- Hive Five
- Posts
- π Hive Five 103 β 2022 CVE data review and bypass firewalls with of-CORs
π Hive Five 103 β 2022 CVE data review and bypass firewalls with of-CORs
Hive Five
By securibee π
Hi friends,
Greetings from the hive!
I hope you had a great first week of 2023.
If youβve been following my Tweets, you know that Iβve been working on my first Ghost site. I enjoy the project and love learning new things and designing websites.
Taking on this new project and working with an unknown platform is further reinforced by something I read a couple of weeks ago, to make success controllable.
Couple this with focusing on what you can control, and you win, even if it fails, as you acquire new skills and make new relationships.
Letβs take this week by swarm!
π The Beeβs Knees
Live Recon Interview in the Smart Contract Series with ret2jazzy. more
Bypass firewalls with of-CORs and typo-squatting. more | video | repo
2022 was a record-breaking growth year for CVE data. Jerry goes through the data and highlights some of the most interesting data points. more | repo
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and more. more
The Top 10 web hacking techniques of 2022 nominations are open. more
οΈπͺ Sponsor
Want me to write about your company? Sponsor the Hive Five.
π₯ Buzzworthy
β Changelog
Intigriti has a new content creator: CryptoCat. more
reconFTW v2.5.1 is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities. more
DOMPurify 2.4.3 is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. more
π Events
π Celebrate
MrTuxracer on his first bug of 2023: A quite crazy authentication bypass affecting a firewall vendor. Keep an eye out for CVE-2023-22620. Keep it up! more
Masonhck357 found his first crit of the year on a 3 year old program. Yessir! more
Valerio Brussani celebrates 2022. Awesome! more
Jason Haddix will be the new CISO and Hacker in Charge at BuddoBot Inc. Letβs go! more
π° Career
Top 3 things you need to change in 2023 if youβre serious about getting a job in 2023 and more. more
β‘οΈ Community
zseano is still having a rough time, dealing with sickness. Feel better soon! more
I_Am_Jakoby is looking to collaborate with content creators in the cyber security field. Anyone interested? more
Alethe had a awful experience with CompTIA. more
Yassine Aboukir is flying out of Bali. Safe travels! more
MrTuxracer shares his Bug Bounty goals for 2023. Crush it! more
π° Read
Manipulating AES Traffic using a Chain of Proxies and Hardcoded Keys. more
Corben Leo hacked a large company (70k+ employees) through social engineering. Legally of course. more
Leaking Secrets From GitHub Actions: Reading Files And Environment Variables, Intercepting Network/Process Communication, Dumping Memory. more
Why 2022 was a record-breaking year in bug bounty awards for GitLab. more
The Auditooor Grindset. So, you want to become a smart contract auditor. more
π Resources
Offensive Security & Reverse Engineering (OSRE) course. This is the whole course that was covered at Champlain College during Spring 20/21. more | labs| notes | slides
Adrian on how to become a Web3 Bug Bounty Hunter in 2023. more
The top 20 bug bounty creators according to Intigriti. more
A collaboratively curated list of awesome Open-Source Intelligence (OSINT) Resources by ARPSyndicate. more
Educational content related to Smart contract auditing and web3 security throughout the 365 days of the year by Sm4rty-1. more
π₯ Watch
I Hope This Sticks: Analyzing ClipboardEvent Listeners for XSS by spaceraccoon, a NahamCon2022EU talk. more
sec4dev 2022 talk: Scaling AppSec by Clint Gibler. more
HackTheBox - Health - 00:00 - Intro more
Another NahamCon2022EU talk: Hunting for Amazon Cognito Security Misconfigurations by Yassine. more
LevelUpX - Series 13: SPI Flash for Bug Bounty Hunters with Nerdwell. more
π΅ Listen
Darknet Diaries top 13 most listened to episodes. more
The Privacy, Security, & OSINT Show 287 - Listener Questions, UNREDACTED 5, & OSINT 10. more
Malicious Life - Cyberbunker, Part 1. more
Huberman Lab - Jocko Willink: How to Become Resilient, Forge Your Identity & Lead Others. more
Derek Sivers β How to Live as a Creator and Why You Should Focus Like a Monomaniac. more
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- β’ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- β’ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- β’ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- β’ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- β’ Deep DISCOUNTS on paid content.
- β’ Experience continuously added NEW BENEFITS.