- Hive Five
- Posts
- π Hive Five 162 β Go Go Bug Bounty Gadgets
π Hive Five 162 β Go Go Bug Bounty Gadgets
How to use Fabric (AI augmentation), Top 10 Hacking Techniques, and more
Hi friends,
Greetings from the hive!
I can't believe how much of a pain it still is to get a new phone in the year 2024. To be fair, I went into a store, so mileage may vary.
Once that's done, transferring your data and apps, including 2fa and whatnot, can be quite the challenge.
I thought I was prepared but then I ran into Google asking me to confirm access to G-Suite using my old phone or Google Authenticator, neither of which I still had access to.
But...we did it...
Let's take this week by swarm!
π The Bee's Knees
In this episode of Critical Thinking - Bug Bounty Podcast Justin and Joel discuss the concept of gadgets and how they can be used to escalate the impact of vulnerabilities. They talk through things like HTML injection, image injection, CRLF injection, web cache deception, and more. YOUTUBE
This video introduces Fabricβan open-source project for augmenting humans using AI. It provides a modular framework for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere. YOUTUBE
Top 10 web hacking techniques of 2023, the 17th edition of the annual community-powered effort to identify the most innovative must-read web security research published last year. PORTSWIGGER
A collection of full-stack resources for programmers. The goal of this page is to make you a more proficient developer. You'll find only resources that the curator found truly inspiring, or that have become timeless classics GITHUB
Go Go XSS Gadgets: Chaining a DOM Clobbering Exploit in the Wild. The takeaway is to keep track of origins, headers, CSP rules, and JavaScript files in your Burp state when youβre bug bounty hunting. BUER
οΈπͺ Sponsor
Hive Five is the go-to resource for industry professionals, decision-makers, and builders/creators in the security and technology space, providing them with the tools they need to 10x their job to be done.
π― From the Hive
π₯ Buzzworthy
β Changelog
xnl-h4ck3r urless v1.3 release added a new arg -fnp/--fragment-not-param to not treat URL fragments # in the same way as parameters. GITHUB
DOMPurify 3.0.9 release is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. GITHUB
YesWeHack unveils workflow-friendly revamp of user interface. YESWEHACK
π News
iOS ARM64 Reversing and Exploitation course by InverseCos and Billy. It has 84 videos, 18 labs, and over 40 hours of content. XINTRA
Get ready for the first BSides in Exeter UK. It'll take place in July. TWITTER
Monke launched MonkeHacks β a short curation of bug bounty progress, notes, resources, and ideas. TWITTER
Canada wants to ban the Flipper Zero. Save Flipper says that Insecure vehicles should be banned, not security tools like the Flipper Zero. SAVEFLIPPER
ZAP Professional Services? ZAP is looking for ways to increase the number of people able to work on ZAP full time. ZAPROXY
π Celebrate
π° Career
β‘οΈ Community
Sasi running into some issues with the HackerOne platform. TWITTER
Ayoub on staying humble and being grateful after meeting a homeless family. TWITTER
The Twitterverse shares the major changes that have happened in computer security since 2017. TWITTER
Tib3rius left TCM Security due to personal reasons. Hope all is well! TWITTER
Jayesh shares his experience with Netlas[.]io to retrieve asset IPs, subdomains, and associated domains. TWITTER
π° Read
Slides of Halver Flake's RingZer0 keynote: Re-visiting 2017: AI and Security. 7 years later - what changed, what endured? GOOGLE
Nom for Security: A Proactive Security Review of Nomulus. Google's Information Security Engineering (ISE) team proactively reviews products outside of product design/launch lifecycles. GOOGLE
A Chromium bug bounty reports: Attacker Can Execute Arbitrary JavaScript Code in the Highly Privileged "devtools://devtools" Origin. CHROMIUM
CSP bypass on PortSwigger.net using Google script resources. JOAXCAR
Frycos code audited the software product Tableau Server which turned out to be prone to several vulnerabilities in its latest version. All attacks were conducted on a test trial environment against the Tableau Cloud in January 2024. GITHUB
π‘ TIL
The browser auto-converts any <image tags to <img tags. TWITTER
12 different pricing psychology tips β I had no idea about the majority of these! TWITTER
Wikipedians can get SO sick of people making the same edits over and over that they'll add invisible comments that pop up when you try to make a change. Depths of Wikipedia shares several. TWITTER
You can play old games on the Internet Archive. TWITTER
There's a command to create temp directories called mktemp. So, you can do cd $(mktemp -d). TWITTER
π― Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@ShaanVP | Shaan Puri | Inventor of the 2 hour lunchbreak. started 6 companies, 3 failed, 2 sold, 1 still going.
