- Hive Five
- Posts
- π Hive Five 201 - Egoless Engineering
π Hive Five 201 - Egoless Engineering
Publish your work and change your life, Handling Cookies is a Minefield, A Geolocation Challenge that took 7 years to solve, and more...
Hi friends,
Greetings from the hive!
Throughout this road trip, it became more and more apparent that I strongly prefer to live outside of (big) cities.
This brings us to other non-negotiables, such as direct access to nature. Being active outside heals most of my wounds and hones my thoughts.
In such environments, it also encourages me to go outside.
Speaking of optimal environments, I've also started to simplify my PKM system and workflows to make them more effective.
Let's take this week by swarm!
π The Bee's Knees
An inspirational talk by Aaron called "Publish your work, change your life." MORE
Egoless Engineering: "One big thing that a lot of people love to do is create new role types. For any new thing a company wants to do, the tendency is to put up a new job description." MORE
SecHub (Mercedes-Benz Group) is a free and open-source security platform that provides a central API for testing software with various security tools, both free and open-source as well as proprietary. MORE
Handling Cookies is a Minefield: "What servers SHOULD send and what browsers MUST accept are not aligned [...]" MORE
It has taken well over 7 years before this geolocation challenge was resolved. Sector breaks down how they did it. MORE
Brought to you by β
Hive Store: For Hackers Who Get It
Wear the gear the community is whispering about.
Our merch isn't just clothingβit's a statement piece that shows the world that you hack a life you love.
Think witty AI jokes that'll make engineers buy you drinks. Privacy puns so sharp, the EFF would high-five you.
Join the cross-pollinators already flexing these conversation-starting pieces.
Upgrade Yourself β
You're getting the free version. Members get more β including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Table of Contents
π° Updates
π― My work
Excited to share the revamped High Five Partnership Program for 2025!
From brand visibility to community impact, we offer dynamic sponsorship tiers to match your goals. See how your brand can thrive with the Hive.
β Changelog
PayloadsAllTheThings 2024.2 reached a major milestone: 8 years of progress and a new beginning. The first release of PayloadsAllTheThings as an Ebook on Leanpub. MORE
The color orange is displacing blue as the dominant hue in the tech industry, think: mymind, Perplexity, Claude, and more. MORE
@HackingDave on cybersecurity automation with AI/LLMs starting to become and will be one of the most desired skill sets in the next 3-5 years in all of security. MORE
XINTRA is actively seeking new trainings for targeting blue/red teams. They offer payment and all trainings will be assessed by their Review Board. MORE
πΌ Work
π° Career
The Cold Email Handbook outlines a playbook for growing a startup through personalized outbound campaigns, from infrastructure to launching scalable campaigns. MORE
The fastest way to kill your business is through tolerance. Write down what excellence looks like. MORE
5 Steps to Start Making $10k/Month Writing Online. MORE
Cybersecurity career paths, including certification roadmaps, domain overviews, and career maps to guide aspiring professionals in navigating this dynamic field. MORE
A masterclass in writing better landing pages, positioning your brand and products, and building features that customers want. MORE
π Productivity
A markdown-like language for plainly recording logs, charts, blogs, journals, and other time-based content. A versatile tool for chronicling one's life and work. MORE
Neovim users share their coolest keymaps, including Folke himself! MORE
This session walks through how to get the most out of Linear, shares strategies to onboard your team, and guides the setup of key features. MORE
Yearly reflecting on one's past experiences can unveil recency bias; a more balanced approach involves progressive summarization across daily, weekly, and quarterly intervals. MORE
π Community
π Celebrate
The Centre for Information Resilience is dedicated to exposing human rights violations and threats to democracy through open-source investigations and research. Worthy cause! MORE
Critical Thinking - Bug Bounty Podcast celebrates 100 episodes, but also bids farewell to co-host Joel, who will be leaving the show. Thanks for all you've done Joel! MORE
After complications from major surgery months ago, Meg is back in the gym 5-day-a-week. LFG! MORE
@nahamsec finding has prompted a software update that will reach millions of devices, a testament to the impact of their work. Awesome! MORE
β‘οΈ Timeline
Rami Tawil (@drunkrhin0), a talented hacker, was born with an insatiable curiosity and a deep desire to understand how systems work, even if it meant breaking the rules. MORE
@ctbbpodcast on how to run a successful bug bounty program that hackers will enjoy hacking on, including tips on program setup, engagement, and rewards. MORE
Shift by @rez0__ and @rhynorater enhances your hacking with AI-powered automation in @CaidoIO. You can sign up for the beta waitlist. MORE
@monkehack demonstrates using voice with Shift (AI HTTP proxy), with a Stream deck executing hotkeys for Shift, dictation, and enter after a few seconds. MORE
After 5.5 years at Google, @raizamrtn (NotebookLM lead), is leaving to build something new. MORE
π Level up
π° Read
A lightning-fast journey from Guest User to Account Takeover. Plugins and in-depth techniques to facilitate the enumeration of the target and the discovery of Salesforce Experience Cloud vulnerabilities. MORE
The fall of Silk Road has not diminished the demand for illicit substances, as people continue to seek out dark web marketplaces for their needs. The intent of this article is to shed light on its security model as a technical curiosity. MORE
The Great Google Password Heist: 15 years of hacking passwords testing their security (and build team culture!). MORE
A critical vulnerability in Kemp's LoadMaster Load Balancer allows remote exploitation through the Web User Interface, enabling full system compromise without any authentication. MORE
RyotaK discovered that the OpenWrt firmware is built using an online service, allowing for a supply chain attack via a truncated SHA-256 collision and command injection. MORE
π‘ Tips
Exposed Internal PKI Infrastructure Detection nuclei template. MORE
Stop fighting your natural tendencies. Embrace them and use them to your advantage. Fighting them is like being a sprinter forced to run marathons β exhausting and futile. MORE
Crowd-sourced best tech, workout gear, boots, knives, and belts from 50 acquaintances, intending to help others find superior goods for the holiday season. MORE
What steps to take if you were to win $656 million in the lottery. MORE
An SSRF tip by @ArchAngelDDay to put
req.query.cont:"https%3A%2F%2F
into your @CaidoIO search bar after hacking on a target for a while and see what comes up. MORE
π§ Wisdom
This is one of life's most powerful lessons to learn. One that I'm still trying to master.
