>be me
>find exposed phpinfo file with ssh/sftp/database creds, private keys, & tokens during external pentest
>creds work & give access to customer data
>contact customer
>customer devs working w/ 3rd party tool
> 3rd party tool: “oh yeah it’s supposed to be public”
>???
Black Badge @DEFCON, Social Engineering | Private Investigator | Locksmith | Offensive Security Consultant

