- Hive Five
- Posts
- π Hive Five 167 - The internet is ours
π Hive Five 167 - The internet is ours
Discover the secrets of LLM security, 9 Ways to Get Ahead of 99% of People, and more...
Hi friends,
Greetings from the hive!
Last week, I started a YouTube channel and published my first video. Check it out!
Iβm also starting to augment myself more with AI, using Simon's brilliant LLM tool combined with Anthropic.
The first task I used it on was summarizing hundreds of link descriptions which would've taken me 1-2 hours. AI enabled me to do it in seconds and it cost me 1 cent.
How could you augment yourself?
Let's take this week by swarm!
π The Bee's Knees
Sophisticate backdoor in XZ Utils allows RCE (CVE-2024-3094): everything you need to know to detect, mitigate, and more. WIZ | MORE 2 | MORE 3 | MORE 4 | VISUAL
Salma on the ridiculousness of pleasing the algorithm: "The internet is ours. It's time to take back control." TWITTER
d3f4ult casually shares a wild piece of lore about themselves. He also has the receipts to back it up, including a Darknet Diaries episode. TWITTER | DARKNETDIARIES
Principal Threat Researcher Tom shares his favorite tools that most are not taking advantage of: Aeon Timeline, Validin, Stairwell, Synapse Enterprise, and GaboRE β I've never heard of any of these, which I find fascinating. He also has an in-depth write-up on how he uses Aeon. TWITTER
Mind Blowing Reverse Shell Demo with DNS data bouncing exfiltration using unconventional methods of exploiting the PowerShell Gallery. YOUTUBE
οΈπͺ Sponsor
Hive Five delivers indispensable insights and resources tailored for security and technology professionals. Our community connects you with field experts, innovative builders, and seasoned decision-makers. Whether you're staying ahead of emerging threats, vetting new tools, or driving strategic initiatives, Hive Five empowers you to operate at the cutting-edge.
π― My work
π₯ Buzzworthy
π News
π Celebrate
TrackPacer got a promotion. Let's go! TWITTER
0verw4tch received their first critical bounty for a sensitive information disclosure vulnerability. Congrats! TWITTER
Max reached the top 100 all-time on Intigriti. Amazing! TWITTER
Zseano is back to coding and content creation mode. Looking forward to it! TWITTER
π° Career
Graham on bullet proofing your career: be as technically competent as you can and make yourself known. TWITTER
The article discusses strategies for hiring low-experience, high-potential individuals and the value they can bring. WORKTOPIA
The Science of 7 Figure Salaries: 9 Ways to Get Ahead of 99% of People. The video shares career advice that truly makes a difference, offering insights for professionals starting out. YOUTUBE
Eugene discusses the importance of communication skills in the cybersecurity field, offering valuable insights for professionals. YOUTUBE
Cure53 is expanding their team. They're looking for an editor to polish 60-120 report pages per week. TWITTER
β‘οΈ Community
TracketPacer shares an insane work story. Holy shit! TWITTER
Jason is working on some dope designs for Arcanum. TWITTER
XNL-H4ck3r is loving the Neo Miami EP by MachineCode. TWITTER
Dope albums to listen to in their entirety by infosec Twitter. TWITTER
Is Burp Suite going downhill lately? The consensus of the responses is yes. TWITTER
π° Read
Daniel tracks 10,000 bugfixes in 10,000 days, demonstrating curl's commitment to quality and stability. These bugfixes happened thanks to 3,134 contributors, out of which 1,252 persons have authored commits merged into the curl source repository. HAXX
PHP is not known for its speed, but Florian decided to enter the "The One Billion Row Challenge" and wanted to see how fast it can get. Spoiler alert: he went from 25 minutes to 12.73 seconds. DEV
Gi7w0rm explores the mechanics and implications of browser fingerprinting. They focus on of VexTrio, a malicious TDS (Traffic Distribution System), which makes use of 29 different functions to check the legitimacy of a visitor who visits an infected webpage. GI7W0RM
Discover how to pan for gold by sifting through network logs to write a new tag. Brianna pulls the curtain back a little bit on how they find and tag on less popular internet traffic. GREYNOISE
π‘ Tips
Mason having success with mcipekci's advice: "If you find 1 sql injection, there's a strong chance there is more." TWITTER
The latest LLM plugin by Simon, llm-cmd, lets you run a command to to generate a further terminal command, review and edit that command, then hit enter to execute it or ctrl-c to cancel. SIMONWILLISON
TIL that Angular's ngInit can be used as a CSS class. TWITTER
π Simon might be one of the most effective engineers I've ever witnessed, and heβs sharing everything in public. His writing, coding, and sheer output just leave me in awe. Protect him at all cost!
π― Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@Mik317_ | Michele Romano | "The walls of Sparta are the chests of its warriors" - Agesilao
@dan_abramov | Π΄ΡΠ½ | welcome to my island
@SwiftOnSecurity | SwiftInSecurity | computer security person at a place. former helpdesk. they/them/tay. Microsoft MVP, Client Security.
@BanjoCrashland | Jason Blanchard | Storyteller. Christian. Husband. Father. Author: I Am Whale Man. Black Hills InfoSec: Excitement Co-Creator. REKCAH! Comics: Co-Publisher.
@k_v0 | vishnu.
π Productivity
Quartz is a simple second brain and digital garden project hosted on GitHub. GITHUB
rez0 demonstrates how to supercharge Vim and enhance bug bounty recon using AI-powered tools and techniques. YOUTUBE
BookPecker provides bullet point summaries of thousands of books, helping readers discover their next read. BOOKPECKER
The author showcases the best tasks plugin in Obsidian, enhancing productivity and task management. YOUTUBE
How to Create Custom Fabric Patterns. A quick tutorial on how to create custom Patterns (AI Prompts) using the Fabric framework. YOUTUBE
π For tasks in Obsidian , I've been using Dataview. It's not as feature-rich as the tasks plugin, but useful enough. It's basically the swiss-army knife.
Get $200 to try DigitalOcean. Level up your bug bounty game with the ultimate VPS solution. It's my go-to for all recon, automation, and even VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
π Technology
Optimizing JavaScript for performance can yield significant improvements, as the author shares common techniques. ROMGRK
Google's blog discusses preventing cross-service UDP loops in QUIC. Infinite loops between servers are something that must be carefully avoided to prevent performance degradation or network overload. GOOGLE
Semgrep's rewriting capabilities, enhanced by LLMs, enable powerful AutoFixes that can revolutionize code maintenance. CHOLY
Emerge tools is breaking down why the LinkedIn iOS app is half a GB. TWITTER
Explore the official Apple Developer YouTube channel. YOUTUBE
π§ Wisdom
Alex on breaking out of self developed barriers by experiencing things you thought were not possible. TWITTER
The Harvard Commencement 2018 speech by graduate speaker Pete Davis addresses graduates with inspiring words. YOUTUBE
Not every day needs to be a big day. YOUTUBE
Explore the daily life in March of a family in a small village in Germany, including garden clean-up, cheese potatoes, geocaching, and DIY orange candle making. YOUTUBE
Ryan on surrounding yourself with people smarter than you. TWITTER
π Quote
"figure out what youβre good at without trying, then try"
π Cross-pollination
Are you flying Boeing? Boeing's been in the news for all the wrong reasons lately. Check your flight number and see your fate. AMIFLYINGONABOEING
I was looking for easily to carry bags and stumbled upon Flip & Tumble. They offer stylish, modern, and reusable bags, backpacks, and purses for eco-conscious consumers. FLIPANDTUMBLE
Exploring the link between ADHD and obesity, providing insights for those affected. YOUTUBE
Witness a day in the life of a dishwasher at a top NYC restaurant. YOUTUBE
The Anxious Generation: How the Great Rewiring of Childhood is Causing an Epidemic of Mental Illness. TWITTER
π I love day in the life videos. There's something endlessly fascinating and intriguing being able to experience someone else's life.
π₯ Now, letβs get into the good stuff. I cover the latest tools, in-depth resources, and the best things I've watched and listened to this week.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- β’ Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- β’ Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- β’ EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- β’ MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- β’ Deep DISCOUNTS on paid content.
- β’ Experience continuously added NEW BENEFITS.