- Hive Five
- Posts
- 🐝 Hive Five 160 – Sisyphus and the Impossible Dream
🐝 Hive Five 160 – Sisyphus and the Impossible Dream
The HTTP Garden, Rust Won't Save Us, and Work on Interesting Problems
Hi friends,
Greetings from the hive!
Over the weekend, I shared the Bee-side of this newsletter. Now, you can discover hundreds of curated links that didn’t make it into the weekly Hive Five newsletter.
This idea was inspired by Hive member Monke. Initially, I shared them as a thread on Discord, which then turned into a channel, and is now its own dedicated weekly blog post.
Let's take this week by swarm!
🐝 The Bee's Knees
The HTTP Garden is a collection of HTTP servers and proxies configured to be composable, along with scripts to interact with them in a way that makes finding vulnerabilities much easier. GITHUB | ShmooCon 2024 talk
Sisyphus and the Impossible Dream by Casey Neistat. If you're not familiar with Casey, I encourage you to check out all of his YouTube videos. YOUTUBE
Rust Won’t Save Us: An Analysis of 2023’s Known Exploited Vulnerabilities. HORIZON3
Conditional Love for AWS Metadata Enumeration. AWS has publicly stated that account IDs are not considered sensitive, but in practice, they do more heavy lifting than we’d like to admit. PLERION
Your work can only be as good as your problems are interesting. A lot of people struggle with doing great work and still being unfulfilled, and your problems might be the problem. DANIELMIESSLER
Which Bee's Knees was your favorite? Reply with the number (#1, #2, #3, #4, or #5)!
️💪 Sponsor
Sponsor the Hive Five and reach a highly engaged community of engineers, security researchers, and ethical hackers who are at the forefront of the industry.
🔥 Buzzworthy
✅ Changelog
Fabric 1.0.0 release: fabric is an open-source framework for augmenting humans using AI. GITHUB
Waymore v2.4 release: Find way more from the Wayback Machine. GITHUB
Shot Scraper 1.4: A command-line utility for taking automated screenshots of websites. GITHUB
HackerOne has been cranking out UX improvements and features based on hacker feedback. This one was requested by sw33tLie for sending an email if you get added as a trusted collaborator to a report. TWITTER
📅 News
PentesterLab is thinking of starting a monthly online meetup. TWITTER
MidJourney is getting into the hardware game and hired an engineer from Apple Vision Pro to be the Head of Hardware. TWITTER
After 15 years Microsoft changed their default font from Calibri to Aptos. MEDIUM
Cybersecurity 2024 from Packt. HUMBLEBUNDLE
🎉 Celebrate
it's been a year since STÖK visited Finland and Disobey for the first time. Now, he's presenting on the Main stage. Let's go! TWITTER
d0nut played in two post-bugbash poker tournaments and won them both. Let's go! TWITTER
Mason is back on the grind. 8 bugs pending on HackerOne, and 6 on Bugcrowd. Welcome back! TWITTER
Forbes Spain wrote an article about Bsysop and the team winning the HackerOne AWC. Amazing! TWITTER
Emily joined a new company as a Cyber Security Engineer. Yay! TWITTER
💰 Career
INTERVIEW: How to Become a pentester and teach via E-Sports ft. Davin Jackson. Step into the world of a Cybersecurity API Penetration Tester and E-Sports team owner. YOUTUBE
HIRING: The Microsoft Threat Intelligence Center (MSTIC) is recruiting experienced nation-state threat hunters — with highly honed threat intelligence analysis skills. TWITTER
STORY: Chris shares why they left Blizzard. Buckle up, this is a wild one. TWITTER
⚡️ Community
In response to "What scene in a movie/show will always make you cry?", Alethe shared the saddest scene from my favorite show Halt and Catch Fire. TWITTER
It's the season of Live Hacking Events. After HackerOne and Bugcrowd, YesWeHack's "Hack Me I'm Famous" is up next. TWITTER
Blaklis found an IDOR leaking billing details for all Shopify stores. The community finds the custom CVSS score questionable. TWITTER
Justin on why you should never give Frans a target. A screenshot tells a thousand words. TWITTER
After X amount of years at Bugcrowd, Grant is moving on. During that time, he climbed the ranks from Application Security Engineer to Vice President of Operations. Fun fact: He was the one who reached out to me to join Bugcrowd after a recommendation. LINKEDIN
📰 Read
On January 25, 2024, Microsoft published a blog post that detailed their recent breach at the hands of “Midnight Blizzard”. In this blog post, Andy explains the attack path “Midnight Blizzard” used and what Azure admins and defenders should do to protect themselves from similar attacks. SPECTEROPS
ShapeSecurity's Javascript VM: Part 1. ShapeSecurity's Javascript Virtual Machine(VM) has a remarkable reputation for being extremely hard to bypass and reverse. Their primary clients consist of corporations that require the highest level of security when it comes to protecting their API endpoints. BOTTING
From Concept to Capability: Required Security Changes for Secure AI Agents. The libraries and frameworks for AI systems are pretty immature right now. Most applications are simple chatbots or forms of retrieval. But as we increase the complexity of the use cases, the current architecture won’t be sufficient. JOSEPHTHACKER
💡 TIL
Michael flew 100k miles in the past two years and shares his top rules for traveling by air. Coincidentally, we've also been sharing tips in the Hive Discord. TWITTER
Pieter Levels copy-pasted his successful landing page to all of his products. Contrary to popular belief, whitespace and adhering to design principles did not increase conversion. TWITTER
Grant shares a visualization of a favorite load-balancing technique at AWS called "the power of two random choices". TWITTER
Git has an auto-correct flag. When used, it provides you with X amount of seconds to cancel your action if the correction is not what you want. STEFANJUDIS
People share what industry "secret" they know that most others don't. Some of these are wild. REDDIT
🍯 Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@Gromak123_Sec | Gromak123 Security | French Security Researcher and Pentester at @Unumkey | C|EH Certified | BugBounty Hunter at @YesWeHack & @Hacker0x01|3 times LeHack Bugbounty's Winner.
