- Hive Five
- Posts
- 🐝 Hive Five 118 - Easiest beginner bugs, the Anatomy of Autonomy, and BrokenSesame
🐝 Hive Five 118 - Easiest beginner bugs, the Anatomy of Autonomy, and BrokenSesame
Hi friends,
Greetings from the hive!
Lately, I’ve been thinking about community and curation. The importance of making everything your own and being authentic.
What’s been on your mind? Reply to this email and let me know.
Let’s take this week by swarm!
🐝 The Bee’s Knees
Hacker Interviews: ArchAngelDDay. His approach to finding bugs in applications involves looking for every place where the application denies a user’s request and then finding ways to bypass those restrictions to find vulnerabilities. more
“Easiest” Beginner Bugs? Access Control and IDORs. Whenever someone asks what bug they should look for InsiderPhD always gives the same answer: IDORs and access control issues. more | what is access control
Stealing GitHub staff’s access token via GitHub Actions. more
BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services. Wiz Research has discovered a chain of critical vulnerabilities in two of Alibaba Cloud’s popular services, ApsaraDB RDS for PostgreSQL and AnalyticDB for PostgreSQL. more
The Anatomy of Autonomy: Why Agents are the next AI Killer App after ChatGPT. Auto-GPT/BabyAGI Executive Summary, a Brief History of Autonomous Agentic AI, and Predictions for Autonomous Future. more
️💪 Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
🔥 Buzzworthy
✅ Changelog
📅 Events
shubs will be doing a talk about hacking EPP servers and the EPP protocol with Sam Curry later this year. more
🎉 Celebrate
rez0 and rhynorater are offering security assessments and pentests for AI-powered services. Exciting! more
ca$s:e cage’s first three weeks at her new job have been going really well. LFG! more
Corben Leo submitted his first critical vuln to @kucoincom on HackenProof. Nice one! more
hipotermia et al are on to the next round in HackerOne’s Ambassador World Cup. Congrats! more
💰 Career
CrowdStrike Red Team is hiring. more
If anyone in the UK is looking for a pentesting role sent Mantis a DM. more
The Electronic Frontier Foundation (EFF) is hiring a Public Interest Technology Director to lead their Public Interest Technology team. more
For any aspiring entrepreneurs, this definitive list of questions from Unusual Ventures is a great “gut check” to test if you’re ready to turn an idea into something concrete. more
Ian Coldwater is looking for work, they’re open to security architect, threat modeling, and security research roles. more
⚡️ Community
Osirys is looking for a Burp bapp that will hide cookies from HTTP requests. more
Jason shares a funny story involving HackerOne and Bugcrowd. more
Katie is ready for Con season. more
0x52 shares their first year stats auditing 115 codebases. They found ~140 high risk vulnerabilities and ~250 medium by spending ~1300 hours reviewing code. more
How many monitors does it take to be a hacker? For me personally, the sweet spot is one monitor. I currently use a 27”. more
📰 Read
The story of Chetan Nayak and Brute Ratel. more
Weblogic CVE-2023-21931 vulnerability exploration technique: post-deserialization exploitation. more
Multiple Critical Vulnerabilities in Strapi Versions <=4.7.1 - Strapi had multiple critical vulnerabilities that could be chained together to gain Unauthenticated Remote Code Execution. more
How To Bypass Cloudflare in 2022 - With an estimated 40% of websites using Cloudflares Content Delivery Network (CDN), bypassing Cloudflare’s anti-bot protection system has become a thing. more
Making TruffleHog faster with Aho Corasick. They used keyword optimization leveraging the Aho-Corasick algorithm. In total, this led to a 2x speedup on average in the overall scanner. more
📚 Resources
HackSpaceCon Workshops & Talks Slides. more
OffcierCia/non-typical-OSINT-guide is the most unusual OSINT guide you’ve ever seen. more
awesome-foss/awesome-sysadmin is a curated list of amazingly awesome open source sysadmin resources. more
Though a bit late, here’s a Beginner’s Guide To BSidesSF. more
🎥 Watch
The Official OSCP course (PEN-200: Penetration Testing with Kali Linux) recently got updated. This is an interview with Jeremy Miller from OffSec about the changes.
Broken Access Control - Lab # 13 Referer-based access control. more
HackTheBox - Investigation walkthrough. more
Your first three Linux IR commands if you’re compromised. more
JavaScript for Hackers, Pt. 3 - reimplementing the app in React. more
🎵 Listen
Latent Space Ep. 8 - AI-powered Search for the Enterprise — with Deedy Das of Glean. The Hard Problems in Building an AI Search Unicorn, Google vs ChatGPT, Doing AI Infra Math, Detecting Generated Text, and why enterprises will need much more than Document QA. more
The Privacy, Security, & OSINT Show 294 - Preparing for Home Disaster. This week they discuss preparation for home disaster along with the latest Privacy, Security, and OSINT news. more
Critical Thinking - Bug Bounty Podcast E16: The Hacker’s Toolkit. Joel and Justin talk about their VPS setup, go-to hacking tools, most often used Linux commands, and the ways they duct tape all of these together for the big hacks. more
Songs to get you hyped in the morning. Get after it! more
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.