As a senior security engineer for the Bishop Fox Capability Development team, Dan builds hacker tools, focusing on attack surface discovery. Dan has extensive experience with application penetration testing (static and dynamic), product security reviews, network penetration testing (external and internal), and cryptographic analysis. He has presented at several Black Hats and DEF CONs on topics such as hacking smart safes, hijacking Google Chromecasts, and weaponizing AI. He has developed several open-source tools including Untwister, which breaks pseudorandom number generators and Unredacter, a tool that takes unredacted, pixelized text and reverses it back into its unredacted form. Additionally, Dan has been quoted in Wired, The Guardian, Business Insider, and Mashable. Dan holds both a Bachelor of Science and a Master of Science in Computer Science from Arizona State University.
Aug 09, 2023
Badge of Shame - Breaking Into Secure Facilities with OSDP
Jan 25, 2023
EzAdsPro BlackBox Advisory
Aug 24, 2022
You're (Still) Doing IoT RNG
Feb 15, 2022
Never, Ever, Ever Use Pixelation for Redacting Text
Dec 27, 2021
How Bishop Fox Has Been Identifying and Exploiting Log4shell
Nov 15, 2021
Eyeballer 2.0 Web Interface and Other New Features
Aug 05, 2021
You're Doing IoT RNG
Jun 04, 2021
SCOTUS CFAA Ruling: What does it mean for pen testers and security?
Mar 09, 2021
Understanding the Driving Factors of a Pen Test
Dec 15, 2020
What We Know (And Don’t) About The SolarWinds Orion Hack So Far
Nov 10, 2020
Cheating at Online Video Games and What It Can Teach Us About AppSec (Part 3)
Nov 02, 2020
Cheating at Online Video Games and What It Can Teach Us About AppSec (Part 2)
Oct 29, 2020
Cheating at Online Video Games and What It Can Teach Us About AppSec (Part 1)
Oct 20, 2020
Accidentally Secure Is Not Secure: A Case of Three Stooges Syndrome
Jun 25, 2020
Stop Treating Breaches Like Natural Disasters: A New Mindset for Application Security
Feb 03, 2020
Dufflebag: Uncovering Secrets in Exposed EBS Volumes
Sep 02, 2019
Cybersecurity Fatalism - How It Poisons Your Decision Making
Aug 08, 2019
Meet Eyeballer: An AI-powered, Open Source Tool for Assessing External Perimeters
Jun 30, 2018
WPA3 Is a Major Missed Opportunity: Here's Why
Mar 08, 2017
The CIA Leak: A Look On the Bright Side...
Aug 10, 2016
Game Over, Man! Reversing Video Games to Create an Unbeatable AI Player
Jul 28, 2015
On the "Brink" of a Robbery
Aug 05, 2014
Untwisting the Mersenne Twister: How I Killed the PRNG
Jul 16, 2014
The Rickmote Controller: Hacking One Chromecast at a Time
Fortifying Your Applications: A Guide to Penetration Testing
Download this eBook to explore key aspects of application penetration testing, questions to ask along the way, how to evaluate vendors, and our top recommendations to make the most of your pen test based on almost two decades of experience and thousands of engagements.
What the Vuln: Zimbra
Watch the inaugural episode of our What the Vuln livestream series as we examine Zimbra Zip Path Traversal vulnerabilities, CVE-2022-27925 and CVE-2022-37042.
Unredacter Challenge: John L.'s Solution
Challenge Accepted! We asked the security community to take Unredacter to the next level by decoding our secret blurred message. Watch as John L. showcases his solution.
Unredacter Challenge: Shawn A.'s Solution
Challenge Accepted! We asked the security community to take Unredacter to the next level by decoding our secret blurred message. Watch as Shawn A. showcases his solution.
Unredacter Challenge: Alejandro's Solution
Challenge Accepted! We asked the security community to take Unredacter to the next level by decoding our secret blurred message. Watch as Alejandro showcases his solution.
Eyeballer: Automating Security Triage with Machine Learning
This easy-to-follow guide explores the capabilities of Eyeballer, a first-of-its-kind AI-powered pen testing tool.
Dufflebag: Uncovering Secrets in Exposed EBS Volumes
In this video, Dan Petro demonstrates how the Bishop Fox open source tool Dufflebag works.
This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.