@irsdl | Soroush Dalili | Appsec Researcher. Works @MDSecLabs.
@johnlestudio | John Lê | Storyteller/Co-creator of GIGA (Vault Comics).
@ayoubfathi | Ayoub FATHI 阿尤布 | Group Vice President of Information Security @noon | Hacker | Entrepreneur | Enjoys building and breaking stuff.
@gardensofalison | 𝒶𝓁𝒾𝓈ℴ𝓃 Product Manager | Mindful Product Manager I talks about finding balance and career growth for early PMs | Building Product Manager Garden.
🚀 Productivity
The Secret Behind Resisting Dopamine. Don’t release too much dopamine too early, you will need it throughout the day. In addition, decrease the need for dopamine, i.e. let go of negative emotions. YOUTUBE
Mischa shares his entire Neovim + Tmux workflow as a DevOps Engineer on MacOS. YOUTUBE
Akita on the benefit of using only one screen: no distraction, good ergonomics, best concentration. TWITTER
Timebox your requests. TLDR: when you ask someone to do something, tell them 1) the maximum amount of time they should spend on it, and 2) whether it’s urgent and important enough to deprioritize other stuff. CRITTER
12 powerful cognitive biases. A "cognitive bias" is a systematic error in thinking that ruins decision-making. TWITTER
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. It's my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
🌐 Technology
Curated list of awesome web apps that work without requesting you to create an account. To save the world from creating user accounts and installing software applications for every damn thing. GITHUB
Hishtory is a better shell history. It stores your shell history in context (what directory you ran the command in, whether it succeeded or failed, how long it took, etc). This is all stored locally and end-to-end encrypted for syncing to to all your other computers. GITHUB
Personal Data Warehouses: Reclaiming Your Data. Every nerd deserves their own personal data warehouse — a system that gives them the same kind of analytical capability that is usually reserved for giant tech companies. YOUTUBE
You’re using AI wrong but it’s not your fault. In this video, Jeff dives into the top 5 mistakes users make with ChatGPT and offer practical solutions to use this chatbot more effectively. From over-specific custom instructions to underutilizing ChatGPT for automation and beyond. YOUTUBE
Why Obsidian is 100% user-supported and not backed by VC investors. (and another reason why I love them). TWITTER
🧠 Wisdom
David Heinemeier Hansson: Constraints Are Your Friends. David reminds the audience of a simple fact: you'll never outdo Microsoft or Google; they will always have more resources than start-ups. YOUTUBE
Pieter created an AI CBT life coach named and modeled after the therapist who helped him a lot during COVID called Cindy that's now free-to-use. TWITTER
Dr. Gurner on a mindset of the possibility of being an early separator in great trajectories. TWITTER
Vortex: "Life is precious and fleeting. Always remember that." TWITTER
💛 Cross-pollination
Multiple Discovery: The Curious Case of Simultaneous Invention. YOUTUBE
5 Fitness Mistakes Made as a Beginner. Patty shares their experiences throughout their fitness journey, this advice will not apply to everyone. YOUTUBE
The Adventure That Saved My Life by Natalie Lynn. Natalie makes cinematic videos that feel like journal entries. YOUTUBE
Vesuvius Challenge 2023 Grand Prize awarded: we can read the first scroll! Take a look at how they did it, what the scrolls say, and what comes next. I previously mentioned this challenge in #114 and #143. SCROLLPRIZE
Amazing picture of birds in a tree by Rajesh Panwar. Nature is forever mesmerizing. TWITTER
🙏 Quote
"Don't delegate understanding. [...] You must recognize the parasite in its earliest form."
Hive Five is an authentic, hand-crafted, human-written weekly newsletter that is free, but not cheap. Consider supporting my work by becoming a paid member for just $99 per year.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.