Hi friend,

Greetings from the hive!

I hope you had a wonderful weekend. Happy Raksha bandhan to all that celebrated! I learned about this festival on the Bugcrowd discord.

I went tubing, that's where you float down a river on an inner tube, and I managed to not get burned! Hurray.

Let's take this week by swarm!

🐝 The Bee's Knees

  1. From Pwn2Own 2021: A New Attack Surface on Microsoft Exchange - ProxyShell!: In April 2021, Orange Tsai from DEVCORE Research Team demonstrated a remote code execution vulnerability in Microsoft Exchange during the Pwn2Own Vancouver 2021 contest. In doing so, he earned himself $200,000.

  2. How to Hack Apple ID: Everyone knows what’s inside a computer isn’t really real. It pretends to be, sure, hiding just under the pixels — but they promise you it isn’t. In the real world, everything has a certain mooring we’re all attuned to.

  3. Common Open Redirection Bug Bounty Mistakes by codingo: Let's talk about open redirections, their impact, and common mistakes made when submitting them to bug bounty programs.

  4. Malicious PDF Generator: Generate ten different malicious pdf files with phone-home functionality. Can be used with Burp Collaborator. Used for penetration testing and/or red-teaming etc.

🙏🏻 Enjoy This Newsletter?

  • Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.

🔥 Buzzworthy

Changelog

📅 Events

  1. Kishore Krishna started beginner spotlight series: Where beginners can ask questions and the community can reply/guide or even offer to mentor them.

  2. Heath Adams announces cloud based labs: They will have a custom built lab, say for PEH, that you can run and pay hourly fees on (at cost) at the click of a button.

  3. h@cktivitycon 2021 - September 18, 2021: a HackerOne hosted hacker conference built by the community for the community.

🎉 Celebrate

💰 Career Corner

  1. Bugcrowd has a few open roles: like this Security Solutions Consultant role which is a remote-first role.

  2. Bishop Fox is expanding their redteam: Currently hiring Senior Red Teamers, U.S. Remote Focused on senior level experience.

  3. Lares is hiring Sr. Red Teamers and Sr. Pentesters: They took a candid approach to the job post, because they also like to have fun at work.

📰 Articles

  1. Common mistakes when using permissions in Android: When an Android app needs access to sensitive resources on the device, the app developers make use of the permissions model.

  2. iOS Pentesting 101: It is no secret that mobile devices are on the rise.

  3. Blast Radius: DNS Takeovers: Patrik Hudak showcases his research into the impact DNS takeovers can have on companies.

  4. Web App Pentesting With Burp Suite Scan Profiles: With the introduction of the Configuration Library in Burp Suite 2.0’s release, they’ve been creating more and more predefined templates to use during our web application penetration tests.

📚 Resources

  1. Collection of tools and methods created to aid in OSINT collection: Feel free to add to your own investigative toolkit, however you may NOT sell or host this without obtaining prior permission.

  2. HackTricks: Here you will find the typical flow that you should follow when pentesting one or more machines.

🎥 Videos

  1. John Jackson on joining Sakura: "To be honest I never thought I'd make a video like this in a million years."

  2. Hacker Heroes #10 - bug_dutch (Interview): Flo van der Vlist (@bug_dutch) is currently climbing the Intigriti leaderboard at light speed.

  3. How a global police force took down Emotet: How do you defeat a highly organised criminal gang when you don’t know who or where they are?

🎵 Audio

  1. Hacking Your Health - The Podcast: Episode 001 recorded and ready to go, an introduction to both @HackingDave & @bencanning87.

  2. The Privacy, Security, & OSINT Show: 224-Employment Privacy & Security.

  3. BBC The Lazarus Heist - Hacking Hollywood: First episode of an excellent series about the Lazarus Group.

  4. The InfoSec & OSINT Show - 64 Daniel Cuthbert & Pen Testing with the ASVS: Daniel Cuthbert talks about the OWASP Application Security Verification Standard.

Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.

Upgrade Now

Get access to premium content

Subscribe

Keep Reading

No posts found