- Hive Five
- Posts
- π Hive Five 203 - How To Live an Epic Life
π Hive Five 203 - How To Live an Epic Life
Career Advice for New Tech Workers in 2025, 7 Simple Rules to Crush Your To-Do List, Karpathy's Favorite Books, Best Products of 2024, and more...
Hi friends,
Greetings from the hive!
Obsidian update, I've started using the plus, minus, next method in my daily note. Then, use Dataview to roll that up to weekly, monthly, quarterly, and yearly reviews.
Let me know if youβre interested in seeing an Obsidian / PKM rundown from me.
Let's take this week by swarm!
π The Bee's Knees
Useful LLM tools and tips on how to make the most of them, covering Cursor,
llm
CLI, and Open Interpreter. MORE
The llm
CLI in particular has so many useful use-cases. Itβs one of my favorite tools of 2024. I can't wait to implement the ones mentioned in the article: Interrogate repositories using files-to-prompt, Ask questions to any website using markitdown, and Ask questions about any Youtube video using yt-dlp.
How @ArchAngelDDay became H1-305's Most Valuable Hacker. You can't control the scope or other hackers' skills, but with focus, creativity, and the right strategies, you can tip the odds in your favor MORE
In the new gameshow Leet Heat, contestants are asked a rapid-fire series of questions that span across the full stack of modern web development. If they get the answers right, they earn points. But if they're wrong? The spice level goes up. MORE
How an obscure PHP footgun led to RCE in Craft CMS. The behavior of the
register_argc_argv
flag is not intuitive and this will probably not be the last security vulnerability caused in this way. MOREJesse Itzler discusses how to live an epic life without setting rigid goals for the new year, in conversation with Sam Parr and Shaan Puri. MORE
Brought to you by β
Hive Store: For Hackers By Hackers
Support the Hive by becoming a swag-wearing cross-pollinator
Hack a life you love in style. Weβve got shirts, hats, mugs, mouse pads, and more.
Think witty AI jokes that'll make ChatGPT chuckle. Privacy puns so sharp, the EFF would hive five you.
Join the cross-pollinators who are already flexing these custom swag items.
Upgrade Yourself β
You're getting the free version. Members get more β including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Table of Contents
π° Updates
π― From the Hive
Ever since Chrome's initial launch, I've had a love hate relationship with it. I've tried Brave, Firefox, Vivaldi, Arc and others, but I always keep coming back to Chrome.
Now, with their recent changes, I want to spread my wings again and try something new. After Arc's "rug pull", I'm going to give Zen a try.
β Changelog
reconFTW v2.9 release: API leaks, 3rd party misconfigurations, JS source maps, IIS Shortnames, and more.
πΌ Work
π° Career
Career Advice for New Tech Workers in 2025. The goal with all of this is to get ourselves onto a good team. MORE
How Posthog redefined the PM and engineer relationship, and optimized everything they do for speed and autonomy. MORE
Adam Savage advises the unsure to pursue their interests and passions, for the path often reveals itself when one follows what captivates them. MORE
How to get your first customers (even with ZERO audience). MORE
Roadmap for becoming a highly paid DevOps engineer in 2025, with guidance from an experienced DevOps engineer. MORE
π Productivity
This Obsidian vault template provides a 'Product usage analysis' note exploring data-driven insights on product usefulness. MORE
A demonstration of how Kepano edits his website using Obsidian 1.8, with seamless integration between @obsdmd, Jekyll, a local web viewer, and GitHub deployment. MORE
Seven simple rules to crush one's to-do list each day, from managing energy levels to clearing mental clutter, helping get more done with less stress. MORE
Filetrees are bad but oil.nvim is good, allowing you to edit your filesystem like a buffer. MORE
If you're a neovim user I urge you to give it a go. It allows you to do ANYTHING you already do on a daily basis, but to files instead.
How to actually achieve your goals in 2025 (evidence-based): 1. Write Them Down, 2. Look at them every week, 3. Monitor your Progress, 4. Visualize Obstacles, Tie them to an Identity. MORE
π Community
π Celebrate
@iqimpz first full year of full-time Bug Bounty work was quite successful, with 160 vulnerabilities reported, including 41 critical and 41 high-severity issues. MORE
After a rocky start, @un1tycyb3r fortunes turned around: a child due in January 2025, a dream job doubling their pay, and the ability to be home with their wife. MORE
Alphabet's year-old AI bug bounty program has seen a remarkable surge in participation, with over 140 bug reports and $50,000 in bug rewards for Gen AI. MORE
@Bsysop took on the challenge of organizing the Bug Bounty Village at Brazil's largest cybersecurity conference, H2HC, and with a great team, managed to pull it off after months of hard work. Amazing! MORE
The king of automation, @codecancare, has reached over 200,000 reputation points on @Hacker0x01. MORE
π Level up
π° Read
Diving deep into CVE-2024-23917, a vulnerability in JetBrains TeamCity that leads to an authentication bypass. MORE
Last month the AI industry's narrative suddenly flipped β model scaling is dead, but "inference scaling" is taking over. This has left people outside AI confused. What changed? Is AI capability progress slowing? MORE
The Ruby on Rails
_json
Juggling Attack is an in-band signaling attack targeting JSON parsing. MORESOQL injection in Salesforce Apex earned Rooted0x01 a handsome sum, demonstrating the power of exploiting database vulnerabilities, even in environments without traditional tables. MORE
Two examples where Argo CD is deployed in a way that unexpectedly enabled privilege escalation and authentication bypass. MORE
π‘ Tips
@Zseano, a security researcher, has found AI to be immensely helpful in analyzing JavaScript code. His current method includes providing AI with JS code, and it constructs all necessary requests and explains details they may have overlooked. MORE