@damian_89_ | Damian Strobel | laravel golang pentesting itsecurity easm bugbountyhunting php webdev websec itsec
@cinzinga_ | cinzinga | Security Consultant | Bug Hunter | OSEP, OSCP + some others.
@IanColdwater | Ian Coldwater | Kubernetes SIG Security co-chair, container escape artist, goose in the mainframe. They/them. Stay punk.
@saamux | Samuel | Iβm learning.
π Productivity
Raycast plugin Dash Off is the fastest way to dash off a quick email to yourself and others. Inspired by Andrew Wilkinson's tweet. RAYCAST
notesGPT generates action items from your notes in seconds. Powered by Convex, Together.ai, and Whisper. GITHUB
How Ali Abdaal manages his time using the 5 Skills of Time Management. YOUTUBE
A first look at Zed, a fast new code editor written in Rust with AI built in. Learn the pros and cons of this promising new developer tool and compare Zed to VS Code. YOUTUBE
How Danny researches in Obsidian. YOUTUBE
π The 5th skill that Ali mentions is following through. It's all about overcoming procrastination and kicking into high gear during that final 20%. To add to this is knowing when to stop. Ship first, iterate later.
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. It's my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
π Technology
JavaScript Bloat in 2024: "Call me old-fashioned, but I firmly believe content should outweigh code size." TONSKY
4 web devs had 4 hours to build a real-time, multiplayer web app that is NOT a chat or drawing app using PartyKit as part of the build. YOUTUBE
How to run a local AI chatbot on Windows in 5 min, no cuts, no edits, with Ollama, LMStudio, OpenAI. YOUTUBE
Let's build the GPT Tokenizer. The Tokenizer is a necessary and pervasive component of Large Language Models (LLMs), where it translates between strings and tokens (text chunks). YOUTUBE
Andrej Karpathy wrote a love letter to Obsidian: "Obsidian is around the state of the art of a philosophy of software and what it could be." TWITTER
π Something interesting that Andrej mentioned on Twitter was that making a video amplifies your message so much more, than just writing.
π§ Wisdom
Bell Labs colleagues Ken Thompson and Dennis Ritchie developed UNIX, a multi-tasking, multi-user operating system alternative to the batch processing systems then dominating the computer industry. YOUTUBE
Cts on the difference between G-suite and a custom stack. TWITTER
David says: "To find your voice as a writer... imitate, then innovate." TWITTER
David on sharing your work: "If you do quality work, you have a duty to promote it". TWITTER
Kelsey says that knowing what he knows now, he would start learning in public as soon as possible. TWITTER
π Cross-pollination
Redditors share movies they consider 100% perfect. Movies they would watch over and over again for many reasons: actors, scripts, lore, myths, and truths. REDDIT
Twitterverse shares their best books with fewer than 100 pages. TWITTER
5. Nathan shares an interesting approach to losing weight while building muscle. He eats the same thing every day in the morning and afternoon, and then he's in such a good spot that it doesnβt matter much what he eats for dinner. TWITTER
Dancing has the largest effect of any treatment for depression. TWITTER
Des made a thread of exceptional writers, such as Paul Graham, Jason Fried, and others. He says: "the thing all of them have is the ability to consistently build on their previous ideas, connecting them all together, delivering the "meaningful learning" that educators often talk about." TWITTER
π Quote
"Some men die by shrapnel, and some go down in flames, But most men perish inch by inch, In play at little games."
οΈπͺ Become a Member
Hive Five is an authentic, hand-crafted, human-written weekly newsletter that is free, but not cheap. Consider supporting my work by becoming a paid member for just $8.25 per month ($99 per year). Check out the perks.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- β’ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- β’ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- β’ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- β’ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- β’ Deep DISCOUNTS on paid content.
- β’ Experience continuously added NEW BENEFITS.