• Hive Five
  • Posts
  • ๐Ÿ Hive Five 82 โ€“ Must-watch talks at DEFCON, how to become an expert, and how to ask and get a yes

๐Ÿ Hive Five 82 โ€“ Must-watch talks at DEFCON, how to become an expert, and how to ask and get a yes

Photo by Jon Tyson / Unsplash

Hi friends,

Greetings from the hive!

I hope you had a good weekend. If I seem more absent on social media lately, my personal life has been turbulent. Nothing bad, just busy.

Also, I will be at DEFCON, so hit me up if you're going too! I'd love to meet up. This also means that there'll be no edition next week.

Let's take this week by swarm!

๐Ÿ The Bee's Knees

  1. Tom Anthony - Fuzzing XSS Sanitizers for Fun and Profit (talk).

  2. Bugcrowd will be hosting two Bug Bash events in Vegas at Hacker Summer Camp: After months of hard work and late nights, Bugcrowd is stoked to announce it'll be hosting two Bug Bash events in Vegas at Hacker Summer Camp!

  3. LiveOverflow on how to become an expert: "In order to learn you have to be practicing at the edge of your ability, pushing beyond your comfort zone. You have to use a lot of concentration and methodically repeatedly attempt things you aren't good at." Source: The 4 things it takes to be an expert.

  4. Must-watch talks at DEFCON via CJE.

  5. Snyff Talks About Hacking, Learning and Creating PentesterLab.

๐Ÿ™ Support the Hive

Enjoy reading the Hive Five? Consider sponsoring the next edition.

You can also follow me on Twitter.

๐Ÿ”ฅ Buzzworthy

โœ… Changelog

  1. renniepak wants to get more experience with deep diving.

  2. hakluke on making his own schedule: "I've been doing this for about 11 weeks now. [...]"

  3. SecLists 2022.3: SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place.

๐Ÿ“… Events

  1. The Diana Initiative - August 10-11, 2022: In-Person at The Westin Las Vegas Hotel & Spa.

  2. DEF CON 30 - August 11-14.

๐ŸŽ‰ Celebrate

๐Ÿ’ฐ Career Corner

โšก๏ธ From the Community

๐Ÿ“ฐ Articles & Threads

  1. Nomad drained for $150M - One of the most chaotic hacks via samczsun.

  2. Taking leaps, not steps: "Today is a big day filled with a lot of different feelings. [...]"

  3. How To Hack Web Applications in 2022 - Part 2: TL/DR: Web applications have both authentication and authorization as key concepts and if bypassed by an attacker, it can compromise sensitive data.

  4. CVE-2022-31813 - Forwarding addresses is hard.

  5. reconFTW, an overview: Reconnaissance, assets discovery, attack surface mapping, subdomains discoveryโ€ฆ the initial step in a pentesting or bug hunting assessment is one of the most important and will help you find those sites that nobody found before.

๐Ÿ“š Resources

๐ŸŽฅ Videos

๐ŸŽต Audio

  1. The Privacy, Security, & OSINT Show #273 - Credential Exposure Removal.

  2. Smashing Security #286 - Hackers doxxed, Pornhub probs, and Co-op security measures.

  3. Malicious Life - Andrew Ginter - A 40-Year-Old Backdoor ML B-Side: Ken Thompson is a legendary computer scientist who also made a seminal contribution to computer security in 1983 when he described a nifty hack that could allow an attacker to plant almost undetectable malicious code inside a C compiler. Surprisingly, it turns out a very similar hack was also used in the SolarWinds attack.

Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have **every cloud resource you need** at an affordable price.

Subscribe to the Hive Five to read the rest.

Become a paying subscriber of the Hive Five to get access to this post and other subscriber-only content.

Already a paying subscriber? Sign In

A subscription gets you:
Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
Experience continuously added NEW BENEFITS.