- Hive Five
- Posts
- 🐝 Hive Five 41 – Light The Night
🐝 Hive Five 41 – Light The Night
Hi friends,
Greetings from the hive!
I hope you had a wonderful weekend! I didn't do anything in particular except watch and contribute to NahamSec's "Light The Night" Fundraiser. Last I saw, he raised over $17,000 in support of The Leukemia & Lymphoma Society! Truly heartwarming.
Let's take this week by swarm!
🐝 The Bee's Knees
Layer 8 Conference: The Layer 8 conference is solely dedicated to social engineering and open source intelligence (OSINT) discussions.
Double spending bug in Polygon’s Plasma bridge: They thought they were out of the security game for a while now and that their interests have moved on to other fields. Polygon Double-Spend Bug Fix Postmortem — $2m Bounty.
How to get useful answers to your questions: 5 years ago they wrote a post called how to ask good questions. But it’s missing a few of the tactics they use to get useful answers like “interrupt people when they’re going off on an irrelevant tangent”.
CVE-2021-2471 MySQL JDBC XXE: Prior to MySQL Connector/J 8.0.27, the getSource() method exists in MysqlSQLXML, but the getSource() method has no security check when external general entities included in XML sources, consequently,here exists a XXE vulnerability.
Disclosed GitLab report from vakzz: Stored XSS in markdown via the DesignReferenceFilter.
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
🔥 Buzzworthy
✅ Changelog
Rustlang 1.56 release: This version ships with the new edition: Rust 2021!
Nuclei v2.5.3 release: It includes a number of new features and bug fixes, making it easier to debug.
Introducing Shodan Trends: Shodan was originally designed as a tool to understand how technology use is changing on the Internet.
📅 Events
Chia Project: Chia Network is excited to announce the launch of their Bug Bounty program with the support of Bugcrowd.
Hardwear.io Security Trainings and Conference Netherlands 2021: Oct 28, 2021.
Texas Cyber Summit: Oct 29, 2021.
🎉 Celebrate
Happy birthday to Tuan Anh Nguyen: Congrats!
Valeriy crossed 5k rep at H1: Awesome!
kiwi is working on their infosec blog: Exciting!
Jason Haddix has big con plans for 2022: Can't wait!
💰 Career Corner
Are you a bug bounty recon/automation master?: and are you looking for a job right now? (full-time, benefits, can still do bounties on side, etc.) - Hit up sshell_.
Sam Parr ️has a coworker named Edie: She's one of the most effective, hardworking people he's ever worked with. But it wasn't obvious at first that she'd be as amazing as she is.
The Paranoids infosec intern alert: They're looking for three awesome interns who are looking to get a solid start in our industry.
Four tips to increase your DevOps salary: This is the second in an occasional series looking at DevOps salaries and careers.
📰 Articles
Exploiting Hibernate Injections: Hibernate is a database ORM framework for Java offering developers a uniform interface and syntax to interact independently with underlying relational databases like MySQL, PostgreSQL, and many more.
Moodle - Stored XSS and blind SSRF possible via feedback answer text: When managing a course in Moodle, it's possible to add a 'Feedback' activity.
A Scientific Notation Bug in MySQL left AWS WAF Clients Vulnerable to SQL Injection: GoSecure ethical hackers found a bug in MySQL that has security consequences.
All Your (d)Base Are Belong To Us, Part 2: Code Execution in Microsoft Office (CVE-2021-38646): After discovering relatively straightforward memory corruption vulnerabilities in tiny DBF parsers and Apache OpenOffice, they wanted to cast my net wider.
📚 Resources
What to do if all you have is an IP address asked by kirbstr.
Totally Insecure Web Application Project (TIWAP): a web security testing lab made using Flask for budding security enthusiasts to learn about various web vulnerabilities.
🎥 Videos
Katie Explains: Modern Web Development: She often tell people not to focus too much on CTFs or challenges on Twitter, but why? Well modern web dev has come a long way and many challenges just aren't realistic to what the modern web looks like.
Fuzzing Firefox using In-process Fuzzing with Frida - Browser Security #2.
Android Exploits 101 Workshop: This workshop is an overview of the "shape" of modern Android exploits with examples.
Zwink - S1E1: What is Bug Bounty Hunting & "The Suck Factor": He explains at a high level what Bug Bounty hunting is and the initial "suck factor" which will have to be overcome when getting started.
$2,500 Leaking parts of private Hackerone reports - timeless cross-site leaks:️ This video is an explanation of bug bounty report submitted on Hackerone to Hackerone's own bug bounty program.
🎵 Audio
Jocko Podcast - 221: The Unimaginable Path of Jonny Kim. SEAL Combat Medic, Doctor, Astronaut.
Mac Power Users - Unleashed, Indeed: Stephen and David talk through Apple's new batch of MacBook Pros, powered by the M1 Pro and M1 Max systems on a chip.
Automators Micro-Automations: It's those tiny little automations that can make your life easy.
Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.