- Hive Five
- Posts
- ๐ Hive Five 164 - Craftsmanship is timeless
๐ Hive Five 164 - Craftsmanship is timeless
How to become a Wikipedian, Deception Engineering, and Open-Source Software
Hi friends,
Greetings from the hive!
Toriyama, the creator of Dragon Ball Z, passed away last week. The first time I saw DBZ was in the 90s while vacationing in France. Even though my brother and I didn't speak the language, we were instantly hooked.
What stood out was the craftsmanship. Even Masashi Kishimoto, the creator of Naruto, considered Toriyama his sensei and an inspiration.
I witnessed another form of craftsmanship during my plane ride last week as I watched "Jiro Dreams of Sushi."
The dedication, mystery, and eye for detail were awe-inspiring.
Let's take this week by swarm!
๐ The Bee's Knees
In this comprehensive guide, Reza delves into the world of iOS security from an offensive perspective, shedding light on the various techniques and methodologies used by attackers to compromise iOS devices and infiltrate their sensitive data. HASHNODE
How to Become a Wikipedian in 30 minutes. Have you ever thought about getting started editing Wikipedia, but then decided not to because you were just overwhelmed by the number of policies it felt like you needed to understand? MOLLYWHITE
Hunting for Fortinet CVE-2024-21762: Vulnerability Research for Detection Engineering. Knowing both the affected and patched versions is going to mean a patch diff, but with Fortinet being proprietary software, finding these versions and decrypting them is going to be the first battleโฆ GREYNOISE
How to use Trello as a versatile yearly planner by splitting the year in calendar weeks, yearly and quarterly goals, and leveraging fixed categories. YOUTUBE
This Chrome extension intermittently checks your installed extensions to see if the developer information listed on the Chrome Web Store has changed. If anything is different, the extension icon will display a red badge, alerting you to the change. GITHUB
Which Bee's Knees was your favorite? Reply with the number (#1, #2, #3, #4, or #5)!
๏ธ๐ช Sponsor
Hive Five is the go-to resource for industry professionals, decision-makers, and builders/creators in the security and technology space, providing them with the tools they need to 10x their job to be done.
๐ฏ Last week on the Hive
๐ฅ Buzzworthy
โ Changelog
Waymore v3.3 added a Discord notification webhook. GITHUB
xnLinkFinder v5.1 refines error messages regarding connection issues and ensuring removal of trailing slashes from scope prefixes to avoid double slashes in output links. GITHUB
Fabric v1.1.3 contains multiple enhancements for additional models and easier installation process. GITHUB
Noir v0.13.0 added a Lightweight LexerParser for analyzing the syntax of source code to enable better analysis, and more. GITHUB
A new addition to PortSwigger's XSS cheat sheet by h4nsmach1ne using onformdata. TWITTER
๐ News
HackerOne is kicking off their next Live Hacking event in April. It takes place in Singapore. TWITTER
NahamSec et al are hosting a web app and recon hacking training with HackingHub at Hack Space Con. TWITTER
Google announced its March 2024 core update and new spam policies. This is designed to improve the quality of Search by showing less content that feels like it was made to attract clicks, and more content that people find useful. GOOGLE
Cloudflare announces Firewall for AI. It's an advanced Web Application Firewall (WAF) specifically tailored for applications using LLMs. CLOUDFLARE
๐ Celebrate
Ebrietas earned nearly $150k on Bugcrowd's T-Mobile program. Wow! TWITTER
Ben and Justin both join Caido as advisors. Exciting! TWITTER
Meg completed her first-ever unassisted pull up. Let's fucking go! TWITTER
Ian signed a job offer. Well deserved! TWITTER
After over 5 years of bug bounty and filing almost 2000 reports, Douglas achieved the Insecticide bug for 500 reports closed as resolved. TWITTER
๐ฐ Career
x1m is hiring a Senior Infrastructure Pentester in the Netherlands. TWITTER
In this episode of Day in My Tech Life step into the world of a Data Scientist who previously worked in Tech Sales with Indiana. YOUTUBE
GreyNoise Intelligence is seeking a Deception Engineer to join their team. In this role, you will architect and create hyperrealistic decoys and sensors across their global sensor network to expand and improve threat detection to enrich cyber threat intelligence data. GREENHOUSE
Roasting based on the role that you're applying for, e.g. design. TWITTER
Never work for free, but not all compensation is monetary, e.g. think of portfolio pieces, recommendations/endorsements, and access. TWITTER
