- Hive Five
- Posts
- 🐝 Hive Five 153 - How to Make 2024 The Best Year of Your Life
🐝 Hive Five 153 - How to Make 2024 The Best Year of Your Life
Hi friends,
Greetings from the hive!
Merry Christmas and happy holidays. I hope you're able to spend time with family and friends.
Today's quote in my Obsidian system is a timely one:
"What is important is seldom urgent and what is urgent is seldom important."
— Dwight D. Eisenhower
While writing this, I'm listening to the Blue Eye Samurai soundtrack.
Let's take this last week of the year by swarm!
🐝 The Bee's Knees
rez0 talks about AI Application Security: Understanding Prompt Injection Attacks and Mitigations. YOUTUBE
SMTP Smuggling: Spoofing E-Mails Worldwide. In the course of a research project in collaboration with the SEC Consult Vulnerability Lab, Timo Longin - known for his DNS protocol attacks - discovered a novel exploitation technique for yet another Internet protocol. SEC-CONSULT
Sam shares a blind XSS bug on Apple's iCloud+ that led to a base64 encoded Harry Potter quote on an internal iCloud account debug and administration page. TWITTER
The Security Research Legal Defense Fund aims to help fund legal representation for persons who face legal issues due to good faith security research and vulnerability disclosure in cases that would advance cybersecurity for the public interest. SECURITYRESEARCHLEGALDEFENSEFUND
Blue Eye Samurai: Driven by a dream of revenge against those who made her an outcast in Edo-period Japan, a young warrior cuts a bloody path toward her destiny — Whether you're a seasoned Anime watcher or first-timer, I'd recommend this show to anyone. It's a masterpiece. NETFLIX | SOUNDTRACK
Which Bee's Knees was your favorite? Reply with the number (#1, #2, #3, #4, or #5)!
️💪 Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
🔥 Buzzworthy
✅ Changelog
waymore v1.37 by xnl-h4ck3r: Find way more from the Wayback Machine. GITHUB
knoxnl v2.8 by xnl-h4ck3r release: A Python wrapper around the amazing KNOXSS API by Brute Logic. GITHUB
waymore v2.0 by xnl-h4ck3r release: Find way more from the Wayback Machine. GITHUB
Bugcrowd released v1.12 of the Vulnerability Rating Taxonomy. New additions include AI application security and LLMs. BUGCROWD
🎉 Celebrate
d0nut's channel is eligible to apply to the YouTube Partner Program. Let's go! TWITTER
Rhys is a year older. Congrats! TWITTER
Meg is thankful to work at her current job. Awesome! TWITTER
Tuan passed the $1M milestone on Bugcrowd. Huge congrats! TWITTER
sumgr0 is on a 12-month streak at HackerOne. Woot! TWITTER
💰 Career
From $4 an Hour to Fortune 500 CEO: "I Did What Nobody Else Wanted to Do". YOUTUBE
Making $300/hr as a Cybersecurity GRC SME ft. Miranda Stanfield, CISA. YOUTUBE
The big "secret" about confidence and success. YOUTUBE
shenetworks shares a crappy interview performance and others share theirs. TWITTER
The vuln research team at Rapid7 is hiring for a lead Security Researcher. TWITTER
⚡️ Community
Justin remembers Kris Nóva. YOUTUBE
A vlog of late 2022, when STÖK and P4fg went to Copenhagen for 13371122. YOUTUBE
The 2023 Ambassador World Cup Final: Results, Impact, and Looking Ahead. HACKERONE
Community answers to what people are most proud of doing/being a part of in 2023. TWITTER
STÖK shared his first day of his new minimalistic nomadic life experiment. TWITTER
📰 Read
CVE-2023-43826: Integer overflow in handling of VNC image buffers. This write-up describes the details of an integer overflow vulnerability discovered in Apache Guacamole. GITHUB
Retro Gaming Vulnerability Research: Warcraft 2. NCCGROUP
Facebook Is Being Overrun With Stolen, AI-Generated Images That People Think Are Real. 404MEDIA
Verizon Gave Her Data to a Stalker. ‘This Has Completely Changed My Life’ - “Verizon royally fucked up,” Poppy told me in a phone call. “There’s no way around it.” Verizon, she added, was “100% at fault. 404MEDIA
What Are Server-Side Request Forgeries And How To Exploit Them? Server-Side Request Forgeries (SSRF) vulnerabilities arise when any kind of web service or component (like an app or API) uses your input to craft a request on behalf of the server. NOVASEC
💡 Tips
bashbunni warns us not to buy SanDisk portable SSDs because of their high failure rate. TWITTER
Midjourney v6 text generation tips for the best results. TWITTER
Cobalt is your go-to place for downloads from social and media platforms. zero ads, trackers, or other creepy bullshit. Simply paste a share link and you're ready to rock. COBALT
🍯 Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@shehacks_ke | SheHacks KE | A community of women cyber warriors founded & led by women, looking to bridge the skills and gender gap in InfoSec in Kenya.
