Hi friends,
Greetings from the hive!
I hope you had a good week and a wonderful weekend. I finally set up this monitor arm I've had for quite a while. I was holding off until I was going to purchase a new monitor but deemed that unnecessary.
This weekend I learned about interstitial journaling. It combines note-taking, to-dos, and time tracking. Before, I never used timestamps in notes I took throughout the day. So I think this might be an excellent way to approach things.
Did you learn anything new this past week?
Let's take this week by swarm!
🐝 The Bee's Knees
Self-Learning Reverse Engineering in 2022: There are some awesome tools nowadays to accelerate your self-education for reverse engineering. godbolt and dogbolt are amazing to quickly learn basic assembly and reversing.
Online No One Knows Youre Dead - ShmooCon 2016: Most hackers have a massive digital footprint: social media, servers at co-location sites, servers at home, overly-complicated IT infrastructure, and various other IT gear connected in crazy ways. What happens when one of us suddenly dies? How do our loved ones pick up the pieces.
Hacking Together an ASM Platform Using ProjectDiscovery Tools: I leaked the tools before the release of this article. Sorry! In this article, they’re going to walk through hacking together a simple attack surface monitoring platform by using ProjectDiscovery tools, bash, and, flask. They will also be using MongoDB & Redis for scan data and scan queues.
seclilc Talks About Hacking, Recon and Breaking Into Cybersecurity: Lilly has one of the most amazing stories about how she has broken into cybersecurity and what she did to get her first pentest job.
Operational, Digital, and Personal Preventative Self-Care at hackersummersamp - "New Normalish" Edition: CJE usually writes a piece for first-timers and newbies on how to get the most out of Hacker Summer Camp and how to stay safe digitally and physically. This tradition began in the early days of Bugcrowd, when DEF CON was part of new-hire induction.
🙏 Support the Hive
Enjoy reading the Hive Five? Consider sponsoring the next edition.
You can also follow me on Twitter.
🔥 Buzzworthy
✅ Changelog
interactsh web client update: There's now a notification panel that lets you directly post the interaction information to supported platforms.
waymore v1.6: You can now run a docker version of 𝘄𝗮𝘆𝗺𝗼𝗿𝗲 thanks to @wellpunk, and more.
One List For All v2.4.1.1: Rockyou for web fuzzing.
📅 Events
The Diana Initiative - BiaSciLab Beginning Soldering - Hands on Workshop: This class teaches you the basics of soldering as you build the BiaSciLab Fluffy McGlitter Sparkle badge! This class is open to up to 20 people on a first come first serve basis - no fee! Aug 11 2-3pm.
🎉 Celebrate
Katie's home office is finished: Let's go!
💰 Career Corner
⚡️ From the Community
dawgyg is busy with Live Hacking Events: "im going to start on the programs for the bash tomorrow. spent the last 2 weeks on h1-702, now need to do the bug bash"
Michael is looking foward to DEFCON: "[..] Hopefully I'll be able to meet some people from this great community."
Candace will be opening up a scholarship for 5 Sec+ exams: They co-run a Discord server called SecurityNewbs.
Geekboy will be in Vegas for DEFCON: "If you're interested in security, automation and opensource or like what we're doing at @pdiscoveryio and have feedback, discussion, or insights to share, don't hesitate to reach out."
📰 Articles
Exploiting GitHub Actions on open source projects: GitHub Actions is a commonly used CI/CD pipeline for automated testing and deployment. While Actions make it easier to test and deploy, it also adds security risks to the project and its subsequent infrastructure if misconfigured.
Want to start hacking? Here's how to quickly dive in: Johan Carlsson started part-time hacking in May 2021 and is already number 7 on GitLab's HackerOne Top 10 list.
Automata - A General-Purpose Automation Platform: In this post, CaptainFreak summarizes how they ended up building Automata. A platform to easily create and run arbitrary and powerful workflows that during their executions, can also store data as well as invoke alerts.
📚 Resources
secfiles: edoardottt's files for security assessments, bug bounty and more.
safe-harbour: security.txt collection of most popular world-wide domains.
🎥 Videos
May Contain Hackers 2022 - World's Largest Hackercamp: It's held every 4 years, this time it was near Amsterdam.
🎵 Audio
The Privacy, Security, & OSINT Show #272 - Processor Attacks Explained: This week Paul Asadoorian joins the pod to explain vulnerabilities within computer processors with potential solutions.
Smashing Security #285 - Uber's hidden hack, tips for travel, and AI accent fixes: Uber may not face prosecution over its handling of a 2016 data breach - but its former chief security head does; how to defend your digital devices' data while on vacation, and how to change your accent with artificial intelligence.
Darknet Diaries EP 121 - Ed: In this episode we hear some penetration test stories from Ed Skoudis.
Get $100 to try DigitalOcean - The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.