Analyzing Open Buckets: a Beginner’s Journey Through Misplaced Secrets

Track 1 - Jungle

Thu, 30 Jun 2022 @ 15:20:00

In this talk I’ll discuss what I learned going into my first role in cyber security, as I joined a threat intelligence team that discovers publically accessible buckets on the Internet, and reports them to their owners for remediation. From simple challenges such as why nothing happens when I type my password into the terminal (hint: the terminal doesn’t show passwords) to automating myself out of a job with a script, only to learn to do more. I will also discuss two specific case studies.