MonkeHacks #63

Client-Side Tips, Pushups, Pressure

MonkeHacks #63

It’s been a sunny week here in Edinburgh. My friend from Sweden is visiting me at the moment, so that’s kept me occupied, and otherwise I’ve continued pentesting and upskilling.

I found a really nice park area near my flat, and I can express nothing short of immense disappointment in myself for not finding it sooner. There’s a cycle path stretching across a quarter of Edinburgh, and I had no idea that it existed and passed right by my apartment.

I’m definitely feeling the pressure of my upcoming talks now. I’ll do my best to deliver a good presentation. I generally cope well under pressure but it’s starting to encroach on my comfort a bit. Contrary to what you’d think, the best thing to do in these situations is to take care of yourself and be in your best healthy state, because that allows you to work more consistently, rather than chugging Red Bull to get through the workload.

Some cool allotments here in Edinburgh, that I discovered on the cycle path.

Weekly Ideas / Notes 

  • Jorian noted a way to alter the parameters being sent by a form, if the injection point is after the form declaration. This is one of those things that you put into your notes for a future bug - and you may regret it if you don’t.

  • Not just that - slonser noted an amazing way to leak the URL of a page using only an image. This might be fixed by Chrome soon - exploit (ethically) while you can!

  • avlidienbrunn released Archive Alchemist - a tool to test extraction vulnerabilities in archives such as ZIP and TAR files.

  • I spent a few hours working on Intigriti’s May Challenge by the one and only Johan Carlsson. It’s quite difficult. I’ve not solved it yet, I think I’m about 70% of the way there.

  • I’ve been doing 100 pushups a day every day this week (a habit I picked up from my friend Kodai). It’s another habit I want to maintain, and it joins my existing habits of studying German and Arabic, journalling, and walking at least 10,000 steps a day. Small, consistent steps.

  • I’ll be on the hacker panel at Security@ UK 2025 in London on June 4! If you’re going to it, please say hello!

  • That’s all for this week. Ironically, I have more to write about when I’m less busy. This week has just been insanely hectic. Until next time!

Resources