- Hive Five
- Posts
- š Hive Five 130 - New JavaScript analysis tools, and DEFCON advice
š Hive Five 130 - New JavaScript analysis tools, and DEFCON advice
Hi friends,
Greetings from the hive!
Community, public roadmaps, and documentation are often overlooked or mishandled. Obsidian does all exceptionally well.
Not to mention that their product is amazing. The speed of iteration and level of craftsmanship is something to admire.
Looking at their roadmap makes me excited for the future.
Letās take this week by swarm!
š The Beeās Knees
Introducing jswzl: In-depth JavaScript analysis for web security testers by Charlie Eriksen. more
Deviantās DEFCON Advice. Tips that help you in your planning for DEFCON, Black Hat, BSides, and the rest of Hacker Summer Camp. more
Dangerzone enable you to take potentially dangerous PDFs, office documents, or images and convert them to a safe PDF. more
Secrets of an Android App Bug Hunter. Sergey Toshin tells the story of how he became a top Android bug hunter and how he finds critical vulnerabilities. more
JSluice is a new tool by TomNomNom that extracts URLs, paths, secrets, and other interesting bits from JavaScript. more | talk | slides
ļøšŖ Sponsor
Interested in being a sponsor?
š„ Buzzworthy
ā Changelog
DOMscan v0.0.2. comes with a handy new feature: --interactive, which pauses after each payload. more
Smol-ai/menubar v0.0.12 release added Local Models, Dark Mode, and new Icons. more
PentesterLab released 3 code review challenging in Java. more
Important Rana Khalil Academy changes, such as addition of modules, topics, and price changes. more
GAP Burp extension v3.5 is available. A major bug where site map roots with port numbers other than 80 or 443 werenāt processed correctly has now been fixed. more
š Events
š Celebrate
Giuseppe following his intuition and is going back to CTFs, exploring vulnerabilities, and finding bugs. Awesome! more
XNL-h4ck3r started a YouTube channel. Subscribe now! more
Celebrating everyone who started bug bounty hunting after 30. LFG! more
Patrik hasnāt spent a single minute in front of a screen this weekend. #goals! more
š° Career
Guidelines to follow when you want to start a business as a family person with children. more
13 infosec career hacks by Matt Johansen. more
You donāt HAVE to spend your work days hopping from meeting to meeting. more
How to unlock hidden remote jobs with Google. more
Long-form concept breakdowns, career thoughts, and immediately actionable advice, in chronological order. more
ā”ļø Community
š° Read
Encrypted Doesnāt Mean Authenticated: ShareFile RCE (CVE-2023-24489). more | advisory
Reversing Mac Donaldās table beacon. more
All your parcel are belong to us, a Troopers 2023 talk. more
RCE in GitLabās CLI tool. After starting at GitLab in October of last year, one of the first reviews that came their way was their CLI tool, which was only recently published officially. more
Root Cause Analysis of CVE-2023-32439 Type Confusion in Webkit by Sunjoo Park. more
š Support
Enjoy reading the Hive Five? You can treat me to a coffee!
You can also share the newsletter with your friends.
š” Tips
Gwendel shares a tip based on NahamSecās usage of crt.sh. more
Paul shares how heās using the newly released JS tools. more
Justin shares a methodology that helps you decide when to move on from your bug bounty target. more
Justin reiterates the importance of understanding basic browser functionality and key technologies. more
David shares a lifehack, order a coffee at a 5-star hotel and work in the lobby instead going to Starbucks. more
šÆ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
superhero1 | superhero1 | create educational content on IT security, CTFs & BugBounty.
willbtlr | Will Butler | Current: Red Team in FinTech | Former: Red Team @100xGroup, @Cruise, @Apple, and @PwC | I tweet about security, software, entrepreneurship, and fitness.
@jeffrey_way | Jeffrey Way | I am error.
@TJ_Null | Tony | Blue Teamer in Disguise | SANS Netwars Champion. Former community manager and founder of the Offsec community for @offsectraining.
@BrettFromDJ | Brett @ Designjoy | Built a one-man design agency to $2m/yr.
š Productivity
Dickieās process to improve anything: define, gather, systemize, and repeat. more
Douglas on putting Building a Second Brain in practice: āIdeas are grasshoppers. Catch them right away, so you donāt lose them!ā more
Hack your brain with Obsidian. A deep-dive into No Boilerplateās second brain, and if you take his advice, your second brain. more
Clean as you go (a life hack for code). Jason shares a story about a habit he picked up working in restaurants, and how the lesson he learned still helps him write better software to this day. more
Taking notes on podcasts with Snipd, Readwise, and Obsidian. more
š Technology
Una tweeted something I never thought about: āInternet Explorer was such a great name.ā ā I agree! more
GPT for your specific use case by finetuning Falcon 7b/40b instructed with your own data. A step-by-step guide on how to train the falcon model to generate high quality midjourney prompt. more
Lima: a nice way to run Linux VMs on Mac. Lima stands for Linux on Mac and allows you to run Linux virtual machines for running containerd. more | tool
How to Use AI to Do Stuff: An Opinionated Guide. Ethan covers the state of play as of Summer, 2023. more
š§ Wisdom
š Cross-pollination
A moving hack that blew my mind. What a game changer! more
Why We Create. Shot on a canon R5 C by Peter McKinnon. more
Adam Wathan used an accountability coach to lose 65 pounds and shared his journey in real-time. more
How to make a chicken sandwich in only 6 months. Oh, itāll also cost you $1500. more
TIL you can expedite your US passport processing by contacting your congress person. more
š Fact
A hangover is caused by the bodyās production of acetaldehyde (ethanal) in the body from the alcohol consumed. Taking honey provides the body with sodium, potassium, and fructose, which aid recovery. Honey is also a rapid source of energy and the fructose accelerates alcohol oxidation in the liver, thereby acting as a sobering agent.
This bee fact is brought to you by The Beekeeperās Bible: Bees, Honey, Recipes & Other Home Uses.
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. Itās my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- ā¢ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- ā¢ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- ā¢ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- ā¢ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- ā¢ Deep DISCOUNTS on paid content.
- ā¢ Experience continuously added NEW BENEFITS.