- Hive Five
- Posts
- 🐝 Hive Five 97 – Email Graffiti, The anatomy of a MP4 file, and Learning lockpicking while blind, divergent, and more
🐝 Hive Five 97 – Email Graffiti, The anatomy of a MP4 file, and Learning lockpicking while blind, divergent, and more
Photo by Hin Bong Yeung / Unsplash
Hi friends,
Greetings from the hive!
I hope you had a wonderful weekend and to those celebrating, a nice Thanksgiving.
The recent Mastodon exodus made me look for a way to cross-post to Twitter, and vice versa. This led me to Moa. I’ve only used it for a couple of hours, but so far, so good.
What have you automated lately?
Let's take this week by swarm!
🐝 The Bee's Knees
So, you want to get into bug bounties? Shubs, a 10 year bug bounty veteran, genuinely believes that hard work and a dedication to learning will lead you to success in bug bounties. more
Corben Leo hacked a phone company earlier last year. He found a stupidly simple way to view the call logs of 50M customers. more
Email Graffiti: hacking old email. Not long ago security researchers found they could take over old tweets that linked to links that don’t work anymore. Did you know you can do the same thing with email? more | blog
Learning Lockpicking while Blind, Divergent, and More. more
Header spoofing via a hidden parameter in Facebook Batch GraphQL APIs - Specifying the Host: header results in unpredictable behaviour. more
️💪 Sponsor
Want me to write about your company? Sponsor the Hive Five.
🔥 Buzzworthy
✅ Changelog
📅 Events
TomNomNom is speaking at NahamCon2022EU on December 17. more
hakluke is doing a talk at IWCon 2022 about how he identified a prolific IRL scammer using OSINT techniques at December 17-18. more
Looking for an opportunity to demonstrate your skills with Burp Suite? Complete the challenges by 31 December 2022 for chances to prove your skills, win swag, and a Burp Suite Certified Practitioner exam credit. more
🎉 Celebrate
💰 Career
The Paranoids at Yahoo are hiring for Incident Response intern program (Summer 2023). more
⚡️ Community
📰 Read
hipotermia struck back at a phishing campaign. more
Hacking in the Cloud - Cloudgoat: ec2_ssrf. Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with EC2 access was possible. more
CVE-2022-41924 - RCE in Tailscale, DNS Rebinding, and You. more
Remote Command Execution in a Bank Server. more
Remote Code Execution in Spotify’s Backstage via vm2 Sandbox Escape (CVSS Score of 9.8). The Oxeye research team has been able to gain remote code execution in Spotify’s open source, CNCF-incubated project—Backstage, by exploiting a VM sandbox escape through the vm2 third-party library. more
📚 Resources
🎥 Watch
A New HOPE (2022) - ActivityPub Four Years Later: The Good, the Bad, and the Fedi. more
HackTheBox - RedPanda walkthrough. more
Most important security lessons of 2022 for more
Discover Publicly Exposed Cloud Resources in AWS. One of the biggest concerns over the use of cloud services is the potential risk of exposing data and resources publicly. more
Can You Spot The Vulnerability? Cross-site WebSocket Hijacking. more
🎵 Listen
DAY[0] 170 - Hacking Pixel Bootloaders and Injecting Bugs. more
DAY[0] 169 - Racing Grafana, Stealing Mastadon Passwords, and Cross-Site Tracing. This week has the return of cross-site tracing, HTML injection, a golang specific vulnerable code pattern, and a fun case-sensitivity auth bypass. more
Smashing Security 299 - EV charging risks, FTX, and an ancient apocalypse. more
Malicious Life - Jailbreaking Tractors. more
Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have **every cloud resource you need** at an affordable price.
Subscribe to Premium to read the rest.
Become a paying subscriber of Premium to get access to this post and other subscriber-only content.
Already a paying subscriber? Sign In.
A subscription gets you:
- • Join a private Discord COMMUNITY: Engage in chat, uplift one another, grow together, and explore shared interests.
- • Access to COMPLETE HIVE ARCHIVE: Unlock a treasure trove of tools, resources, videos, and audio, catering to all your needs.
- • EXCLUSIVE & BONUS content: Delve into hundreds of curated links that didn't make it into the newsletter.
- • MEMBER-ONLY events: Take part in digital meetups, focus sessions, and more.
- • Deep DISCOUNTS on paid content.
- • Experience continuously added NEW BENEFITS.