Obtaining database passwords from a billion-dollar company

from blog Mac's Tech Blog, | ↗ original
↗ original
This is a story about how in 2021, I discovered a vulnerability affecting an unnamed billion-dollar company and disclosed it to them, earning my largest bug bounty ever! Accidental Discovery At first, I was just doing some work on kubecost, a Kubernetes tool which estimates costs for running pods. The first thing that caught my security eye was...