- Hive Five
- Posts
- š Hive Five 133 - How to Study Bug Bounty Hunting
š Hive Five 133 - How to Study Bug Bounty Hunting
Hi friends,
Greetings from the hive!
Bram Moolenaar, the creator of VIM, passed away on August 3rd according to his family. His software and approach have profoundly impacted my and many othersā journey.
In addition to his work on Vim, Moolenaar was an advocate for ICCF Holland, supporting AIDS in Uganda. Donate now.
Letās take this week by swarm!
CleanShot 2023-08-05 at 22.11.38.png
š The Beeās Knees
HTML Over the Wire - A new web app architecture pattern is being adopted by many popular frameworks. Letās talk about risk! TL;DR: Early web applications made you wait after every click until it could render an HTML response on the server and send it back. more
CSRFing VS Codeās Debug Adapter Protocol. Local debug adapter TCP servers, deployed as part of a Debug Adapter Protocol (DAP) implementation used by VS Code, Visual Studio and other development tools, are vulnerable to cross-site request forgery (CSRF) from malicious JavaScript executed in the IDE userās web browser. more
Hahwul is excited to announce the release of his toy project called āNoirā. Itās a source code analysis tool that identifies API endpoints, methods, parameters, and more within the source code, providing various formats of output. more
How to Study Bug Bounty Hunting. Learning how to hack and applying it to bug bounty can be approached in a variety of ways. While there isnāt a clear-cut path to follow, simply providing a list of recommended resources isnāt always very helpful to all types of learners. more
Leaked Secrets and Unlimited Miles: Hacking the Largest Rewards Vendor. Between March 2023 and May 2023, they identified multiple security vulnerabilities within points[.]com, the backend provider for a significant portion of airline and hotel rewards programs. more
Which Beeās Knees was your favorite? Reply with the number (#1, #2, #3, #4, or #5)!
ļøšŖ Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
š„ Buzzworthy
ā Changelog
HackerOne is letting go of employees. more
ZAP is a founding member of the Software Security Project. more
An insight into the ongoing NCC layoffs by Tib3rius. more
jesseduffield/lazydocker v0.21.1 is the lazier way to manage everything docker. more
Intigriti introduces ranged bounties: a flexible and granular bounty mechanism. This addition provides program editors the ability to define minimum and maximum bounty amounts per severity level. more
š Events
A chance to win a golden ticket to Intelās Project Circuit Breaker vent. more
zomato is running a campaign for SQL injection (50% bonus) on their select assets on HackerOne. more
PentesterLab is doing two workshops at DEFCON. more
NahamSec, Jason Haddix, and STĆK are hosting a meetup on Thursday. more
Betting on Your Digital Rights: EFF Benefit Poker Tournament at DEF CON 31. more
š Celebrate
š° Career
Things you can do as a candidate to stand out when applying for jobs. more
d0nut shares a sad realization: āYouāre seldom rewarded for working hard and long hours, but rather for working on the right high impact work.ā more
Two program/vulnerability management individuals are looking for new roles. more
How to manufacture luck and get your next job. more
How To Become A Penetration Tester. more
ā”ļø Community
Ben on exceeding his DEFCON expectations and achievements. more
Fishing is something that Kyle likes doing when not researching security stuff. more
Corgi on how fascinating it is how much context in media is lost through time/generations. more
Hackers are getting ready for H1-813 in Tokyo. more
Retired full-time bug hunters share their perspective. more
š° Read
AWS WAF Bypass: invalid JSON object and unicode escape sequences. more
Huawei Theme Manager Arbitrary Code Execution. more
Wiz Research discovers CVE-2023-2640 and CVE-2023-32629, easy to exploit privilege escalation vulnerabilities in the OverlayFS module in Ubuntu affecting 40% of Ubuntu users. more
Donāt you (forget NLP): Prompt injection with control characters in ChatGPT. Like many companies, Dropbox has been experimenting with large language models (LLMs) as a potential backend for product and research initiatives. more
Serverless Functions Post-Mortem. Around 2016, the term āserverless functionsā started to take off in the tech industry. In short order, it was presented as the undeniable future of infrastructure. Itās the ultimate solution to redundancy, geographic resilience, load balancing and autoscaling. more
š Support
Enjoy reading the Hive Five? You can treat me to a coffee!
You can also share the newsletter with your friends.
š” Tips
Check out The Safe Room show by AWS CIRT on Twitch. They talk about security in the cloud, security trends, and more. more
Exploiting SQL injection vulnerabilities is all about your knowledge of the targetās Database Management Systems, reading documentation, and leveraging specific functions. more
šÆ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@0xAshFox | AshF0x // Peer | Just a guy trying to get into CyberSecurity. Teaching myself with books and the internet.
@adamwathan | Adam Wathan | Creator of @tailwindcss. Listener of Slayer. Austin 3:16.
@zeldman | zeldman | Author. Designer. Web Standards Godfather. Employer Brand at @Automattic. Publisher, @AListApart, @ABookApart. Avaās dad. Peteās brother. He/him.
@n7_sec | n7 | Web App Sec | Bug Bounties | OSCP / CRT
@cassidoo | Cassidy | Making memes, dreams, & software!CTO at @contendaco!Married to @ijoosong.I like jokes and mechanical keyboards!She/Her.
š Productivity
Delegation hack: for any task you delegate, have the person record a 3 min video of how they do it. more
7 Habits For Effective Text Editing 2.0. A large percentage of time behind the computer screen is spent on editing text. Investing a little time in learning more efficient ways to use a text editor pays itself back fairly quickly. more
6 key components that make up the perfect formula for ChatGPT and Google Bard: Task, Context, Exemplars, Persona, Format, and Tone. more
Streamline Your Workflow: How A Personal User Manual Can Improve Collaboration. more
How Danny focuses 8+ hours a day. more
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. Itās my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
š Technology
Best tools that you can embed on a webpage where people can submit questions. more
Tuts+ Code (originally Nettuts) is closing ā It was one of the main educational resources Iāve leveraged on my journey. more
Behind āHello Worldā on Linux. What happens when you run a simple āHello Worldā Python program on Linux? more
Run Llama 2 on your own Mac using LLM and Homebrew. more
AI Creativity: Can LLMs Create New Things? Is generative AI output novel creation or simple imitation? more
š§ Wisdom
Stop caring about what you should do. more
š Cross-pollination
š Fact
As knowledge about beekeeping spread, so did the search for more sophisticated forms of beehive. While skeps were still widely used, there was continual experimentation with different types of straw for skep-making and with different types of wooden hive. The chief aim was to create a hive that prevented the keeper from having to kill the bees in order to harvest the honey.
This bee fact is brought to you by The Beekeeperās Bible: Bees, Honey, Recipes & Other Home Uses.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- ā¢ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- ā¢ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- ā¢ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- ā¢ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- ā¢ Deep DISCOUNTS on paid content.
- ā¢ Experience continuously added NEW BENEFITS.