Hi friends,

Greetings from the hive!

I hope everything is going well in your life. I just finished watching this week's Sunday Recon with guest Louis Nyffenegger. I'm always fascinated and inspired by the variety of guests.

Here's what's been on my mind lately, in random order: minimalism, anti-fragility, living in the now, mindset, and gratitude.

What's been on your mind lately?

Let's take this week by swarm!

🐝 The Bee's Knees

  1. Q: How to write a BUG BOUNTY report that actually gets paid?: YES! That's one of the topics STÖK and Jason Haddix and KUGG will answer in this episode of Bounty Thursdays.

  2. NahamCon2022 - Jason Haddix (jhaddix) - The Bug Hunter’s Methodology: Application Analysis v1: I had to do another one. One of the most anticipated talks (at least for me).

  3. mitmproxy2swagger: A tool for automatically converting mitmproxy captures to OpenAPI 3.0 specifications. This means that you can automatically reverse-engineer REST APIs by just running the apps and capturing the traffic.

  4. Hunting evasive vulnerabilities: Do you ever wonder about the vulnerabilities you've missed? Why didn't they show themselves - and will they be discovered by somebody else later?

🙏🏻 Support the Hive

🔥 Buzzworthy

Changelog

  1. reconFTW v2.3: Terraform + Ansible deployment on AWS by Stoo0rmq, added rate limit new flag by Job-de-Bruijn, new default resolvers from trickest, mall fixes and improvements.

  2. DalFox v2.7.5: Improve XSS Patterns, set Maximum for Headless Browser, improve codes and update packages

  3. DOMPurify v2.3.8: Cleaned up a minor issue with the 2.3.7 release, thanks @johnbirds.

  4. unfurl v0.4.0: Adds JSON output option. Thanks, @tracertea.

📅 Events

  1. HackTheBox "Cyber Apocalypse" CTF is BACK for 2022 - 14th - 20th May, 2022: Their global community CTF is here again with an intergalactic mission for you.

  2. LYT Conference - May 16-20, 2022: Linking your thinking is where you connect ideas to help you think critically and creatively; fluidly and flexibly; connectively and joyfully—in a way that accumulates in value for them over time.

  3. Save the bees - National day of action for bee-safe plants - May 21th 2022: One of the most important ways we can help pollinators this spring is by increasing the availability of bee-safe plants for gardeners and landscapers.

  4. Azeria Labs - OBTS Course - October 3rd - 5th, 2022: For researchers aiming to keep up with the latest technology trends, the Arm architecture has become more relevant than ever.

🎉 Celebrate

💰 Career Corner

  1. TomNomNom on aligning work timezones: "If you're a bit of night-owl, or just not much of a morning person: I can highly recommend working remotely for a company that's in a timezone several hours behind you :)"

  2. shenetworks network is looking for employment: Anyone hiring security related roles? Mainly blue team but feel free to post anything for others looking.

  3. Trusted Sec and Binary Defense are hiring: 100% full remote work (U.S. only).

  4. Why I left Google - work-life balance / Scott Kennedy: At the time, he had a hard time expressing why he needed to make the change, even though he knew with certainty.

⚡️ From the Community

📰 Articles

  1. Multiple bugs chained to takeover Facebook Accounts which uses Gmail.: This bug could allow a malicious actor to takeover a Facebook account after stealing a Gmail OAuth id_token/code used to login to Facebook. This happened due to multiple bugs that were chained.

  2. A tale of a trailing dot: Trailing dots on host names in URLs is the gift that keeps on giving.

  3. Earn $200K by fuzzing for a weekend - Part 2: Below are the writeups for two vulnerabilities they discovered in Solana rBPF, a self-described “Rust virtual machine and JIT compiler for eBPF programs”.

  4. A Fun SSRF through a Headless Browser: But let's talk about the coolest one. So you can learn. Render means to "process information".

📚 Resources

  1. Jason's practice target super thread: E.g. for offensive security people that want to take their theory to live targets.

  2. Jack asks about technologies and innovations: "What's a technology or innovation that when you saw it you said hell no. But now you use it all the time?"

  3. forrest-orr/Exploits: This repository contains their personal collection of Windows CVE they have turned in to exploit source, as well as a collection of payloads they've written to be used in conjunction with these exploits.

  4. Datadog Security Labs Research and Proof of Concept Code: This repository aims at providing proof of concept exploits and technical demos to help the community respond to threats.

🎥 Videos

  1. Bug Bounty 101 #16 - Login Dialogue Bypass via Password Spray / Brute Force Attack: In this bug bounty video, Z-Wink goes over the subtle differences in brute force, dictionary attack, and password spray and show real examples using Burp Intruder of wow these attacks are conducted to break into login dialogues (for authorized testing targets) without knowing usernames or passwords.

  2. How the FBI Investigated the First Bank Robbing Hacker - Darknet Diaries Ep. 23 Vladimir Levin: When banks started coming online, they almost immediately started being targeted by hackers.

🎵 Audio

  1. Cloudflare Pages, Hacking a Bank, and Attacking Price Oracles [Bug Bounty Podcast]: Some interesting vulnerabilities this week from a Cloudflare Pages container escape chain, to hacking a bank's web application with some neat tricks to get abuse a file-write in a hardened envrionment, and even another dumb smart-contract bug.

  2. The Privacy, Security, & OSINT Show #261 - A Client Stops By: This week a client stops by to discuss his recent full privacy reboot, plus the latest news.

  3. Smashing Security #274 - Hands off my biometrics, and a wormhole squirmish: Clearview AI receives something of a slap in the face, and who is wrestling over an internet wormhole? All this and more.

  4. Malicious Life - How to Russia-Proof Your Democracy [ML BSide]: In 2007, Estonia - then already a technologically advanced country - suffered a large-scale DDoS attack that crippled many organizations and digital services.

Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.

Upgrade Now

Get access to premium content

Subscribe

Keep Reading