Hi friends,

Greetings from the hive!

I hope you had a good time during my absence. I made it back from DEF CON but I was accompanied by Covid. I spent this past week recovering. Though I'm still not 100%, here's this week's Hive Five and a short rant.

I'm not a fan of American lawn culture. It feels obsessive. Not to mention that it doesn't look appealing at all to me. What prompted this was Adriana's war on lawns.

More shine to real nature, creativity, and being different.

Let's take this week by swarm!

🐝 The Bee's Knees

🙏 Support the Hive

Enjoy reading the Hive Five? Consider sponsoring the next edition.

You can also follow me on Twitter.

🔥 Buzzworthy

Changelog

  1. Findomain v8.2.0: It's a release with minor changes, security fixes, some development configurations added and that's it.

  2. ysoserial.net v1.35: Deserialization payload generator for a variety of .NET formatters.

📅 Events

  1. Uncurled – the presentation Tuesday August 23, 2022: Everything Daniel knows and learned about running and maintaining Open Source projects for three decades.

🎉 Celebrate

💰 Career Corner

⚡️ From the Community

  1. d0nut's dream is to no longer work a 9-5: Instead he wants to build really cool, high performance, high quality rust tools and libraries.

  2. sw33tLie had a blast at the Vegas Bug Bash: "I hope everyone doing bug bounties gets to experience a LHE at least once. It feels unreal to meet all the folks you've been working with in the past years."

📰 Articles & Threads

  1. Things TESS learned at the Bugcrowd Bug Bash: "There's seriously a lot going in the backend when we make a submission. [...]"

  2. Intro to Cross-chain bridges and its security: Blockchain enables various opportunities for its users. There are many takes on how blockchain should behave and what it should offer.

  3. Discovering Domains via a Time-Correlation Attack on Certificate Transparency: Many modern websites employ an automatic issuance and renewal of TLS certificates. For enterprises, there are DigiCert services. For everyone else, there are free services such as Let’s Encrypt and ZeroSSL. There is a flaw in a way that deployment of TLS certificates might be set up.

📚 Resources

  1. dh0ck/Wi-Fi-Pentesting-Cheatsheet: Personal notes used to pass the OSWP exam.

  2. trickest/wordlists: These wordlists are based on the source code of the CMSes/servers/frameworks here.

  3. payloadbox/sql-injection-payload-list: SQL Injection Payload List.

  4. Command Line Text Processing: From finding text to search and replace, from sorting to beautifying text and more.

🎥 Videos

🎵 Audio

  1. The New Guy at the Office Is a Secret Super Hacker - Darknet Diaries Ep. 36 - Jeremy From Marketing: Penetration testers are good guys, hired by companies to hack into their own networks by any means necessary. Pro hacker and ex-marine "Tinker" goes undercover as a marketing temp for the toughest crack of his career.

  2. Smashing Security 286 - Hackers doxxed, Pornhub probs, and Co-op security measures: Pornhub has a problem, the UK's Co-op supermarket is accused of big brother tactics, and we take a look at a security researcher's attempt to reveal the true identify of hackers.

Get $100 to try DigitalOcean. The go-to VPS for bug bounty hunters. I use it for all of my own recon and automation needs, plus it also doubles as a VPN. They have every cloud resource you need at an affordable price.

Upgrade Now

Get access to premium content

Subscribe

Keep Reading

No posts found