RSSAmplifier

Blog

Eaton Works Feed

Feed of news/blog postings on the Eaton Works website.

eaton-works.comRSS feed ↗38 posts

Latest posts

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

VE Commercial Vehicles My Eicher platform had a critical vulnerability that let you take over anyone s account and gain control over their vehicle fleets.

Inside an AI coal mine security camera network powered by plaintext passwords

Coal India s intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.

Exploiting vulnerabilities in Johnson & Johnson web apps

Campus Recruiting vulnerability exposed student information, and Audit Tracking Management System vulnerability exposed confidential internal audit data.

Using cookies to hack into a tech college’s admission system

The Sri Krishna College of Engineering and Technology (SKCET) in India made elementary mistakes in web app security.

Hacking a pharmacy to get free prescription drugs and more

Super admin exploit on Dava India Pharmacy s website gave complete control over everything.

I’m The Captain Now: Hijacking a global ocean supply chain network

Exploring security blunders in Bluspark Global s BLUVOYIX, an ocean logistics / supply chain platform used by hundreds of the world s largest companies.

A Cracker Barrel vulnerability

Cracking open the rewards admin panel.

Hacking India’s largest automaker: Tata Motors

Tata Motors gave away the keys to their infrastructure and customer data on their public websites.

(DEF CON 33) How I hacked over 1,000 car dealerships across the US

On August 10, 2025 at DEF CON 33 in Las Vegas, I presented what could possibly be the biggest vulnerability I may ever discover in the automotive industry. Read and watch how I managed to take over a top automaker s entire dealer ecosystem.

Taking remote control over industrial generators

Industrial generator smart platform had insecure APIs that could enable remote control by anyone.

Intel Outside: Hacking every Intel employee and various internal websites

Hardcoded credentials, pointless encryption, and generous APIs exposed details of every employee and made it possible to break into internal websites.

I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny

A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people s delivery orders, view user information, and more.

How 1 Exposed Honeywell API Gave me Control Over an Internal Engineering System

(ASPEN) APIs are crucial for web apps but pose security risks. I uncovered a critical flaw in Honeywell s BEDQ system, highlighting the need for strong API security.

Gaining admin access to a Siemens cloud system

(ASPEN) Understanding the Risks of Client-Side Authentication: Why relying on client-side security isn’t enough.

Lessons in Securing Mobility Site Management APIs

(ASPEN) Mobile device management (MDM) systems are essential for large enterprises to track devices accessing the corporate network and ensure security. Read how a vulnerability on Johnson & Johnson s Mobility Service Portal made it possible to access employee corporate devices.

Angular-ing for AuthZ, Problematic anti-patterns in Single Sign On Systems

(ASPEN) A critical SSO vulnerability in a Fortune 500 app risked millions of records. Learn about SSO security risks, fixes, and protecting APIs from similar attacks.

Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website

A vulnerable API on Toyota Tsusho Insurance Broker India s premium calculator website exposed Microsoft corporate cloud credentials.

CVE-2023-6483: Improper/missing API authentication in ADiTaaS v5.1

The story of CVE-2023-6483, my first CVE and biggest security disclosure yet.

Tapping into a telecommunications company’s office cameras

API flaw enabled livestreaming of a telecommunications company’s office cameras.

Compromising Honda’s power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API

A vulnerable password reset API made it possible to take over any account and gain admin-level access to the platform. In addition, broken/missing access controls made it possible to access all data on the platform.

Insecure Toyota CRM exposed Mexican customer information

Breaking into a Toyota CRM and exploiting it to view customer information.

Hacking into Toyota’s global supplier management network

Inside an exploit that allowed logging in to Toyota s GSPIMS application as any user, including system admins.

Syndication feed now available

An Atom feed is now available for the site.

How the Xbox 360 knows if your hard-drive is genuine

Reverse engineering the kernel-mode authenticity check, and how Microsoft knows about your hacked/custom hard-drive.

How Microsoft attempted to make the Xbox 360 dashboard load faster

The October 2012 Xbox 360 dashboard update moved the dashboard from the nand flash to the hard-drive. Does it make a difference?

Hacking into the worldwide Jacuzzi SmartTub network

Two vulnerable Jacuzzi SmartTub administration panels exposed worldwide customer data for multiple brands.

Microsoft accidentally exposed their private Xbox game developer forums

A misconfigured staging site exposed several years worth of private Xbox game developer forum content.

Building the new Eaton Works website

The tech stack and decisions behind my new website.

An experience with Daimler’s vulnerability reporting program

Reporting sensitive content exposure on an MBUSA website to Daimler.

DevTool Source Code Released

Find it on GitHub!

Reverse engineering and removing Pokémon GO’s certificate pinning

A deep dive into Pokémon GO s certificate pinning.

Now Fully HTTPS

Also: HSTS!🔒

DevTool Released

An old, private Xbox 360 development application has been released.

FATXplorer update released

An update to the FATXplorer application has been released. The purpose of this update is to bring further stability to the previous version and to address various issues reported by customers.

Transition to the Disqus commenting system

Disqus now powers comments on this site.

FATXplorer v2.5 released!

A major update is now available for FATXplorer. Check it out!

XePatch Released

A small and simple Xbox 360 patch viewer/editor.

New Homepage!

Welcome to my new homepage!