@arcwhite | Andy White | Employee #1 and Director of Software Engineering (AU) @bugcrowd. Ruby, infosec, pol. He/him.
@smaury92 | smaury | Co-Founder @ShielderSecCTF Player @JBZTeamCliff Jumping Lover (23mt max so far)@[email protected].
@sw33tLie | sw33tLie | Hacker and CS student, 22yo.Top 50 @ Bugcrowd.
@ddprrt | Stefan Baumgartner @deadparrot@mastodon.social | Author | writes about Rust.
🚀 Productivity
How to Make 2024 The Best Year of Your Life with Ali Abdaal. YOUTUBE
Amanda wakes up every morning and writes from 5-7am. Her 8yo daughter started joining her. TWITTER
Heynote is a dedicated scratchpad for developers. HEYNOTE
Nominate your Obsidian 2023 Gems of the year. You can nominate projects in the following categories: plugins themes, tools, content, vault templates. OBSIDIAN
How to have buckets of time. One of the most important techniques DHH embraced for managing my time is to direct related tasks to a bucket, let that bucket accumulate until full, then empty it all in one go. HEY
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. It's my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
🌐 Technology
A totally comprehensive history of web development and JavaScript frameworks. YOUTUBE
A cool story about how Maria started contributing to Neovim. YOUTUBE
How to use coding AI assistants effectively with Ado Kukic. What can an AI coding assistant do, and what’s the best way to add one to your workflow? YOUTUBE
Ask HN: What's your "it's not stupid if it works" story? Here are two of them: displaying a screenshot full-screen to do GUI manipulations and renaming Google Chrome to firefox.exe just to get it to run. YCOMBINATOR
A collection of Consumer electronics magazine from 1954 to 2003 in several renewed editions. WORLDRADIOHISTORY
🧠 Wisdom
Dr. K teaches us why you need to get better at doing nothing. YOUTUBE
sunil on what we used to call "surfing" has been replaced by "doomscrolling". It's time to take things back in control. TWITTER
"The mark of a novice is wasted movement. They do too much. Experts do less. [...]" says David Perell. TWITTER
Sahil talks about Shoshin, a Zen Buddhist idea that means "the beginner's mind.". This is something we should apply to everything. TWITTER
8 Japanese Techniques to Overcome Laziness. INSTAGRAM
💛 Cross-pollination
Ancient Therapy for Modern Problems: Stoic Philosophy Explained. YOUTUBE
Scarface: Tiny Desk Concert — This one radiates with his decades-long passion as an emcee and producer. It might be my favorite Tiny Desk so far. YOUTUBE
Vincenzo Capuano is a 3rd generation Neapolitan pizza master. He learned “Arte Bianca” — the art of baking (the literal translation is “white art”) — from his grandfather. The dough-making skills are next level. TWITTER
TIL that people get part-time jobs for the employee discount. TWITTER
Tech stuff for Ten-yr-olds. Tech stuff for Ten-year-olds Chromebook; iPad Mini; Kindle Paperwhite Kids; Nintendo Switch. SUBSTACK
🐝 Fact
AUTUMN TASKS (average temperature 41-66°F/ 5-19°C)
The autumn is a time for ensuring the bees that go into winter are well-fed and healthy and their colonies are strong.
These have the best chance of survival until the weather warms up again in early spring. As the outside temperatures fall and brood rearing has finished, the bees begin to form a winter cluster.
There are certain tasks the beekeeper has to do before this happens.
This bee fact is brought to you by The Beekeeper's Bible: Bees, Honey, Recipes & Other Home Uses.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.