- Hive Five
- Posts
- š Hive Five 132 - The key to succeed in bug bounty
š Hive Five 132 - The key to succeed in bug bounty
Hi friends,
Greetings from the hive!
Health is something to easily take for granted. We never really appreciate what we have until itās gone.
Iāve only been sick for two weeks now, and itās already been tough. What was once easy becomes a struggle.
Sleepless nights, no more routine, and progress halted. No more plans. Eating becomes a chore, and hobbies fall by the wayside. Itās just me trying to get through the day.
My takeaway is to be more grateful, to be truly thankful for my health, and to help those who are in need.
Letās take this week by swarm!
š The Beeās Knees
NahamSec released all of the NahamCon2023 talks. Check out talks by ArchAngelDay, Daniel Miessler, and many more. more
The key to succeed in bug bounty. An interview with hacker and content creator NahamSec. more
AWS Security Series: IAM Vulnerable. Learn how to create your own vulnerable playground using Terraform. Then, learn how to exploit it using 10 privilege escalation scenarios. part 1 | part 2
Chaining our way to Pre-Auth RCE in Metabase (CVE-2023-38646). Metabase is an open-source business intelligence tool that lets you create charts and dashboards using data from a variety of databases and data sources. more | advisory
The Legacy of Stagefright. Every so often a piece of security research will generate a level of excitement and buzz thatās palpable. Dan Kaminskyās DNS bug, Barnaby Jackās ATM Jackpotting, Chris Valasek, and Charlie Millerās Jeep hacking escapades. more
Which Beeās Knees was your favorite? Reply with the number (#1, #2, #3, #4, or #5)!
ļøšŖ Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
š„ Buzzworthy
ā Changelog
Dan has rewritten S3Scanner in Go. More features coming soon. more
Jswzl 2023.3.3 features wordlist generation, descriptor highlighting improvements, and more. more
Caido v0.27.2 introduces convert workflows: drag and drop blocks to create complex conversion pipelines. more
gwen001/cloudflare-origin-ip v1.1.3 tries to find the origin IP of a webapp protected by Cloudflare. more
owasp-amass/amass v4.1.0 is an in-depth attack surface mapping and asset discovery. more
š Events
NahamSec will be telling a few spooky bug bounty stories at Truffle Secās Capfire Security Stories in Vegas. more
STĆK will be a first time speaker at DEFCON with the talk Weaponizing Plain Text: ANSI Escape Sequences as a Forensic Nightmare. more
Join Bugcrowd at the Chandelier Bar at the Cosmo on August 10th from 7-9 PM PST. more
š Celebrate
d3mondev is feeling hyper focused after almost 4 weeks of running every day and eating healthier. Awesome! more
Renniepak is excited to join another Live Hacking Event in Portugal and hack Intel with Intigriti. Go get that MVH! more
Jessica is now a Staff Security Engineer at GoFundMe and Classy. Letās go! more
š° Career
A thread with companies that are hiring for dev rel, designers, and developers. more
Snyff is offering public office hours. Hit him up if you want to talk about careers in security, learning security, etc. more
Consulting versus Internal Security, what are the differences? Which is best? Cybersecurity Meg breaks it down. more
Lawrence on social media and tech Twitter: āit should be a minor part of your life.ā Focus on how to differentiate yourself, technical depth, and your ability to produce. more
ā”ļø Community
Matt reemphasizes how much good stuff is in the two episodes Critical Thinking did on Android hacking. more
Kuldeep spent 12 hours trying to manually exploit a boolean based blind SQL injection because he thought SQLMap couldnāt exploit it. Spoiler alert: it could. more
You can reach DEFCON staff during normal hours of operation to anonymously report any behavior violating our code of conduct or to find an empathic ear by calling + 1 (725) 222-0934. This year weāre also available via Signal and Discord(@defconhotline).
STĆK and Sara are closing their sustainable fashion store and moving up north. Build a house, repair a barn, care for a forest, maybe farm some land and slow things down. more
SickSec is setting up a Discord server exclusively for the Moroccan hacking community. more
š° Read
Greg shares the behind the scenes when Yahoo dropped a 0day on itself as a response to CVE-2007-3147 and 3148. more
How Secrets Leak in CI/CD Pipelines. Continuous integration/deployment (CI/CD) workflows typically require developers to provide valid credentials for the third party resources their pipeline interacts with. more
From IT Support to Bug Bounty Hunting: A Journey into Cybersecurity with CJ Fairhead. more
One Bug at a Time: In depth analysis of 3 IDOR bugs. more
Serverless Functions Post-Mortem. Around 2016, the term āserverless functionsā started to take off in the tech industry. In short order, it was presented as the undeniable future of infrastructure. Itās the ultimate solution to redundancy, geographic resilience, load balancing and autoscaling. more
š Support
Enjoy reading the Hive Five? You can treat me to a coffee!
