- Hive Five
- Posts
- 🐝 Hive Five 117 - Procmon for macOS, Attacking LLM, and MalDev Academy
🐝 Hive Five 117 - Procmon for macOS, Attacking LLM, and MalDev Academy
Hi friends,
Greetings from the hive!
I hope you had a good weekend. I spent mine taking care of a bunch of small children. Very fulfilling but also tiring!
Something I was thinking of this week was happiness and the pursuit thereof. Here are some daily habits of happiness experts that can help.
I should spend more time in nature and start meditating. I also need to hang out with friends outside of professional setting more.
How about you? Let me know by hitting reply.
Let’s take this week by swarm!
🐝 The Bee’s Knees
Red Canary Mac Monitor is an advanced, stand-alone system monitoring tool tailor-made for macOS security research — Mac Monitor is practically the macOS version of the Microsoft Sysinternals tool, Procmon. more | tool
MalDev Academy by mr.d0x and NUL0x4C is a comprehensive module-based malware development course providing fundamental to advanced level knowledge. It features 32 Beginner modules, 49 Intermediate modules, 10 Advanced modules, 20 in the works for updates in the next few months, and 65 Custom code samples. more
Attacking LLM - Prompt Injection. How will the easy access to powerful APIs like GPT-4 affect the future of IT security? — LiveOverflow also breaks down how LLM’s actually work. more
Learn Prompting is a free, open source course on communicating with Artificial Intelligence. more
Google announced the deps[.]dev API which contains critical dependency data for secure supply chains. It’s a dataset of security metadata, including dependencies, licenses, advisories, and other critical health and security signals for more than 50 million open source package versions. more | API
️💪 Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
🔥 Buzzworthy
✅ Changelog
JSpector 2.4.7 is a simple Burp Suite extension to crawl JavaScript (JS) files in passive mode and display the results directly on the issue. more
Findomain v9.0. is the fastest and complete solution for domain recognition. more
DOMPurify 3.0.2 is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. more
ReconAIzer v0.4 is a Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more. more
Syntax × Sentry MMXXIII. Sentry welcomed Syntax to the family — I think more companies should do this. It’s a win-win. It reminded me of Stripe and Indiehackers. more
📅 Events
NahamCon June 15-17: Opening Keynote by geekboy and todayisnew, CTF by John Hammond. Hosted by ippsec and Alh4zr3d with workshops by Jhaddix, Agarri_FR, and 0xTib3rius. more
B-Sides Vancouver Island needs volunteers. Sign up to go to the general meeting, on April 27th. more
Technical Feud gameshow 4/17 9AM PST. It’s family feud, but with programming memes. more
🎉 Celebrate
Nagli claimed the top spot on OpenAI’s new program on Bugcrowd. Let’s go! more | OpenAI bug bounty program
lil c became a Twitch Affiliate. Congrats! more
mert leads the March Bugcrowd leaderboard. Here’s their breakdown: P1s - SQLi x3, IDOR x2, RCE x2, and info (session) leak x1. more
TESS inaugurated first P1 accepted for OpenAI. more
💰 Career
Paul’s buddy Derek, a dedicated and experienced infosec pro, is on the job market. They have 10+ years in cloud hosting & infosec, and a diverse skillset in blue team and red team. more
Ask a Manager salary 2023 survey — I love transparency. The more the merrier. more | Ask a manager
⚡️ Community
Dominik says that ironically, getting laid off has been the best thing to happen to them this year. more
RogueSMG is having a blast using Trickest to simplify complex things such as Subdomain brute with HUGE list(s), resolving subs, targeted nuclei scans, run custom scripts/checks, etc. more
meg lost 90+ pounds and did a complete body re-comp. Here’s what she eats in a week — I tend to overeat, so this is quite helpful for me to see. more
Ambassador Spotlight AWC Edition - remonsec. He helps his community thrive by bringing them together to share skills in Bangladesh. more
📰 Read
Mustafa found an interesting endpoint during recon. It was an empty page but there was file associated with malware. more
Hijacking Arch Linux Packages by Repo Jacking GitHub Repositories. In this blog post, they discuss how many AUR packages (use GitHub packages that) are vulnerable to repo jacking attacks. more
Brief instructions for how to modify and push to someone else’s PR on GitHub. more
XSSI (Cross Site Script Inclusion) to Steal AccessToken — Ankit found that the confidential data including the Access Token and UID is sent inside a JSONP response. more
The Uninvited Guest - IDORs, Garage Doors, and Stolen Secrets — In late 2022, while conducting independent security research, Sam discovered a series of critical vulnerabilities in Nexx’s smart device product line. more
🙏 Support
Enjoy reading the Hive Five? You can treat me to a coffee!
You can also share the newsletter with your friends.
📚 Resources
Summary of GodfatherOrwa’s talk at InfoSecComm’s IWCON 2.0 — Nithin shares key takeaways from the talk, covering subdomain enumeration, port scanning, collecting endpoints, dorking, searching for source/backup files, sensitive dataleaks, PII search, and generic tips. more | talk
Using AI to Develop Realistic Sock Puppet Accounts - There has been a lot of buzz over new and innovative ways to implement AI, such as Chat GPT, into our every day OSINT Analysis. more
leebaird/discover is a collection of custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing and creating malicious payloads and listeners with Metasploit. more
f/awesome-chatgpt-prompts is a collection of prompt examples to be used with the ChatGPT model. more
🎥 Watch
Red and Blue Ep 2: Roadmap - Just a red team guy and blue team guy looking at stuff together. more
Broken Access Control - Lab #12 Multi-step process with no access control on one step. more
HackTheBox - Encoding walkthrough, including topics such as building a webserver in Flask to exploit a SSRF. more
“Through the Eyes of a Thief” at DakotaCon 2023. more
Cloud Hacking: Common Attacks & Vulnerabilities. more
🎵 Listen
Day[0] Binary Exploitation Podcast 204 - Glitching the Wii-U and Integer Overflows. more
Day[0] Bug Bounty Podcast 203 - Pentaho Pre-Auth RCE and Theft by CAN Injection. Some fun issues this week as they explore code execution in Synthetics Recorder stemming from a comment in the code. An auth bypass in Pentaho leading to RCE via SSTI, car theft via CAN bus message injection, and how to become a cluster admin from a compromised pod in AWK Elastic Kubernetes Service. more
Critical Thinking - Bug Bounty Podcast E15 - The Israeli Million-Dollar Hacker Nagli. more
The Privacy, Security, & OSINT Show 293 - Financial Software Considerations. more
Latent Space Ep. 7 - Segment Anything Model and the Hard Problems of Computer Vision with Joseph Nelson of Roboflow. Meta open sourced a model, weights, and dataset 400x larger than the previous SOTA. Joseph introduces Computer Vision for developers and what’s next after OCR and Image Segmentation are solved. more
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.