Hi friends,

Greetings from the hive!

I hope you had a wonderful weekend. I ordered some new hardware and am still looking for some more. In particular a keyboard and a monitor.

I also spend some time thinking about the next steps for the Hive community. I narrowed it down to a couple of options. Now, it's time to execute.

Let's take this week by swarm!

🐝 The Bee's Knees

  1. Introduction to Bash Programming: Bash is one of the most flexible programming languages and it's especially useful for infosec and bug bounty automation.

  2. Building a POC for CVE-2021-40438: If you’re blue team and want to know what an exploit for this looks like for filtering purposes they’ve added that information for you in the conclusions section. one-liner.

  3. BT’s Metaversal Album Treasure Hunt Solution: The musical artist known as BT recently launched his 14th album as an interactive NFT experience on the Arweave blockchain called Metaversal. Part of this experience was a multiple day long puzzle treasure hunt.

  4. SAML Padding Oracle: ArcGIS is a family of software providing geographic information system services. In this blogpost they show how they found and exploited an AES-CBC padding oracle in this flow. (Via PentesterLab)

🙏🏻 Enjoy This Newsletter?

  • Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.

🔥 Buzzworthy

Changelog

  1. Datasette 0.59 is out: adding column descriptions in metadata, a new register_command plugin hook, enhanced --cors support and a bunch of other fixes and documentation improvements.

  2. Paul Seekamp's Internal Security Assessment - Field Guide update: Beginner/intermediate's guide has been updated.

  3. Burp Suite 2021.9 released: allowing you to manually test hidden HTTP/2, improving scanning of SPAs, and providing a number of updates for Burp Intruder.

  4. Rana Khalil updated The Web Security Academy Course: now includes 8 additional videos that cover the Server-Side Request Forgery (SSRF) vulnerability.

  5. Sharpener 1.07 released: This extension should add a number of UI and functional features to Burp Suite to make working with it easier.

📅 Upcoming Events

  1. Join Ben Sadeghipour for Introduction to Web Application Hacking & Bug Bounty on Nov. 8-10: Participants are given hands-on experience by learning each vulnerability category & completing a series of challenges.

  2. Come join the world's first virtual vim conf: Vimmers from all around the world to connect and share their love and passion for all things vim! The current date is tentative! It will most likely change. We will update as it does.

🎉 Weekly Wins

💰 Career Corner

📰 Articles

  1. Bachelor's thesis on HTTP Request Smuggling: During the spring of 2021, Mattias Grenfeldt and Asta Olofsson wrote their bachelor's thesis in Computer Science at KTH Royal Institute of Technology in Sweden. They studied HTTP Request Smuggling.

  2. How to PoC your Bug Leads: Picture this scenario: you’ve spent the entire day fruitlessly examining smart contract code. And now you’ve stumbled across a snippet of code that makes your Spidey-Senses tingle. You get excited.

  3. STEM Methodology: White Oak Security’s unique, custom-crafted Systematic Threat Evaluation Methodology (S.T.E.M.) was built by their founder and CEO, Christopher Emerson.

📚 Resources

🎥 Video

  1. How To Search For CSRF: Learn how to find cross-site request forgery (CSRF) vulnerabilities.

  2. How to conduct a basic security code review | Security Simplified: Performing a source code review is one of the best ways to find security issues and vulnerabilities in an application.

  3. Overflowing Function Pointers On The Heap: After they found some function pointers they could use for exploitation, they instructed sudo to find their heap locations.

🎵 Audio

  1. Application Security Podcast: Security Engineer, @mazen160 joins them to introduce Infrastructure as Code and TerraForm. Interview With the AppSec Podcast: Terraform Security.

  2. Jocko Willink - Extreme Ownership (audiobook): provides huge value for leaders at all levels. An inspiring and page-turning read, the leadership lessons are easy to digest and implement.

Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.

Upgrade Now

Get access to premium content

Subscribe

Keep Reading

No posts found