- Hive Five
- Posts
- Hive Five 40 – Extreme Ownership
Hive Five 40 – Extreme Ownership
Photo by Karsten Winegeart / Unsplash
Hi friends,
Greetings from the hive!
I hope you had a wonderful weekend. I ordered some new hardware and am still looking for some more. In particular a keyboard and a monitor.
I also spend some time thinking about the next steps for the Hive community. I narrowed it down to a couple of options. Now, it's time to execute.
Let's take this week by swarm!
🐝 The Bee's Knees
Fabio Viggiani & Fredrik Alexandersson - Gone in 45 min, War stories from Incident Response.
Introduction to Bash Programming: Bash is one of the most flexible programming languages and it's especially useful for infosec and bug bounty automation.
Building a POC for CVE-2021-40438: If you’re blue team and want to know what an exploit for this looks like for filtering purposes they’ve added that information for you in the conclusions section. one-liner.
BT’s Metaversal Album Treasure Hunt Solution: The musical artist known as BT recently launched his 14th album as an interactive NFT experience on the Arweave blockchain called Metaversal. Part of this experience was a multiple day long puzzle treasure hunt.
SAML Padding Oracle: ArcGIS is a family of software providing geographic information system services. In this blogpost they show how they found and exploited an AES-CBC padding oracle in this flow. (Via PentesterLab)
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
🔥 Buzzworthy
✅ Changelog
Datasette 0.59 is out: adding column descriptions in metadata, a new register_command plugin hook, enhanced --cors support and a bunch of other fixes and documentation improvements.
Paul Seekamp's Internal Security Assessment - Field Guide update: Beginner/intermediate's guide has been updated.
Burp Suite 2021.9 released: allowing you to manually test hidden HTTP/2, improving scanning of SPAs, and providing a number of updates for Burp Intruder.
Rana Khalil updated The Web Security Academy Course: now includes 8 additional videos that cover the Server-Side Request Forgery (SSRF) vulnerability.
Sharpener 1.07 released: This extension should add a number of UI and functional features to Burp Suite to make working with it easier.
📅 Upcoming Events
Join Ben Sadeghipour for Introduction to Web Application Hacking & Bug Bounty on Nov. 8-10: Participants are given hands-on experience by learning each vulnerability category & completing a series of challenges.
Come join the world's first virtual vim conf: Vimmers from all around the world to connect and share their love and passion for all things vim! The current date is tentative! It will most likely change. We will update as it does.
🎉 Weekly Wins
Justin Kennedy recommending Agarri's Burp training: Sounds amazing!
Ozgur Alp is the SRT grand champion: Incredible!
Tuan Anh Nguyen got dope swag: Looking good!
Shaun is 2nd All Time on Sony VDP: Congrats!
💰 Career Corner
Job - Canva is looking for a Vendor Risk Analyst for Security Governance / Risk & Compliance.
Job seeker - 4 year exp. security individual: They do web/mobile/network security and source code review.
📰 Articles
Bachelor's thesis on HTTP Request Smuggling: During the spring of 2021, Mattias Grenfeldt and Asta Olofsson wrote their bachelor's thesis in Computer Science at KTH Royal Institute of Technology in Sweden. They studied HTTP Request Smuggling.
How to PoC your Bug Leads: Picture this scenario: you’ve spent the entire day fruitlessly examining smart contract code. And now you’ve stumbled across a snippet of code that makes your Spidey-Senses tingle. You get excited.
STEM Methodology: White Oak Security’s unique, custom-crafted Systematic Threat Evaluation Methodology (S.T.E.M.) was built by their founder and CEO, Christopher Emerson.
📚 Resources
PimpMyBurp #6 Generate your reports directly in Burp Suite with RIO.
Great resource for Ruby (on Rails) deserialization via deesee.
redact.photo: The fastest way to censor sensitive information. (Untested)
GitHub Security Lab: Resources related to GitHub Security Lab.
🎥 Video
CSRF - Lab #7 CSRF where Referer validation depends on header being present | Long Version.
How To Search For CSRF: Learn how to find cross-site request forgery (CSRF) vulnerabilities.
How to conduct a basic security code review | Security Simplified: Performing a source code review is one of the best ways to find security issues and vulnerabilities in an application.
Overflowing Function Pointers On The Heap: After they found some function pointers they could use for exploitation, they instructed sudo to find their heap locations.
🎵 Audio
Application Security Podcast: Security Engineer, @mazen160 joins them to introduce Infrastructure as Code and TerraForm. Interview With the AppSec Podcast: Terraform Security.
Jocko Willink - Extreme Ownership (audiobook): provides huge value for leaders at all levels. An inspiring and page-turning read, the leadership lessons are easy to digest and implement.
spaceraccoon recommends Nicole Perlroth's "This is how the world ends": I have added it to my to-read list. (book link)
Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.