Don't wait for the perfect conditions to take action. Just as one wouldn't delay a drive from LA to NY due to potential construction or accidents, one should bet on themselves and take action to solve problems. MORE
Jordan Peterson, a renowned psychologist, exhorts listeners to discipline themselves, pursue meaning over happiness, and avoid wasting their lives. MORE
Step 1. IMMEDIATELY retain an attorney.
Step 2. Decide to take the lump sum.
Step 3. Decide right now, how much you plan to give to family and friends.
Step 4. Don't hire an investment manager.
[...]
The rise of foundation models has incentivized a diversification of skillsets in both software engineering and AI research itself. MORE
π Resources
(Re)Building the Ultimate Homelab NUC Cluster: how to deploy a cluster using proxmox, the hardware setup, and building your own Active Directory Lab environment. MORE
Bellingcat's Open Source Challenge invites users to test their open-source research skills through a series of unlockable challenges. MORE
AI Model Comparison allows you to see and compare every AI model easily. 100% free & open-source. MORE
UEVR: An Exploration of Advanced Game Hacking Techniques. MORE
Awesome list of keywords and artifacts for Threat Hunting sessions. MORE
π Explore
Get $200 to try DigitalOcean β the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
π§° Tools
Nerve is a tool that allows creating stateful agents with any language model of one's choice, without requiring any code writing. MORE
Studio is a lightweight, browser-based GUI client for managing SQLite-based databases like Turso, LibSQL, and rqlite, offering a range of features to simplify database management. MORE
Recon scripts for Red Team and Web blackbox auditing. MORE
QuickSSRF is a plugin designed to integrate with CAIDO and leverage the Interactsh service from ProjectDiscovery. MORE
AutorizePro is an innovative Burp plug-in with a built-in AI analysis module that focuses on unauthorized access detection. MORE
π₯ Watch
The ideas behind Rock-solid curl, their new long-term support curl release branches. How they work, why they do them, how the different from the normal curl releases and so on. MORE
Van spent 3 weeks and $599.47 fixing a dumb playground toy. MORE
A YouTuber and full-stack engineer discusses using Lovable and Supabase to build a SaaS startup, covering product management, web technologies, and client-server architectures. MORE
The remarkable progress of AI is demonstrated by the ability to complete a 60-minute coding task in just 60 seconds, as shown in this podcast episode where an app was built with a single prompt. MORE
@0xtib3rius demonstrates how to hack websites using XML External Entities (XXE). MORE
π΅ Listen
Jarett Dunn, known as StaccOverflow, orchestrated a dramatic heist dubbed the "Stacc Attack", stealing millions from a website called Pump Fun. MORE
Bolt.new, Flow Engineering for Code Agents, and >$8m ARR in 2 months as a Claude Wrapper. The Stackblitz and Qodo CEOs dish on building production coding agents, from going viral as the hottest new consumer/low-code agent, to the gnarliest enterprise deployments for code/test agents. MORE
π Technology
exo is a project that allows running an AI cluster on everyday devices like iPhones, iPads, Android, Mac, and Linux, forgoing the need for expensive NVIDIA GPUs. It aims to unify one's existing devices into a powerful GPU. MORE
Elastop is a terminal-based dashboard for monitoring Elasticsearch clusters in real-time. MORE
Writing down (and searching through) every UUID. MORE
Next-level frosted glass with backdrop-filter. MORE
Learn everything you need to start writing Lua in 30 minutes. MORE
π Interesting
π Quote
"The sure sign of an amateur is he has a million plans and they all start tomorrow."
π Learned something?
Upgrade Yourself β
You're getting the free version. Members get more β including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Share Hive Five β
Share this newsletter with your friends and colleagues.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
Until next week, take care of yourself and each other,
Bee π
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.