You can also share the newsletter with your friends.
š” Tips
šÆ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@n00py1 | n00py | Retweeter of InfoSec/Offsec/Pentest/Red Team. Occasional blogger/Independent security research.
@garrytan | Garry Tan éåå “ | President & CEO @ycombinator āFounder @InitializedāPM/designer/engineer who helps foundersāYouTube creator.
@RayRedacted | Ray [REDACTED] | He/him | Assoc Producer Emeritus: @DarknetDiaries Cybersecurity Researcher.
@joohoi | Joo N/A // @[email protected] | Hacks for beer. FOSS, infosec and privacy. Chaotic good. Managing a red team at @visma.
@JemYoung | Jem Young | Engineering Manager - Web Platform @Netflix. Co-host of @FrontendHH. Instructor on @FrontendMasters. Taller in real life.
š Productivity
TIL you can put apps, files, and folders in the finder toolbar. Just hold the command key and drag it on the toolbar. more
A sneak peek at Obsidianās newly introduced properties in YAML frontmatter. Currently only available for Insiders. more | related
Why Canvas is great in Obsidian ā This video blew my mind. I had no idea these things more
How to stay healthy when life gets busy (as a software developer) by bashbunni. more
š Technology
Esther opens up about her Twitter > X experience. I particularly liked this quote: āElon has an exceptional talent for tackling hard physics-based problems but products that facilitate human connection and communication require a different type of social-emotional intelligence.ā more
How to run a Developer Twitter Space: what to do before, during, and after. more
Worldcoin: a solution in search of its problem. āHaving my eyeballs scanned by a shiny chrome orb so I can someday receive cryptocurrency disbursements because artificial intelligence has stolen my job sounds like something from the pages of a half-baked sci-fi novel.ā Molly writes. more | related
How to deal with fatal: bad object HEAD in git ā for when you have to tame the mythical git creature. more
Apple already shipped attestation on the web, and we barely noticed. Thereās been a lot of concern recently about the Web Environment Integrity proposal, developed by a selection of authors from Google, and apparently being prototyped in Chromium. more
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. Itās my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
š§ Wisdom
David on the difference between pixels on a screen and experiencing and doing the real thing ā Robin Williams in Good Will Hunting puts it perfectly. more
A great illustration showcasing that hard decisions result in an easy life. more
Megās powerful mantra: āI will not let my past traumas dictate my future.ā more
How to improve your standing in life: wake up early and work out, invest your free time to build a marketable skill, and live well below your means. more
Michael Phelps: think small to accomplish big things. more
š Cross-pollination
Sam Berns philosophy for a happy life. He was diagnosed with Progeria, a rare, rapid aging disease, at the age of 2. more
Listenlater.fm generates a personalized podcast feed for you to listen to. You let it know about articles youād like to read later. When you do, it adds a spoken version of the article to your feed for you to listen to whenever your ears are free. more
Gangsta Lorem Ipsum dummy text generator. more
The proper way to roll a burrito ā I had no idea! more
Steven Deobald: Vipassana for Hackers. In this talk, Steven attempts to create relatable contexts and analogues to describe these mechanics with the objective of making the material accessible, even for those who have never tried meditating before. more
š Fact
Types of mead:
BALCHE/PITARILLA: mead fermented with the bark of the balche tree
BRACKET/BRAGGET/BRAGOT: beer mixed with honey or mead
CAPSICUMEL: mead fermented with chili peppers
CHOUCHENN: mead produced in Brittany, sometimes with fresh sea water
CYSER: fermented apple and honey
CZWORNIAK/DWOINIAK/POLTORAK/TROINI-AK: types of Polish mead with a varying ratio of honey to water
HYDROMEL: weak mead
MELOMEL: mead with added fruit
METHEGLIN/METHEGLEN: mead with spices or herbs
MULSUM/OMPHACOMEL/PYMENT: grape wine sweetened with honey
RHODOMEL: mead fermented with roses and honey
TEJ: a mead made by Ethiopians, to which powdered leaves and bark are added
This bee fact is brought to you by The Beekeeperās Bible: Bees, Honey, Recipes & Other Home Uses.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- ā¢ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- ā¢ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- ā¢ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- ā¢ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- ā¢ Deep DISCOUNTS on paid content.
- ā¢ Experience continuously added NEW BENEFITS.