๐ Deception Engineer is one of the coolest job titles I've seen.
โก๏ธ Community
Mason enjoys how smooth Caido is, and says it's tough to justify another year of a Burp Suite Pro license. TWITTER
Birb shares why they left the Hack The Box community. TWITTER
While STรK enjoys Caido and the community's attention, he's still happy with Burp. TWITTER
d0nut is in love with Caido's workflows. TWITTER
Jswzl is hopeful that there'll be a plugin for Caido soon. TWITTER
๐ฐ Read
Corben on an attack surface being larger than you'd expect. He explains how to find network misconfigurations and publicly accessible internal assets. TWITTER
Using form hijacking to bypass CSP. The idea is you have a HTML injection vulnerability that is protected by CSP. PORTSWIGGER
A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass. WHITEKNIGHTLABS
Key tools and approaches for using AI in OSINT and investigations. SUBSTACK
๐ก Tips
Paul hits us with another one-line leveraging subfinder, dnsx, httpx, and katana. TWITTER
Justin shares a CSS injection tip: "CSS import statement don't have to be at the top of a style sheet, if the CSS injection sink is insertRule." TWITTER
TIL that CyberChef is developed by the UK's intelligence, security and cyber agency. Also, version 10 just dropped. TWITTER
When directory brute-forcing, never filter based on status code, says Corben. TWITTER
Corben on directory brute-forcing based on framework, using different HTTP methods. TWITTER
๏ธ๐ช Become a Premium Member
Hive Five is an authentic, hand-crafted, human-written weekly newsletter that is free, but not cheap. Consider supporting my work by becoming a paid member for just $8.25 p/mo ($99 p/yr).
โ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
โ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
โ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
โ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
โ Deep DISCOUNTS on paid content.
โ Experience NEW BENEFITS continuously added.
๐ฏ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@ShawarkOFFICIAL | Shawar Khan | Just a guy who breaks into web like a .357 bullet. Security Researcher | Red Team Member at @synackredteam | Synack Acropolis | Acknowledged by Top Tech Giants.
@CyberSecRicki | The Infosec recruiter - Ricki Burke | Champion for neurodiversity. Founder of CyberSec People. Host of Hacking into Security podcast. Co-organiser of SecTalks_GC and @BSidesGC.
@bitquark | bitquark.
@kyliestew | Kylie Czajkowski | growth engineering manager @vercel โข ambassador @notionhq โข avid hiker โข fan of dogs, mountains, javascript, open source โข she/her.
@turakbusra | Busra | Cyber Security | OSCP | Bug Hunter | Researcher @SynackRedTeam.
๐ Productivity
Projectable is a highly configurable TUI project manager. You can do everything your project needs from a comfortable and smooth interface. GITHUB
Plumber is a no-code solution that helps public officers automate their repetitive tasks and eliminate human error, so they can focus on their more important work. It supports a growing list of both government and commercial apps and services. GITHUB
How to take notes when you suck at it. In this episode of the Bug Bounty course, Katie talks about the importance of developing a personal note-taking system that supports both hacking and learning. YOUTUBE
Chris Titus shows off his new desktop featuring Wayland, Hyprland, and Systemdboot. YOUTUBE
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. It's my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
๐ Technology
Puter is an advanced open-source desktop environment in the browser, designed to be feature-rich, exceptionally fast, and highly extensible. GITHUB
xh is a friendly and fast tool for sending HTTP requests. It reimplements as much as possible of HTTPie's excellent design, with a focus on improved performance. GITHUB
termbot is a CLI tool for interacting with GPT, analyze local files, and more. GITHUB
Download tipsheets and audio recordings from sessions at the 2024 NICAR data journalism conference. IRE
Swyx says that every AI engineer should be building their own therapist using voice. TWITTER
๐ง Wisdom
Bashbunni shares things you can do instead of doomscrolling on your phone, such as playing board games and having a cooking party. TWITTER
TIL about Rejection Therapy - where you confront rejection until it no longer evokes a fear response and normalizes it instead. TWITTER
Mark Manson on critics: "If you wouldn't ask them for advice, then fuck their criticism." TWITTER
How Derek Sivers suggests you learn JavaScript: learn plain JavaScript, make it stick, and avoid shortcuts. SIVE
Underrated Open-Source Projects that deserve more recognition according to HN. One example from the comments is Bruno, an alternative to postman, that's fully local and syncs to git easily. YCOMBINATOR
๐ Cross-pollination
Why children need risk, fear, and excitement in play โ This was something that was definitely more prevalent and normalized in the 90s. AFTERBABEL
CMโ15 is a tiny studio microphone with a large-diaphragm capsule and groundbreaking features. It's the latest addition to Teenage Engineerings field system, a versatile studio quality, ultra-portable microphone that comes with a built-in professional usb-c audio interface with built-in preamp. TEENAGE
The Case Against CaffeineโReduce anxiety, improve sleep, and effects on productivity. SUBSTACK
Before Macintosh: The Apple Lisa. This is a documentary that explores the history, technology, people, stories and industry influence of this lesser-known personal computer. VIMEO
Discover Open-Source Alternatives to Popular Software. OPENALTERNATIVE
๐ญ Quote
โAlways look ahead and above yourself. Always try to improve on yourself. Always strive to elevate your craft."
๐ ๏ธContinue reading
That wraps up the website version of the Hive Five. Subscribe now and access the following must-see sections (tools, resources, watch, listen) in the upcoming newsletter.
Donโt want to miss out? Get access today. Elevate your experience with a premium membership, granting you exclusive entry to the Hive Archive, and unlocking a host of additional benefits.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- โข Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- โข Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- โข EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- โข MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- โข Deep DISCOUNTS on paid content.
- โข Experience continuously added NEW BENEFITS.