- Hive Five
- Posts
- 🐝 Hive Five 115 - AI models become a threat to hackers, 2023 Web Hacking Roadmap, and why DNS always breaks the internet
🐝 Hive Five 115 - AI models become a threat to hackers, 2023 Web Hacking Roadmap, and why DNS always breaks the internet
Hi friends,
Greetings from the hive!
I hope you had a peaceful weekend. I’m writing this while listening to Merry Christmas Mr.Lawrence by Ryuichi Sakamoto.
I’ve noticed that the least bit of friction will prevent me from doing something. So, I’ve been slowly improving those processes, and automating where possible.
Make it easier for yourself. Cut things out of your life. Reduce scope.
What process have you improved lately?
Let’s take this week by swarm!
🐝 The Bee’s Knees
Our Future As Hackers Is At Stake! Copilot, ChatGPT and other AI models become a threat to hackers. We rely on insecure code, but when all developers moved over to code generated by AI, we will lose our job. We need to act fast! more
2023 Web Hacking Roadmap - How To Bug Bounty. more
Why does DNS always break the internet? Katie talks about how the internet actually works and what we mean when we say web security. more
Leveraging LLMs for solving bounty hunting pain points. In 2022, Charlie embarked on a journey with jswzl, believing that a single developer could deliver immense value without a team by focusing on high-value outputs and minimizing low-leverage work. more | tool - socksprox
BingBang: AAD misconfiguration led to Bing.com results manipulation and account takeover. How Wiz Research found a common misconfiguration in Azure Active Directory that compromised multiple Microsoft applications, including a Bing management portal. more
️💪 Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
🔥 Buzzworthy
✅ Changelog
HACKTORIA welcomes Joaquin Iglesias as their new CTF engineer. more
Caido released some much-requested features: Copy as cURL, Change between GET and POST in Replay/Forward, Timestamp of requests, and more. more
GitHub Copilot X was announced and it has an impressive set of new AI coding features. Learn how Microsoft is bringing ChatGPT features directly into your code editor. more
gwen001/related-domains 1.1.2. Find related domains of a given domain. more
Dalfox 2.9 Release. In this release of Dalfox, a flag has been added to record Dalfox traffic in HAR file and Raw HTTP Req/Res, which can be checked in CLI Output or JSON Report, etc. more
📅 Events
🎉 Celebrate
💰 Career
⚡️ Community
📰 Read
PHP filter chains: file read from error-based oracle. This attack method was first disclosed during the DownUnder CTF 2022, where @hash_kitten created a challenge where the players where asked to leak the /flag file with an infrastructure based on the following Dockerfile and code snippet. more
You Are Not Too Old (To Pivot Into AI). more
How to avoid the aCropalypse. Last week, news about CVE-2023-21036, nicknamed the “aCropalypse,” spread across Twitter and other media. more
Cognitive Biases in Hacking. In this post monke describes a few of the common biases that may occur in your thought process, with examples for each. more
Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research. CloudTrail is a crucial AWS service that provides a record of API calls and other important activities in AWS environments. Teams can use this information for auditing purposes and to identify potential security incidents. more
📚 Resources
ZwinK shares Android pentesting resources. more
People sharing their biggest mistake they’ve made in bug bounty. more
Fun lab/training/CTF techniques, tactics, exploits or tools that are not suitable for a junior tester to use on a client unsupervised or at all. more
Decurity/semgrep-smart-contracts contains Semgrep rules for smart contracts based on DeFi exploits. more
People’s best tricks, tools and ideas for wordlist generation. more
🎥 Watch
HackTheBox - Sekhmet walkthrough. more
Broken Access Control - Lab #10 User ID controlled by param with password disclosure. more
In this video, Tib3rius walks through the solutions to the Hack The Box Cyber Apocalypse CTF 2023 web challenges. more
Cloud Hacking: The Basics. more
Cheat Engine: Beating the Final Game. Tutorial 10 in a Game Hacking Series. more
🎵 Listen
Day[0] Binary Exploitation Podcast 200- Integer Bugs & Synthetic Memory Protections. They talk about Pwn2Own policy changes, a couple memeable overflows, and some new anti-ROP mitigations on OpenBSD. more
Day[0] Bug Bounty Podcast 199 - Bypassing CloudTrail and Tricking GPTs. They discuss applying AI/ChatGPT to security research, but before that they have a few interesting vulnerabilities. more
Critical Thinking - Bug Bounty Podcast Episode 13: How to Find a Good BBP + Acropalypse + ZDI. In this episode they talk about how to determine if a bug bounty program is good or not from the policy page. more
Smashing Security 315: Crypto hacker hijinks, government spyware, and Utah social media shocker. A cryptocurrency hack leads us down a maze of twisty little passages, Joe Biden’s commercial spyware bill, and Utah gets tough on social media sites. more
Risky Business #701 - Why infosec is wrong about TikTok. more
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.