- Hive Five
- Posts
- ๐ Hive Five 202 - A Bias to Action
๐ Hive Five 202 - A Bias to Action
New terminal on the block: Ghostty, Neovim tutorial series, Docker fundamentals for hackers, and the Four Quarters productivity method. Recent buzz includes Meta's Llama 3.3 70B model launch and critical findings in Android security vulnerabilities.
Hi friends,
Greetings from the hive!
Crafting digital tools with thoughtful design and attention to detail creates a truly exceptional user experience.
The art of software development isn't just about functionality - it's about creating tools that users genuinely enjoy using every day.
In addition, they have to be customizable to every user's unique workflow. Some that come to mind are Obsidian, Neovim, Tmux, and soon Ghostty.
Each of these tools shares a common thread: they were created by developers who deeply understand their users' needs and workflows.
Let's take this week by swarm!
๐ The Bee's Knees
Burp Suite extension Burpference allows you to capture in-scope HTTP requests and responses from Burp Suiteโs proxy history and ship them to a remote LLM API in JSON format. MORE
Citrix Denial of Service: Analysis of CVE-2024-8534. Assetnote is back, this time to look at a patch for yet another memory safety vulnerability. MORE
Documentary on Hackers Who Get Paid to Hack Companies. Cybernews interviewed Bryce (@YTCracker), Ben (@NahamSec), Sam Curry (@Zlz), Frederik (@STรK), Neiko (@Specters), Vanya (@BusesCanFly, Phoenix (@LilRed), Andrรฉ (@0xacb). MORE
As Facebook rapidly scaled to a billion users, the company struggled to maintain focus on Zuckerberg's original vision, leading to the codification of their story into a Little Red Book. Which they distributed internally. MORE
The WorstFit Attack is a vulnerability affecting Windows ANSI executables, exposing hidden transformers. This research provides a list of all executables vulnerable to the attack. MORE
Brought to you by โ
Hive Store: For Hackers By Hackers
Support the Hive by becoming a swag wearing cross-pollinator
Hack a life you love in style. Weโve got shirts, hats, mugs, mouse pads, and more.
Think witty AI jokes that'll make ChatGPT chuckle. Privacy puns so sharp, the EFF would hive five you.
Join the cross-pollinators already flexing these custom swag items.
Upgrade Yourself โ
You're getting the free version. Members get more โ including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Table of Contents
๐ฐ Updates
๐ฏ My work
A sneak peek of something Iโve been working on called the โExperience Engineerโ. With 53% of customers never returning after one poor experience, the right support ecosystem matters.
I use my 20+ years of experience to help companies build the bridge they need. Providing the following services: Knowledge Architecture, Community-Powered Support, and Self-Service Intelligence.
โ Changelog
Ghostty 1.0, an open-source project under the MIT license, is set for public release in December after nearly two years of development and private beta testing. MORE
I've been following Ghostty terminal on and off for a while. To my surprise, it's going to be publicly released this month!
What I wanted to call out, besides the marvel of engineering, is the level of care and thoughtfulness that goes into it.
The creator, Mitchell, co-founded HashiCorp, and is also behind Vagrant, Packer, Consul, Terraform, Vault, Nomad, Waypoint, and more. Rwxrob and many others put him on their list of software engineers to follow.
An end of an eraโฆI remember moderating Twitch for HackerOneโs H1-2010, the Worldโs Largest Live Hacking Event.
A "Malcolm in the Middle" revival has been ordered at Disney+, with the original cast of Frankie Muniz, Bryan Cranston, and Jane Kaczmarek returning to the show. MORE
๐ผ Work
๐ฐ Career
Nintendo of America seeks a Security Engineer to bolster its cybersecurity posture and safeguard critical systems. MORE
Show and tell of people making $500/month on side projects in 2024. MORE
In 2008, Aaron Swartz wrote actionable advice on "How to Get a Job Like Mine?" MORE
Nearly every organization that is designed to have an impact has a board of directors, whether that's a small non-profit, a giant corporation, or anything in between. Let's find out what they do. MORE
Negotiating one's salary can yield significant gains, as demonstrated by Chloe's $50,000 increase. Here are her effective negotiation tactics. MORE
๐ Productivity
6 habits to make 2025 your best year yet. MORE
"Habit: 1 - Ignoring The Concept of Annual Goals
Habit: 2 - The Weekly Review
Habit: 3 - The Morning Manifesto
Habit: 4 - Focus Logs
Habit: 5 - Standing Order Social Events
Habit: 6 - Multimodality Multitasking."
