Caido, Learning and Food

public
5 min read
Caido, Learning and Food

Table of contents

It's been quite a chill week, focusing on my new programs and playing games.

Caido

My friend Mizu and I looked at the latest Caido plugins, and that's amazing. It's been a while since I looked at them, and the Store is now full of very nice plugins. Here are some of the best :

Drop

GitHub - caido-community/drop: A plugin for collaboration in Caido
A plugin for collaboration in Caido. Contribute to caido-community/drop development by creating an account on GitHub.

It's the best way to collaborate with someone else. On your Replay tab or anywhere, you have a little dropdown to send the request to one of your friends. This way, he will receive it directly on his caido, which is amazing.

It's way better than copying it, sending it through Discord, trying to put it on your Caido, setting the URL, boring.

Shift

GitHub - caido-community/shift: Seamless AI Integration into Caido
Seamless AI Integration into Caido. Contribute to caido-community/shift development by creating an account on GitHub.

It's now totally free and included in the Caido Plan, which is really great. With it, you can automatically rename Replay Tabs using AI, which can be useful in some cases, so as not to be lost.

It's also possible to use AI directly on Caido to help you, to have a memory of some IDs you're using a lot.

Note++

GitHub - caido-community/NotesPlusPlus: Markdown Notes for Caido
Markdown Notes for Caido. Contribute to caido-community/NotesPlusPlus development by creating an account on GitHub.

This one is really game-changing. You can have your notes in Markdown directly per project.

You can also put in the notes some replay tabs, and click to come back to them. It's really great to have one tool to rule them all. Now I only need Caido to be open when hunting. No need for other tools, just the proxy.

QuickSSRF

GitHub - caido-community/quickssrf: Detect SSRF within Caido
Detect SSRF within Caido. Contribute to caido-community/quickssrf development by creating an account on GitHub.

It's the equivalent of the Collaborator from Burp. It's amazing as this is the same, so you can also use it for FTP, SMTP, etc, pretty great.

The only missing thing I see is the ability to modify the response as bebiks did it on his tool https://ssrf.cvssadvisor.com/, which is pretty useful. I hope they will add the possibility to do it soon.

I also use other plugins, so go check all of them to see which one fits your needs.

It's now very easy to build your own. I really need to come back on that and building mine.

Learning

I also received this new book. I never looked at this type of vulnerability, doing research, fuzzing, and so on. So it can be great for me to learn, just the basics, to be aware of how to do it.

It can also be helpful for some bug bounty programs, so let's see if it interests me or not.

From Day Zero to Zero Day

I really love to learn new stuff, but I'm also pretty bad at not switching my focus. I can learn something pretty fast, be quite good at it, and then totally abandon and forget about it.

I found after many years that it's not my thing to be excellent at one thing, even if it's really what I wanted to do. It's hard to admit it, but it's the case. But as I'm pretty good at understanding anything, and pretty fast, I need to use that as a force instead of trying to find the one thing to focus on.

Speaking of learning, ChatGPT is just releasing new stuff that is amazing. First, the agent one. It's not as good as building yours at the moment, but it's pretty great to see that it's available to anyone, and easy to use, so in the next months it will be game-changing.

Also, a new Study Mode has been released, which can be very useful to learn new stuff. It will not give you the answer directly, but ask you some questions to help you find the answer. To learn cybersecurity, it will be game-changing as well.

Food

I love to cook and make a really good meal. But sometimes, it's annoying doing it. Especially when you're focused on something, trying to pop a bug. Or when you're playing Mario Kart with friends.

The thing is that, as I'm pretty sporty, I want to eat good food, with proteins and stuff. So prepared meals are usually full of carbs and not made for performance.

Also, I tend to always eat the same things, chicken with vegetables and rice. It's nice but pretty boring, and I'm too lazy to prepare nice food only for me.

So what are my options? Hiring a private chef to cook me good stuff ? That can be amazing, but I'm still not rich enough to do it.

There are some options in Paris for prepared food that can be delivered every week, it's like ~100 euros per week, which is already what I'm paying for my own food, so it can be a good alternative. But some of them are mainly made to lose weight, which is not my need.

With a friend, we will probably try some of them and see if the quantities are enough and if the food is good enough.

Aituglo

Aituglo

Paris
The author of this blog, a bug bounty hunter and security researcher that shares his thoughts about the art of hacking.