- Hive Five
- Posts
- 🐝 Hive Five 67 – The more you know
🐝 Hive Five 67 – The more you know
Photo by Sean Thomas / Unsplash
Hi friends,
Greetings from the hive!
I hope you had a great weekend. It's getting significantly warmer over here, so it's time to stash the winter clothes.
I finished watching the show Severance on Apple TV. Amazing! Check it out if you haven't already.
My question for you is, do you have a 30-for-30 plan? Let me know if you do!
Let's take this week by swarm!
🐝 The Bee's Knees
Palisade identifies Wormable Cross-Site Scripting Vulnerability affecting Rarible’s NFT Marketplace: On April 14th, Palisade reported a cross-site scripting vulnerability and WAF bypass affecting the “rarible.com” domain. An attacker could inject arbitrary HTML and JavaScript on their profile page which persisted by “following the user around” as they navigated the website.
OffensiveCon22 - Mark Dowd- Keynote -How Do You Actually Find Bugs?: Mark Dowd is an expert in application security, specializing primarily in low level Operating System flaws for desktop and mobile platforms.
Introduction to Z-winK University: The Z-winK University is back! The goal is to teach how to be successful in bug bounty with tons of bug bounty tips.
Psychic Signatures in Java: The long-running BBC sci-fi show Doctor Who has a recurring plot device where the Doctor manages to get out of trouble by showing an identity card which is actually completely blank.
The More You Know, The More You Know You Don’t Know: This is their third annual year in review of 0-days exploited in-the-wild. Each year they’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what they think the trends and takeaways are.
🙏🏻 Support the Hive
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
TCM Security Academy - courses, bundles, gift certs, and access passes. Cybersecurity Training That Doesn't Break the Bank. Don't overspend on your education!
Privacy.com - Protect Yourself Online. Create virtual cards, set a spend limit on each transaction, and track your spend. Take back control of your payments.
🔥 Buzzworthy
✅ Changelog
gau v2.1.1 - speed improvement: Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
📅 Events
Bugcrowd's 8th LevelUp will be held on may 21st: Our goal with LevelUp is to provide education, exposure, and uplift across the global security community for researchers of all experience levels.
hardwear.io Security Trainings and Conference USA 2022 - 6th - 10th June 2022.
NahamCon 2022 speakers - April 30th: Excited to announce this year's NahamCon2022 speakers: @Jhaddix @zseano @infosec_au @samwcyo @codingo_ @InsecureNature @farah_hawaa @hakluke @areyou1or0 @seanyeoh & @devec0 @adrianhetman @gregxsunday Hosted by @stokfredrik & @_JohnHammond.
Tool Talks - Deep Dive Technical Webcast on ripgen Tool - May 11th: As attack surfaces continue to expand at an immeasurable rate, so do subdomain takeovers.
Diving Deeper into Subdomain Takeovers & Mitigations with Shubham Shah - April 29th: They’ll be diving into different types of infrastructure takeovers, with a focus on subdomain takeovers, and how they can be leveraged by attackers and bounty hunters to create real security impact.
🎉 Celebrate
dade got promoted: Congrats!
Mustafa worked on an interesting project: Awesome!
Sick.Codes received a bounty from Microsoft: Let's go!
MasterSEC won best collaboration at H12204: Nice one!
💰 Career Corner
Gillis on saving your cash: "I wanted to take a second to tell the younger folks who may be flush with cash for the first time something: SAVE YOUR CA$H. [...]"
Daniel on how to treat your ideas: "Forget about founding a startup. Instead become a VC for your own ideas. [...]"
Canva is hiring for a variety of technical roles: Including Penetration Testing / Red Team.
Ubisoft's Bug Bounty program is hiring a Technical Program Manager.
⚡️ From the Community
Justin is asking you to share your desk setup: "Getting ready to do my long-term desk setup. Anyone wanna share their setup and what is particularly great about it?"
📰 Articles & Threads
Why using URL shorteners to share sensible URLs is a terrible idea: Great thread about the security considerations while using URL shorteners.
Security issues with cloudflare/odoh-server-go and the ODoH RFC draft #30: Frans has been doing some research around ODoH (Oblivious DNS Over HTTPS) and he's identified some issues with the ongoing and running project at cloudflare/odoh-server-go as well as some issues with the RFC-draft itself lacking important security considerations.
AWAE Course and OSWE Exam Review: This is a review of the Advanced Web Attacks and Exploitation (WEB-300) course and its OSWE exam by Offensive-Security.
What VPS to choose?: There are tons of cloud providers that offer different types of servers with a lot of different options.
Meet the Blockchain Detectives Who Track Crypto’s Hackers and Scammers.
📚 Resources
Semgrep rules for smart contracts: In this repository you can find semgrep rules that look for patterns of vulnerabilities in smart contracts based on actual DeFi exploits.
🎥 Videos
It's been a year since GitHub education's Security Shorts aired: Make sure to check it out if you haven't already.
Sunday Live Recon w/ IppSec: Check out this episode of Live Recon! Hosted by @Jhaddix, @nahamsec and @stokfredrik.
ManoMano’s Red Team Operation - From a Click to an RCE by 0xLupin: In this presentation Roni Carta, alias Lupin will share how it was possible to gain access to one of ManoMano’s servers by finding exploiting a vulnerability through a Red Team Operation.
The Pivot - Kicks & Chips - Deep Dive into Scalper Bots: Scalper bots are designed to automatically buy a large amount of an exclusive item such as tickets, sneakers, or GPUs, often to resell them for profit.
🎵 Audio
Another iOS Bug and Edge Chakra Exploitation [Binary Exploitation Podcast]: A massive 11,000 byte overflow in WatchGuard, some discussion about lock-related vulnerabilities and analysis, and a look at a ChakraCore exploit dealing with all the mitigations (ASLR, DEP, CFG, ACG,CIG).
The Privacy, Security, & OSINT Show #258 - Introducing UNREDACTED Magazine: This week they announce their new privacy-themed magazine and present a warning about using Telnyx.
Smashing Security #271 - Crypto break-in, Google blurring, and mics not muting: NetFoundry's OpenZiti is an open source, free and easy way for the world to embed zero trust networking into anything.
Darknet Diaries #115 - Player Cheater Developer Spy: Some video game players buy cheats to win. Let’s take a look at this game cheating industry to see who the players are. Support for this show comes from Axonius. Securing assets — whether managed, unmanaged, ephemeral, or in the cloud — is a tricky task.
Malicious Life - Aaron Swartz: When 24-year-old Aaron Swartz was caught scraping millions of science articles off of JSTOR, he faced up to 35 years in prison plus a fine of up to 1 million dollars. Did Aaron’s crime justify such a harsh punishment?
Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.