The Four Quarters Method, outlined by Gretchen Rubin, offers a system to overcome procrastination and boost consistency, promising to skyrocket one's productivity. MORE
This tutorial explores the fundamentals of Neovim's Buffers, Windows, and Tabs, crucial concepts for navigating and organizing the text editor's interface. MORE
Right on time, as I (regrettably) still don't know the difference between the three. I believe I'm using tabs in LazyVim. Mastering ones tools is something that'll pay off in the long run.
๐ Community
๐ Celebrate
After 125 hours of rigorous testing over 56 days, Deev Pal received their first four-digit bounty from one of the largest public bug bounty programs. LFG! MORE
A year of video editing has taken Jexx on a remarkable journey, and they plan to soon share a side-by-side comparison to showcase their progress. Awesome! MORE
@JonathanBouman, a true friend, surprised @zseano with a custom-made kilt after Sean won a kilt and trophies at a recent HackerOne event but did not receive them. #goals MORE
The @DarknetDiaries podcast episode on @RachelTobac was the most listened to in 2024, with a 570% increase in streams over the average episode. Congrats! MORE
The NET GALA, a prominent event, will return in 2025. The organizers are seeking sponsors to make the event grander than the previous year. Exciting! MORE
๐ Follow
Awesome accounts to follow. Randomly selected from my curated Twitter lists.
@bencodezen | Ben Hong | @vuejs core team | senior staff dx engineer @netlify | @nuxt_js ambassador | @GoogleDevExpert.
@simps0n | Renato Rodrigues.
@theflofly | Florian Courtial | Full-time bug hunter.
@JR0ch17 | Jasmin Landry.
@IAmMandatory | RedTeam @Snapchat | Previously @Google, @Uber, @BishopFox. XSS Hunter author, DNS/TLD/web security researcher.
๐ Level up
๐ฐ Read
This article disclosed 7 vulnerabilities, 2 of which pose a threat to Google Pixel devices, while the others pose a threat to all Android devices, regardless of vendor. MORE
Following the recent cleo ITW exploitation, @HuntressLabs has released their analysis of the full post-exploitation chain. MORE
From Template to Threat: Exploiting Freemarker SSTI for Remote Code Execution. MORE
This blog provides an in-depth analysis of the exploitation process for an unauthenticated XXE vulnerability in Ivanti Endpoint Manager, identified as CVE-2024-37397. MORE
This post explores two vulnerabilities discovered in Shiny, the most popular web framework for the R programming language. MORE
๐ก Tips
After you find a WAF bypass (the origin IP in this case), go into Burp Network Connection "Hostname resolution overrides" and add the IP address so you can test as usual. MORE
This one-liner command, augmented by AI, lists the processes listening on network ports, allowing one to identify any potentially orphaned servers running on the machine that could be shut down. MORE
TIL about the Pugh Matrix, a tool for prioritizing tasks. MORE
๐ง Wisdom
Carta CEO memo titled: A Bias to Action, addresses challenges of keeping a growing, and in their case regulated, organization executing with the same relentless and risk-taking spirit of the early days. MORE
Questions are like keys. They unlock doors. Here are several for: decision making, conversation, and business. MORE
After serving 16 years in prison for armed robbery, Wallo, a gifted orator from Philadelphia, harnessed his storytelling abilities to build a multimillion-dollar business and amass a sizable fortune. MORE
โA big cheat code to success is not accepting reality that is given to you. Not the limits, not the ideas of other people.โ MORE
Be relentless: "Rivers don't cut through rock because they are powerful, they cut through rock because they are persistent." MORE
๐ Resources
Security assessment of RubyGems.org, the essential package manager for Ruby applications with over 184+ billion downloads. MORE
A curated list of awesome projects, libraries, and tools powered by Frida. MORE
The Public APIs repository is a curated collection of public APIs from various domains, maintained by the community, offering developers a trove of resources for building their own products. MORE
A simple, free answer to "how do I get started with Rails 8" in the form of a brand-new official tutorials created by Chris Oliver. MORE
๐ Explore
๐งฐ Tools
Get $200 to try DigitalOcean โ the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
Eightify offers an AI-powered service to summarize YouTube videos, saving time by quickly extracting key ideas. Users can either pay for the service or bring their own API key. MORE
My opinion on AI is that it's there to augment oneself. That's why I believe tools such as Eightify will become more and more embedded into our everyday tasks, WHILE we're doing them. Having to go to a separate service is too much friction.
