- Hive Five
- Posts
- 🐝 Hive Five 95 – What is a server, hiring resources, and a Twitter refugee’s guide to Mastodon
🐝 Hive Five 95 – What is a server, hiring resources, and a Twitter refugee’s guide to Mastodon
Photo by Taylor Vick / Unsplash
Hi friends,
Greetings from the hive!
I hope you're doing wonderful. They say all good things come in twos. This week I got two shots, the flu vaccine and a Covid booster.
I also made two discoveries this week: I found out that you can view the traffic of a GitHub repo, and that regular Insulin costs $25but is slow acting, old, and not easy to manage.
Have you learned anything new?
PS: I'm trying out a new section format with the link(s) on the end. Let me know what you think!
Let's take this week by swarm!
🐝 The Bee's Knees
What is a Server? Let's look at server software and servers in data centers to understand how the word is used. more
pwn.college, a education platform for students (and other interested parties) to learn about, and practice, core cybersecurity concepts in a hands-on fashion. more
Reverse Engineering the Apple MultiPeer Connectivity Framework. more
GCP Penetration Testing Notes. more
Accidental $70k Google Pixel Lock Screen Bypass. more
🔥 Buzzworthy
✅ Changelog
Introduction of the ability to privately report vulnerabilities to repository maintainers on GitHub. more
DOMPurify 2.4.1 - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. more
GitHub released two variable open source fonts, Mona Sans and Hubot Sans. more
Another GitHub release, code search. A new way to search and navigate code. more
📅 Events
🎉 Celebrate
TESS shouting out sw33tLie for creating SNS in a cleaner version. Love to see it! more
Viktor havin success focusing on one bug bounty program. Go get 'em! more
Happy birthday STÖK. Salute! more
TomNomNom (and many others) thank project discovery for being committed to open source. Awesome stuff! more
💰 Career
Hiring resources, tips, and quality companies that are hiring. more
The hiring process is ultra-competitive. Here are 16 ways to stand out in a hiring process. more
List of companies that are hiring software engineers, data engs, and EMs. more | doc
ali is looking for mid level developer roles. more
How to Social Engineer your way into your dream job by Jason Blanchard. more
⚡️ Community
Justin Gardner has been doing a security audit of the Amazon Echo Show lately and it's been a blast. more
Michał Bentkowski revived his old website. Let him know if you have feedback! more | website
Writing Python extensions for Burp Suite is getting more and more awful, Agarri says. more
WISP's top needs in 2023 survey. This survey data is used to prioritize their goals and focus areas for the upcoming year. more
hakluke started building a new SaaS and is back in Laravel after 7 years! more
📰 Read
In the past two years, Keen Security Lab did in-depth research on the security of Tesla Cars and presented our research results on Black Hat 2017 and Black Hat 2018. [more](Exploiting Wi-Fi Stack on Tesla Model S)
A Twitter Refugee's Guide to Mastodon. more
Sam Curry formed a small team of hackers and collectively hunted for vulnerabilities on John Deere’s security program. During their 10 day engagement, they found 100 unique vulnerabilities with 50 rated critical, 32 high, 14 medium, and 4 low severity. more
Practical client side path traversal attacks. more
📚 Resources
Jack Rhysider has a Darknet Diaries Discord with 15,000 members. more
InfoSec Black Friday Deals. All the deals for InfoSec related software/tools this Black Friday / Cyber Monday. more
Talk to Books - Browse passages from books using experimental AI. more
The Hitchhiker's Guide to DFIR: Experiences From Beginners and Experts. This is a book written for the DFIR community, by the DFIR community. more
ThinkstScapes Quarterly | 2022.Q3. 21 talks from three budding trends: using AI/ML to amplify side-channel attacks, clever cryptography that goes beyond simple data protection, and software analysis at scale. more
🎥 Watch
Stephen Sims - A Look at Modern Windows Kernel Exploitation. more
We Hack Purple Podcast Episode 59 with Guest Vitaly Unic, the head of AppSec Research at Bright Security. more
How to get greater bounties for MEDIUM and LOW risk reports? more
Hacker Interview with djdurado. more
HackTheBox - Shared walkthrough. more
🎵 Listen
DAY[0] Binary Exploitation Podcast 166 - OpenSSL Off-by-One, Java XML Bugs, and a Samsung Chain. more
DAY[0] Bug Bounty Podcast 165 - Apache Batik, Static Site Generators, and an Android App Vulnerability. more
Malicious Life - What can chess grandmasters teach us about Cyber? more
Risky Business #684 - DoJ seizes 50,000 stolen bitcoins from popcorn tin. more
Smashing Security 297: Mastodon 101, and the Hushpuppi saga - Graham offers some security and privacy advice for those exodusing Twitter to Mastodon, and Carole slams the door shut on a notorious scammer with a huge Instagram following. more
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have **every cloud resource you need** at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.