Readit News logoReadit News
EatonZ commented on Hacking India's largest automaker: Tata Motors   eaton-works.com/2025/10/2... · Posted by u/EatonZ
connectsnk · 5 months ago
Are there any open source tools that scans the code and detects such gaffes
EatonZ · 4 months ago
TruffleHog: https://trufflesecurity.com/trufflehog

I worked for them a little bit and their product is really impressive and works great.

EatonZ commented on Hacking India's largest automaker: Tata Motors   eaton-works.com/2025/10/2... · Posted by u/EatonZ
hannofcart · 4 months ago
> As recently seen with Intel, there seems to be a trend where developers will do this pointless client-side decryption. When the client has the key, it’s strange that anyone would think that would be secure.

I stay and work in India. Yesterday, as part of a VAPT audit by a third party auditor, the auditors "recommended" that we do exactly this. I wonder if this directive comes as part of some outdated cyber security guidelines that are passed around here? Not entirely sure.

When I asked them about how I'd pass the secret to the client to do the client side encryption/decryption without that key being accessible to someone who is able to MITM intercept our HTTPS only API calls anyway, the guy basically couldn't understand my question and fumbled around in his 'Burp' suite pointing exasperatedly to how he is able to see the JSON body in POST requests.

Most of the security people we've met here, from what I can tell are really clueless. Internally, we call these guys "burp babies" (worse than "script kiddies") who just seem to know how to follow some cookie cutter instructions on using the Burp suite.

EatonZ · 4 months ago
Appreciate the insight!
EatonZ commented on Exploiting McDonald's APIs to hijack deliveries and order food for a penny   eaton-works.com/2024/12/1... · Posted by u/2bluesc
foxyv · a year ago
So what you are saying is, they are working for exposure?
EatonZ · a year ago
There are certainly more things I could have done to get more $/hour. I ultimately find these things enjoyable and help keep my skills sharp.

u/EatonZ

KarmaCake day525August 1, 2016
About
https://eaton-works.com/
View Original