← All talks

Secrets That Survive: Finding Runtime Credentials in Production Web Applications - Hemanth Gorijala

BSides SATX34:29139 viewsPublished 2026-07Watch on YouTube ↗
About this talk
BSides San Antonio 2026 June 13 at St. Mary's University A bug bounty researcher found Azure credentials in a JavaScript file and called it done. I kept going — four Azure AD credentials, enough to authenticate as the application itself. Full account takeover. The organization had GitLeaks in CI/CD and static secret scanning. The credentials were still live. Shift-left tools scan what you commit. They do not scan what you serve. Once a secret reaches production, it disappears from every scanner's view.
[ feedback ]