I found 900 S3 buckets exposing Terraform state files. 41 had live AWS credentials.
I built a scanner that guesses S3 bucket names and looks for .tfstate files.…
I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty.
I was poking at a fintech’s mobile API and noticed something that…