Bishop Fox named “Leader” in 2024 GigaOm Radar for Attack Surface Management. Read the Report ›

Meet the Author

Dan Petro Senior Security Engineer

As a senior security engineer for the Bishop Fox Capability Development team, Dan builds hacker tools, focusing on attack surface discovery. Dan has extensive experience with application penetration testing (static and dynamic), product security reviews, network penetration testing (external and internal), and cryptographic analysis. He has presented at several Black Hats and DEF CONs on topics such as hacking smart safes, hijacking Google Chromecasts, and weaponizing AI. He has developed several open-source tools including Untwister, which breaks pseudorandom number generators and Unredacter, a tool that takes unredacted, pixelized text and reverses it back into its unredacted form. Additionally, Dan has been quoted in Wired, The Guardian, Business Insider, and Mashable. Dan holds both a Bachelor of Science and a Master of Science in Computer Science from Arizona State University.

Past Speaking Engagements:

Subject Matter Expertise:

  • Network security
  • IoT and product security
  • AI/machine learning
  • CFAA
  • DNS exploits
  • DDoS attacks
  • Malware
Dan Petro

Posts from Dan Petro

Aug 09, 2023

Badge of Shame - Breaking Into Secure Facilities with OSDP

Jan 25, 2023

EzAdsPro BlackBox Advisory

Aug 24, 2022

You're (Still) Doing IoT RNG

Feb 15, 2022

Never, Ever, Ever Use Pixelation for Redacting Text

Dec 27, 2021

How Bishop Fox Has Been Identifying and Exploiting Log4shell

Nov 15, 2021

Eyeballer 2.0 Web Interface and Other New Features

Aug 05, 2021

You're Doing IoT RNG

Jun 04, 2021

SCOTUS CFAA Ruling: What does it mean for pen testers and security?

Mar 09, 2021

Understanding the Driving Factors of a Pen Test

Dec 15, 2020

What We Know (And Don’t) About The SolarWinds Orion Hack So Far

Nov 10, 2020

Cheating at Online Video Games and What It Can Teach Us About AppSec (Part 3)

Nov 02, 2020

Cheating at Online Video Games and What It Can Teach Us About AppSec (Part 2)

Oct 29, 2020

Cheating at Online Video Games and What It Can Teach Us About AppSec (Part 1)

Oct 20, 2020

Accidentally Secure Is Not Secure: A Case of Three Stooges Syndrome

Jun 25, 2020

Stop Treating Breaches Like Natural Disasters: A New Mindset for Application Security

Feb 03, 2020

Dufflebag: Uncovering Secrets in Exposed EBS Volumes

Sep 02, 2019

Cybersecurity Fatalism - How It Poisons Your Decision Making

Aug 08, 2019

Meet Eyeballer: An AI-powered, Open Source Tool for Assessing External Perimeters

Jun 30, 2018

WPA3 Is a Major Missed Opportunity: Here's Why

Mar 08, 2017

The CIA Leak: A Look On the Bright Side...

Aug 10, 2016

Game Over, Man! Reversing Video Games to Create an Unbeatable AI Player

Jul 28, 2015

On the "Brink" of a Robbery

Aug 05, 2014

Untwisting the Mersenne Twister: How I Killed the PRNG

Jul 16, 2014

The Rickmote Controller: Hacking One Chromecast at a Time

Resources from Dan Petro

image of purple eBook cover with blue text and white page with graphs on dark background
Guide

Fortifying Your Applications: A Guide to Penetration Testing

Download this eBook to explore key aspects of application penetration testing, questions to ask along the way, how to evaluate vendors, and our top recommendations to make the most of your pen test based on almost two decades of experience and thousands of engagements.

Learn More
Bishop Fox Livestream Zimbra Tile
Webcast

What the Vuln: Zimbra

Watch the inaugural episode of our What the Vuln livestream series as we examine Zimbra Zip Path Traversal vulnerabilities, CVE-2022-27925 and CVE-2022-37042.

Learn More
Screenshot of video of Dan Petro interviewing John L about the Unredacter challenge
Video

Unredacter Challenge: John L.'s Solution

Challenge Accepted! We asked the security community to take Unredacter to the next level by decoding our secret blurred message. Watch as John L. showcases his solution.

Learn More
Screenshot of video of Dan Petro interviewing Shawn A about the Unredacter challenge
Video

Unredacter Challenge: Shawn A.'s Solution

Challenge Accepted! We asked the security community to take Unredacter to the next level by decoding our secret blurred message. Watch as Shawn A. showcases his solution.

Learn More
Video screenshot of Dan Petro interviewing Alejando about the security tool challenge
Video

Unredacter Challenge: Alejandro's Solution

Challenge Accepted! We asked the security community to take Unredacter to the next level by decoding our secret blurred message. Watch as Alejandro showcases his solution.

Learn More
Bishop Fox Eyeballer ebook cover page
Guide

Eyeballer: Automating Security Triage with Machine Learning

This easy-to-follow guide explores the capabilities of Eyeballer, a first-of-its-kind AI-powered pen testing tool.

Learn More
Dufflebag uncovering secrets in exposed ebs volumes Video Thumbnail
Video

Dufflebag: Uncovering Secrets in Exposed EBS Volumes

In this video, Dan Petro demonstrates how the Bishop Fox open source tool Dufflebag works.

Learn More

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.