According to Casey, a few security trends may gain prominence in 2025, such as AI as a target, threat, and tool. MORE
Runa's New York City food recommendations: a curated list of top food spots across Manhattan, Brooklyn, and Queens. MORE
π§ Wisdom
A great question to answer: "have you designed a life youβre happy to live?" MORE
Market competition often fails to produce good products since buyers can't tell quality from marketing. This leads many companies to build rather than buy solutions, despite conventional wisdom. MORE
Whenever one buys, it is wise to consider not just cost, but also cost per use, cost per smile, cost per thrill, cost per externality, and cost per lesson. MORE
How to make the greatest comeback of your life: 1) Feel into your situation, 2) Launch into the unknown, 3) Learn and build like a mad scientist. MORE
π Resources
A proof-of-concept for a path traversal vulnerability (CVE-2024-38819). MORE
Bug bounty hunting has become an exciting way to build security skills, earn extra income, and contribute to securing applications globally. PentesterLab's roadmap offers a step-by-step guide to mastering bug bounty hunting. MORE
Karpathy shares his favorite books, including all short stories by Ted Chiang, Lord of The Rings, How To Live by Derek Sivers, and many more. MORE
An OSINT deep dive uncovers a vast digital trail of alleged killer Luigi Mangione's accounts, addresses, and Google reviews. MORE
People share their best products of 2024, such as innovators like Cursor, OpenAI, and Granola. MORE
π Explore
π§° Tools
getSubsidiaries
is a new tool by @xnl-hacker allows users to retrieve a list of subsidiaries for a selected company, which can be useful for reconnaissance in bug bounty programs. MOREnomore403 allows you to bypass HTTP 40X errors. Unlike other solutions, it automates various techniques to seamlessly navigate past these access restrictions, offering a broad range of strategies from header manipulation to method tampering. MORE
Malimite is an iOS decompiler designed to help researchers analyze and decode IPA files. MORE
creepyCrawler is an OSINT tool that crawls a website to extract useful reconnaissance information. MORE
Lighter web automation with Python. Helium is a Python library for automating browsers such as Chrome and Firefox. MORE
Get $200 to try DigitalOcean β the go-to for all my recon, automation, and VPN needs. Get access to a comprehensive range of cloud resources, all at an affordable price.
π₯ Watch
Raphael Schaad, a gifted designer, collaborated with Cron to create a remarkable calendar app. This session explores the process of transforming a design idea into a tangible reality. MORE
Go is great I hate it. Dax talks about its strong standard library, packaging and deployment advantages, and quick build times. MORE
Techniques for crafting great bug bounty and penetration test reports, including proof of concepts. MORE
The CEO of a 250M company shares their daily routine and approach to work-life balance. MORE
π΅ Listen
Mitchell co-founded HashiCorp, took it all the way to IPO, exited in 2023βand now heβs working on a terminal emulator called Ghostty. Ghostty is set to 1.0 this month, so we sat down to talk through all the details. MORE
Justin and Jason discuss the potential of AI micro-agents in web hacking tasks like fuzzing, WAF bypassing, and report writing. MORE
Between Two Vulns: OpenAI Drama, Quantum Multiverses, and Model Vulnerability Hunting. MORE
An interview with Replit founder Amjad Masad: "I got rejected from YC (4x)β¦. now my side hustle is worth $1.16B". MORE
π Technology
State of JS 2024 is out. According to the report, the most adopted technology and also most loved is Vite. MORE
OpenAI has just released a new AI model that it believes is the future of the technology: a computer program that can reason. Is it a magic trick, a genuine step forward, or both? MORE
Researchers at the University of Helsinki and Cambridge sought to make SQLite even faster, and they published a paper demonstrating up to a 100x reduction in tail latency through asynchronous I/O and storage disaggregation. MORE
How League of Legends runs at scale on AWS. Riot Games revolutionized their game server infrastructure with AWS, leveraging auto-scaling to reduce costs while rapidly responding to shifts in player demand. MORE
Design documents are not always the path to a clean, gradual rollout of functionality. Small incremental changes in pull requests can lead to a more orderly git history. MORE
π Interesting
Deciding whether to rent or buy a home has become increasingly challenging due to rising interest rates and rents. A new rent-versus-buy calculator aims to help younger adults navigate this significant financial decision. MORE
Peter Santenello is an American videomaker, traveler, and entrepreneur known for creating unique documentary-style content about human stories and cultures around the world. MORE
The Disappearance of Literary Men Should Worry Everyone. The novel-writing trade is becoming a female dominion, with women accounting for an ever-increasing share of published fiction. MORE
"But if you care about the health of our society β especially in the age of Donald Trump and the distorted conceptions of masculinity he helps to foster β the decline and fall of literary men should worry you."
π Quote
"Your calendar isn't just recording your time - itβs exposing your lies"
π Learned something?
Upgrade Yourself β
You're getting the free version. Members get more β including exclusive & bonus content, access to an online community of smart and driven people, the complete Hive Archive, deep discounts, and so much more. See what you're missing.
Share Hive Five β
Share this newsletter with your friends and colleagues.
1 REFERRAL = 20% OFF EVERYTHING IN THE STORE
Until next week, take care of yourself and each other,
Bee π
This newsletter may contain affiliate links that support its costs. These links lead to tools, courses, and resources that I've personally found helpful.