MonkeHacks #100
Welcome to MonkeHacks 100. One hundred MonkeHacks. That’s a lot of MonkeHacks!
I started this newsletter in February 2024. Two and a half years later, it’s still going strong! Thank you for reading it and supporting my work. I’ve had many people come up to me over the last two years and tell me that they read my newsletter - when I write, I put it out into the world and forget about it, so I get reminded like “oh, people actually read this thing”. So thank you! I really appreciate it. Here’s to many more of these things.
It’s been a month since the last issue, and life has just been very, very busy. I’m writing this from a Japanese-themed hotel called Yasuragi near Stockholm in Sweden. I needed the rest after a busy Def Con, and I completely unplugged from my computer and token-maxxing endeavours for three days or so.
I have a very personally meaningful Live Hacking Event coming up in September. I can’t share more about it yet, but if you know, you know. And if you don’t know, you’ll find out more soon.
Unrelated to the above, I was at an event organised by HackerOne and a company I cannot disclose in Reykjavik, Iceland. The format was pretty cool - Day 1 was entirely composed of Show and Tells from program hackers, and Day 2 was mostly talks from the host company’s staff. S&T is my favourite part of most LHEs, so Day 1 was a real treat. Then there was the group activity… more on that below.
I gave a talk at Def Con at Bug Bounty Village! Hacktus was unable to attend Def Con, so I stood in for him and delivered his excellent talk on Sunday morning. I really enjoyed meeting everyone in Bug Bounty Village, both the familiar and unfamiliar.
My hackbot received its first fully automated bounties this week, of $2,500 and $500. Big milestone for me as this was my main project for the past two months. Unfortunately, it also got its first dupe, but my dupe rate is surprisingly low! I think I just use my hackbot in unusual ways. At the very least, I’ve covered my token costs. I have some very nice bugs in the pipeline that I hope will pay well.

The squad at Def Con, with the toy cactus representing Hacktus.
Weekly Ideas / Notes
Iceland
So. The group activity. We went whale-watching. We (program staff and about 20-30 hackers) piled onto the tour boat, which sailed for approximately an hour out into Reykjavik’s Faxaflói Bay. When the boat was going fast, it was fine, but when it slowed down to look for whales - oh man. Oh man. The smaller waves started to batter the sides of the vessel, and the boat began to rock side-to-side. This resulted in about 10 people, including myself, getting struck down by a severe bout of seasickness. When the boat came to a complete stop near a surfacing humpback whale, the scene was apocalyptic. A mix of program staff and hackers were sitting down, or leaning on the railings, suffering. Wind and mist from all directions battered us, soaked us through.
We did see a humpback whale and a few white-beaked dolphins, at least. And many, many interesting seabirds like dozens upon dozens of puffins, a few Northern Gannets, guillemots, and what I think were razorbills. The only thing worse than being violently ill on a group activity, is not seeing anything at all to make it worthwhile. Seeing the whale was a fantastic experience but I’m not sure it was worth the three hours of nausea.
That said, I have no regrets about going, and I’m very thankful to the program for organising it. It was an experience nonetheless and a memorable one.
Def Con 34
Last week, I attended Def Con, and a few of you probably saw me there. I gave a talk titled AI Cuts Both Ways to the Bug Bounty Village, which was primarily Hacktus’s slides, as he was unable to make it to Vegas due to visa restrictions.
My time in Vegas was quite chill, honestly. I arrived a day earlier, but in my infinite wisdom, I forgot to book my hotel for the first day, so I booked that a few days before arriving in LV. So I was staying in the Hilton on my first night, and from the second night onwards, I stayed in the Fontainebleu, until I made the same mistake on my departure days and had to book a stay in the Hilton on short notice again.
On the Thursday, I did badge pickup with Splinter, a buddy of mine. I also went to Intigriti’s “Pwn the Pot” event, and did absolutely terribly at poker.
Def Con started on Friday, but I had an invitation to a mini-conference that I cannot disclose, so I attended that as it was a more fruitful for networking purposes. I left that after a few hours and caught the end of the Day 1 talks.
On the Saturday I spent the entire day in Def Con. I bought a FlatSat (satellite hacking simulated environment) and a book on post-training of AI models (for a number of reasons this interests me at the moment). It was so great to catch up with the community. We did some good hacking. My hackbot found some really cool bugs overnight, so that was awesome.
I delivered my talk on Sunday morning, and I spent the rest of the day hanging out with the other hackers in BBV. More hacking, more hanging out. People started to fly out of Vegas again.
Monday was more relaxed - I was hanging out with Splinter again, and we went to see The Wizard of Oz in the Sphere, and he won some money gambling. He also flew out on Tuesday (to go to Mexico for a holiday) so we killed some time in the airport lounge, and I flew back to Manchester (there were direct flights to Manchester, and it’s a 3-hour direct train from Edinburgh, so, y’know, why not). Unfortunately, I found a mega-critical bug on the flight, and did not sleep. It’s unfortunate because I landed at 9am in Manchester, and I couldn’t sleep that day because there was a once-in-a-generation solar eclipse happening in Scotland that I couldn’t miss. So I powered through 27 hours of being awake, and conked out spectacularly once the eclipse was over.
Hackbot
Where do I begin on this? I’ve gone through several iterations, but currently I’ve settled on a scalable Human In The Loop design. I really didn’t have much success with pre-authentication vulnerabilities so I changed tactics and focused on post-auth bugs instead, which yielded my first few findings. I have another tactic but that’s my most successful one at the moment, so forgive me for not sharing it here.
I’m not confident in bug bounty as a long-term career anymore. Yes, we can argue that the frontier just moves, and that you always need to keep up, but bug bounty is hitting its limits for me in terms of fulfilment. So in the next few months I’ll either go all-in on the startup side and reduce bug bounty to a hobby, or I’ll start working somewhere in a security research role. I’m not sure which yet but I’ll be exploring options in both directions.
Resources
Signal Over Noise: AI Agents and the Operator Moat: My friend Ads had an episode with CTBB recently. In it, they cited this article, which I found very interesting. It goes in-depth into the stats and methodology of his hackbot, built without relying on frontier models.
A Shell Is Worth a Thousand Images: Bing Images RCEs: Latest XBOW research. I admire the work that XBOW do, but I definitely question their business moat in the current security climate, where Ads (above) can single-handedly produce a competitive hackbot with impressive results. Maybe they can correct me here.
CookieLess DuoDrop Was Back: A partial bypass of the original DuoDrop research.
OverSecured’s Samsung Vulnerabilities: Oversecured is the work of bagipro, a legendary mobile hacker in the bug bounty space. He just dropped 176 bugs!
frontier class vulnerabilities: it gets worse before it (maybe) gets better: Shubs’ thoughts on the state of security research.
security researchers are doomed: Lupin’s take on the state of security research.
FastJson 1.2.83 Remote Code Execution: RCE in FastJson, courtesy of FearsOff.
