field.

  • SECURITY Magazine: picoCTF 2021, an online cybersecurity competition run by security & privacy experts in @CarnegieMellon's @CyLab, begins March 16 at 12 p.m.

🎉 Celebrations

  • STÖK ✌️: sold out his owasp talk, 230+ slides under 60 minutes. Amazing!

  • Joel Margolis: bought a house, congrats Joel!

  • pry // Ben Bidmead: The latest addition to the Darwin hacking team, 0xLupin. Awesome!

  • Floerer: After never having found interesting CORS misconfigurations they found 2, which both lead to complete account takeover. Killing it!

  • hakluke: Is getting ready to release a new tool "haktrails", a Golang client for easily querying SecurityTrails API data. Can't wait!

  • zseano 🛡️: Donates a laptop to @eXfilPr4tik for his dedication AND he has a baby on the way!

  • Nagli: Following @zseano talk on NahamCon2021 Nagli decided to share his already crafted research on the entire Google TLD domains scraped from OSINT sources, everything on the trello board is in GoogleVRP scope. Go crash it!

📰 Articles

📚 Resources

  • Hardware Hacking NZ: Hardware Hacking NZ is a special interest group for people interested in hardware and embedded system hacking.

  • Oliver's Blueteam Toolkit: This repo contains software I've written for the 2021 CrikeyCon Red vs Blue CTF.

  • m4ll0k/Bug-Bounty-Toolz: m4ll0k's Bug Bounty Tools.

  • CSP Bypass Guidelines: Content Security Policy (CSP) is the last line of defense against the exploitation of a XSS vulnerability, here we will deal with the possible ways to abuse flaws in its implementation.,

  • Using FOCA for OSINT Document Metadata Analysis: FOCA, which stands for (Fingerprinting Organizations with Collected Archives) is a pretty nifty tool to use for collecting documents from a target domain and analyzing metadata found within them.

  • Messing with GitHub's fork collaboration for fun and profit: GitHub has a useful feature called fork collaboration. It works as follows: Interestingly, you don’t have to own a repository to create a pull request from it.

  • Leaked Credentials gives access to internalfb.com: Facebook uses a contracting company in Someplace called Something to test new and upcoming features across the Facebook family.

  • 🍳 Based Cooking 🍲: Only Based cooking.

  • ATTL4S: You Do (Not) Understand Kerberos" slides.

  • Awesome CTO: A curated and opinionated list of resources for Chief Technology Officers and VP R&D, with the emphasis on startups and hyper-growth companies Contents General Hiring Management Handbooks Development process Architecture Tech.

  • Engineering Manager Resources: Engineering Manager Resources A list of engineering manager resource links.

  • 0xSobky/HackVault: This is a container repository for 0xSobky's public web hacks.

  • Bugcrowd Tip Jar 🧠: A curated collection of wisdom nuggets to level up your bug bounty game.

  • Kishore Krishna (@sillydadddy) infosec AMA #38: A Twitter AMA with Ali Tütüncü @alicanact60 as guest.

  • ej s nyman: Asks if there are more tech comics, such as b0rk's.

  • Michael Skelton: Twitter thread, of the best tricks for generating client-specific wordlists.

  • RegEx Crossword: It's a crossword puzzle where you need to fill in the hexes with character sequences, so that they match the regular expressions listed around the edges.

  • OSEP Code Snippets: Based on Offensive Security's PEN-300 course, classes and methods are public, so most binaries should allow for reflective loading as below.

  • alevchuk/vim-clutch: Purchased 2 USB foot switches (pedals) from China, used Ankaka.com and payed 20 USD (includes 2 pedals and shipping to California).

  • WP-XSS-Admin-Funcs: JavaScript functions intended to be used as an XSS payload against a WordPress admin account.

  • Google Bookmarklets: Harvesting lists of urls, titles, dates and descriptions from a Google search query is a recurrent need in digital methods and a hardly automatable one because of Google's restrictions towards robots.

🎥 Videos

🎵 Audio

Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.

Subscribe to Premium to read the rest.

Become a paying subscriber of Premium to get access to this post and other subscriber-only content.

Already a paying subscriber? Sign In.

A subscription gets you:

  • • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
  • • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
  • • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
  • • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
  • • Deep DISCOUNTS on paid content.
  • • Experience continuously added NEW BENEFITS.