- Hive Five
- Posts
- π Hive Five 181 - What the Dying Teach the Living
π Hive Five 181 - What the Dying Teach the Living
Innovative Recon Tool: Lemma, AI Tooling for Software Engineers in 2024, Embrace Action Over Perfection, 12-Minute Foundation Training, and more...
Hi friends,
Greetings from the hive!
I'm excited about several new projects I'm working on, one of which is an Obsidian blog series. I've been using it since its inception and look forward to sharing what I've learned.
But here's the rub: I'm allergic to the last 10%. You know, the tedious stuff - posting, sharing, crafting the perfect hashtag that makes Gary Vee weep with envy.
Now, I'm exploring whether AI is the medicine.
But enough about me. What have you been up to? Are you building, learning, or just going with the flow?
Let's take this week by swarm!
π The Bee's Knees
Lessons learned in 35 years of making software. Itβs more about soft skills than technical skills. MORE
One of the most innovative tools I've seen: Lemma β a Python-based AWS Lambda package and client designed to execute packaged command-line tools in a scalable, remote environment on AWS Lambda. MORE
Unveiling TE.0 HTTP Request Smuggling: Discovering a Critical Vulnerability in Thousands of Google Cloud Websites. MORE
Gooby, a former neurosurgeon with 20 years of training and experience, left his career due to dissatisfaction and ethical concerns about the effectiveness of his work. He discovered that lifestyle factors like diet, exercise, and stress management were more crucial for patients' recovery than surgeries. MORE
Panic! at the SWE Job Market: "When did developers stop being part of the actual product creation process and instead just become project management task workers?" MORE
Hive Five is a weekly newsletter with the best of technology and security, thoughtfully curated, and read by thousands of hackers. Do you have a product or service to promote? Find out more about advertising in Hive Five.
π° Updates
π― My work
#TIL about git -C
β The Notorious B.E.E. π (@securibee)
10:19 PM β’ Jul 10, 2024
β Changelog
GAP-Burp-Extension v5.4 is a powerful Burp Suite extension that helps you find potential endpoints, parameters, and generate a custom target wordlist. MORE
xnLinkFinder v6.4 is a powerful Python tool that discovers endpoints, potential parameters, and generates a target-specific wordlist to aid in your security assessment. MORE
XnlReveal v3.7 is a powerful Chrome/Firefox browser extension that enhances web security by providing various utilities, including detecting reflected query params, accessing Wayback Machine archives, and interacting with hidden or disabled elements. MORE
Retire.js 4.4.3 scanner is detecting the use of JavaScript libraries with known vulnerabilities. It can also generate an SBOM of the libraries it finds. MORE.
Pro users of Caido can now access nightly builds to test new features early. MORE
πΌ Work
π Productivity
Slimzsh is a compact and practical configuration for ZSH, the powerful shell. It effortlessly integrates with fasd, a tool that enhances your workflow. MORE
7 actionable tips to end your phone addiction. Including using apps to block other apps, setting automatic focus modes, and replying to messages from a computer instead of the phone. MORE
In this video, you'll learn how to use and customize the Epic Wheel of Life Audit template in Obsidian to get a more holistic view of your life. MORE
Danny shares why Morgen, an impressive calendar tool, has been an integral part of his workflow for the past 3 years. MORE
Configure Neovim for Golang development and set up an LSP, Debugger, and other plugins to write Golang code effectively. MORE
π Community
π Celebrate
John Hammond discussed CrowdStrike's activities on CNN! MORE
Blaklis was awarded a $10,000 bounty on HackerOne for finding two different bugs, worth $6000 and $4000 respectively. Bringing him closer to his goals! MORE
Pwnii and Brumens received a β¬50k reward for finding a bug in a public program. Encourage others to hunt for bugs in public programs as well. MORE
Cyber Kitten is leaving Bugcrowd to start a new director-level role. Congrats! MORE
Mert is on a 2-month streak, discovering 25 critical/high-level vulnerabilities across 11 different programs in June. Impressive work! MORE
β‘οΈ Stories
π Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@tywilson21 | Tyrone E. Wilson | GirlDad. Cover6Solutions & DCCyberWarriors.
@binaryz0ne | Ali Hadi | B!n@ry | DFIR and Adversary Simulation | dfir @ protonmail.
@adrianhetman | Adrian Hetman | Teaching and tweeting about Web3 and Web3 Security | Tech Lead of the Triaging team immunefi.
@RayRedacted | Ray [REDACTED] | β’He/him β’ Assoc Producer Emeritus: DarknetDiaries Cybersecurity Researcher.
@eboda_ | eboda.
β¬οΈ Level up
π° Read
The Wild West of Proof of Concept Exploit Code (PoC). An analysis of CVE-2024-6387 by the Qualys TRU. MORE
AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases. MORE
WhatsUp Gold Pre-Auth RCE GetFileWithoutZip Primitive CVE-2024-4885. MORE.