GetMarkdown allows users to convert any file to Markdown format directly within their browser, without sending data to a server. MORE
ParamFinder is a beta tool for discovering hidden parameters straight from Caido. MORE
scrapybara provides API-accessible computer environments purpose-built for AI agents. MORE
SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty. MORE
๐ฅ Watch
Master Docker in Less Than 10 Minutes: The Ultimate Guide for Hackers. MORE
A bug was found in Discord that allowed for remote code execution by sending a message. An intro to V8 exploit development and bug hunting. MORE
Ilya Sutskever, a prominent AI researcher, predicts the end of pre-training as we know it, and the emergence of superintelligent systems capable of agentic reasoning, comprehension, and self-awareness. MORE
๐ต Listen
Shopify's Glen Coates discusses the importance of slowing down and improving software, even if it's not exciting, for the sake of reliability and functionality. MORE
Craig Newmark, founder of the renowned classifieds website Craigslist, joins Theo Von to discuss the origins of his creation and his views on the internet and personal philosophy. MORE
@rez0__ takes over the CTBB pod and discusses AI application vulnerabilities with Johann Rehberger, emphasizing the importance of understanding system prompts and safeguards. MORE
Interstellar - S.T.A.Y. on a seamless one-hour loop for you to work to. MORE
๐ Technology
An interview with Annie, who's behind The Depths of Wikipedia account, where she shares fascinating factoids from the site's most obscure and intriguing pages. MORE
Automate Creation of YouTube Shorts using MoviePy. MORE
A collection of small apps that demonstrate how Gemini can be used to create interactive experiences. MORE
"Rules" that terminal programs follow: 1) Your operating systemโs job, 2) Your shellโs job, 3) Your terminal emulatorโs job, 4) The job of whatever program you happen to be running (like top or vim or cat). MORE
Lumen is a command-line tool that leverages AI to generate commit messages, and summarize git diffs or past commits without requiring an API key. MORE
๐ Interesting
For 27 years, the author took photographs while waving goodbye and driving away from visiting their parents in Sioux City, Iowa, never intending to create a series. It gradually turned into our goodbye ritual. MORE
Beautiful website with interactive music theory lessons. Learn how to write your own melodies and progressions, and the fundamentals of making and understanding music. MORE
Amelia has created an intriguing app that uses the Perplexity API to visually display related information in a captivating manner. MORE
Discover history through OldMapsOnline, a platform that allows browsing historical places and searching for old maps with a timeline. MORE
Ruby and Ruby on Rails power the software of prominent companies like Shopify, GitHub, Gitlab, and many others (that I wasn't aware of), showcasing its impressive range. MORE
๐ญ Quote
"Inspire yourself so you can inspire others. Life begins at the end of your comfort zone."
๐ Learned something?
Upgrade Yourself โ
You're getting the free version. Members get more โ including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Share Hive Five โ
Share this newsletter with your friends and colleagues.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
Until next week, take care of yourself and each other,
Bee ๐
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.