Hacker Newsnew | past | comments | ask | show | jobs | submit | EatonZ's commentslogin

TruffleHog: https://trufflesecurity.com/trufflehog

I worked for them a little bit and their product is really impressive and works great.


Appreciate the insight!

There are certainly more things I could have done to get more $/hour. I ultimately find these things enjoyable and help keep my skills sharp.


It would be nice to see rewards that scale with severity. Ultimately they did accomodate me by sending a gift card I can use instead of coupons I would likely have given away, so I appreciate that. Most companies don't offer me anything!


Location: Florida, USA

Remote: Yes

Willing to relocate: No

Résumé/CV: https://eaton-works.com/resume/

Email: eaton@eaton-works.com

I am an experienced C# / .NET Windows desktop developer of more than 15 years with an interest in file systems, reverse-engineering, and security. Some of my recent security disclosures have been front-page news on major media outlets such as Automotive News[1] and TechCrunch[2].

Currently seeking new opportunities in the C# / .NET and/or security space.

Please see my website for a full catalog of my notable work: https://eaton-works.com/

[1] https://www.autonews.com/mobility-report/how-toyotas-supplie...

[2] https://techcrunch.com/2022/06/22/jacuzzi-flaws-admin-expose...


I have just put up an Atom feed, more details: https://eaton-works.com/2023/01/28/syndication-feed-now-avai...


https://i.imgur.com/AFZIA3p.png

It takes in the RSA signature, SHA data hash, and RSA key type. Key types are: XE_PIRS_RSA_KEY = 0x0, XE_LIVEDRM_RSA_KEY = 0x1, XE_DEVICE_RSA_KEY = 0x2 (this is the Sata verification key), XE_XSIGNER2_RSA_KEY = 0x3

It uses key type to load the corresponding public key from memory at static addresses, then verification takes place.


Thank you for the kind words :D My contact info is here: https://eaton-works.com/contact/


If anyone is interested in RSS you can subscribe here to be notified when it's available (I will post about it): https://eaton-works.com/subscribe

You can then unsubscribe & that will delete your email from my list, if you prefer RSS over emails.


Glad everyone enjoyed the writeup! I have several more interesting writeups planned, including a significant hack disclosure (not Xbox/gaming related), so keep an eye out (:


Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: