- MonkeHacks
- Posts
- MonkeHacks #47
MonkeHacks #47
Austria, Advisory, Portswigger Nominations
MonkeHacks #47
This week I was in Vienna, Austria with my friend from Ireland. It was a chill few days between putting in the hours for an ongoing pentest, and seeing various museums. I saw my Austrian friend and went bouldering twice. I arrived back in Edinburgh yesterday after a few weeks of being away, and I’m ready to focus on hacking again.
I don’t have much to write about this week regarding my own work, since I didn’t have the time to do any bug bounty, but nonetheless there is some news.
The Hofburg Palace in Vienna. Currently, the president of Austria uses one wing of it as an office.
Weekly Ideas / Notes
I’m happy to share that I was selected for the Bugcrowd Hacker Advisory Board! You can read more about it here, but effectively I will be providing feedback to Bugcrowd on the hacker’s perspective and experience. Hopefully this, in turn, will lead to a better working environment for us hackers and a better platform for Bugcrowd.
I was accepted into HackerOne Pentests! Not much to add here other than that I’m glad to join the program and I’m looking forward to doing some quality security work.
Unrelated to bug bounty, I went bouldering twice during my trip. I am currently at 6a/6b/6b+ on the Font scale, or around V4 on the V scale.
The annual Top 10 web hacking techniques of 2024: Nominations are here. If you’re not familiar with this, every year Portswigger publish a list of the best web hacking techniques of the year. What’s lesser known is that the nominations list is a treasure trove of good research to read about!
That’s all I have for this week! I’m back in Edinburgh now, so hopefully next week I’ll have more to discuss.
Resources
Nahamsec’s $100k bug ended up in TechCrunch: Based on the article we can deduce that Ben found a headless SSRF, and then reached out to Alex Chapman who, in classic ajxchapman fashion, escalated it to RCE with a Chrome exploit. Congratulations to both! Amazing work.
DoubleClickjacking: A New Era of UI Redressing: A very clever window manipulation trick to get a victim to click a particular button somewhere.
WorstFit: Unveiling Hidden Transformers in Windows ANSI!: Orange Tsai has released the full writeup of the research he presented recently. It’s absolutely brilliant work.