Writing doesn't just refine your thinking, it can actually help you think in the first place. MORE
Encoding Differentials: Why Charset Matters. The absence of charset information can lead to severe XSS vulnerabilities when attackers are able to change the character set that the browser assumes. MORE
π‘ Tips
Cassidoo's Cleaning Tip: Don't leave the room while cleaning. Put items that don't belong at the door, and focus on finishing the task at hand to avoid distractions. MORE
NoSQL injection can be detected by testing for parameters like $lookup, $unionWith, and $match in your wordlist. This research, credited to irsdl, can help identify potential vulnerabilities. MORE
π§ Wisdom
Embrace action over perfection. Start small, overcome uncertainty, and create more. MORE
The AI Engineer in a nutshell, know how to: 1) program well and 2) use LLMs efficiently. MORE
Peter Thiel on Pessimism: "If you think you're going to win, it doesn't mean you're going to win. If you think you're going to lose, you will lose." MORE
Tracking your work in a journal helps you regain focus and clarity when tackling complex problems, like fixing deployment pipeline permissions. MORE
π Resources
Substrate is a crowdsourced project designed to enhance understanding, communication, and action in order to move humanity forward. MORE
The-OSINT-Toolbox by cqcore β discover links to useful, OSINT, Privacy & OPSEC resources, tradecraft, tools, techniques & tactics. MORE
Crafting an engaging bug bounty brief is crucial for success, as it attracts top talent and drives meaningful results. MORE
The Co-Founder of MorningBrew shares his 6-step process to build a successful newsletter business from scratch. MORE
Ask HN: What is the best way to author blogs in 2024? Consensus seems to be static site generators and a (free) hosting provider such as Netlify or Cloudflare Pages. MORE
π Quote
"The gap between knowing what you want and going after it is where fear thrives. You don't need enough courage for the entire journey. You only need courage for the next step.β
π Explore
π§° Tools
Get $200 to try DigitalOcean β the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
APKscan is a tool that scans decompiled and deobfuscated Android files for sensitive data, helping to prevent security leaks. MORE
This project is a CLI tool for testing various types of captchas including puzzle, text, complicated text, and reCAPTCHA using Python and Selenium. The tool also uses OpenAI GPT-4 to help solve the captchas. MORE
Gigaproxy, unlike the single-host limitation of fireprox, allows you to target multiple hosts at once. MORE.
Graphpython is a powerful Python tool for enumerating and exploiting the Microsoft Graph API across platforms. MORE
The reverse shell is a staple technique in the offensive security industry. In this article, Daniel proposes a new tool "oneshell" to solve some of the problems with existing tooling. MORE
π₯ Watch
What could you create if you had 30 minutes to plan and 4 hours to build? Lindsay Wardell, Dev Agrawal, Ben Hong, and Jason Lengstorf took on the Web Dev Challenge to find out. creation
The Paris Games face deepfakes and misinformation threats. Cybersecurity experts warn about fake documentaries and the growing use of deepfakes to disrupt the world's biggest sporting event. MORE
Reverse engineering the AI of the classic Age of Empires game. MORE
Harry is a master copywriter β and thatβs not hyperbole. With Marketing Examples, heβs taught over 100,000 people how to write copy that rips. Learn how to copy that. MORE
Deathβs Honesty. In one of Long Nowβs most moving talks, Ostaseski began: "Iβm not romantic about dying. This is the hardest work you will ever do. It is tough. Itβs sad and itβs messy and itβs cruel and itβs beautiful sometimes and mysterious, but above all that, itβs normal. Itβs a boat weβre all in. Itβs inevitable and intimate." MORE
π΅ Listen
In a puzzling incident, the founder of Canada's largest Bitcoin exchange, Gerald Cotten, died under mysterious circumstances during a trip to India, sparking allegations of an exit scam. MORE
Explore Scott Galloway's journey to $100M on Hampton's MoneyWise podcast with Sam Parr. Learn about financial sacrifice, entrepreneurship, diversification, and giving back from this serial entrepreneur and professor. MORE
Swyx's Fave Podcasts of 2024 - The Big Reset. MORE
Justin and Sina Kheirkhah talk about the start of Shina's hacking journey and explore the differences between the Pwn2Own and HackerOne Events. MORE
David & Mike revisit the topic of moving the needle to discuss what's working and what's changed. MORE
π Technology
Get a 1Password team account for free to support your open-source initiatives. MORE
AI-powered tools face distinct UX challenges across generative tools, copilots, agents, and chat interfaces. These challenges range from reliability and workflow integration to user control, process visibility, and accessibility for non-expert users. MORE
Starting a home lab for DevOps doesn't require an expensive setup. You can do it for $0 by using free tools and repurposing old hardware. MORE
AI Tooling for Software Engineers in 2024: Reality Check (Part 1). How do software engineers utilize GenAI tools in their software development workflow? more
Embedding Neovim HTML within Obsidian allows for seamless integration of text editing and note-taking, empowering users to harness the power of Neovim in their daily workflow. MORE
π Interesting
A day in the gym with Action Bronson and Joe Rogan. Joe shares his workout routine, focusing on kettlebells and windmills. MORE
12-Minute Foundation Training is a simple solution that gives you the means to change the way you move and correct the imbalances caused by our modern habits. MORE
Feedback on creative work often focuses on minor, unimportant details, rather than the bigger picture, hampering the creative process. MORE
Dead simple, drag & drop websites for anything. Websites donβt have to be so cookie-cutter. MORE
Until next week, take care of yourself and each other,
Bee π
P.S. Enjoy the newsletter? Please forward it to a pal. It only takes 16 seconds. Making this one took 16 hours.
Upgrade Yourself β
You're getting the free version. Members get more β including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, and so much more. See what you're missing.