<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on naveen srinivasan</title><link>https://naveensrinivasan.com/tags/security/</link><description>Recent content in Security on naveen srinivasan</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 07 Aug 2026 07:06:00 -0500</lastBuildDate><atom:link href="https://naveensrinivasan.com/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Finding Hidden Internal Apps Through Public Certificate Logs</title><link>https://naveensrinivasan.com/posts/2026-08-07-finding-hidden-internal-apps-through-public-certificate-logs/</link><pubDate>Fri, 07 Aug 2026 07:06:00 -0500</pubDate><guid>https://naveensrinivasan.com/posts/2026-08-07-finding-hidden-internal-apps-through-public-certificate-logs/</guid><description>&lt;p&gt;Here is how anyone can unwrap the organization&amp;rsquo;s internal tools/products that no one is supposed to know about.&lt;/p&gt;
&lt;p&gt;Typically, in software organizations, most of us don&amp;rsquo;t want to share internal applications on the internet, but we unintentionally share application names by requesting certificates. The issued certs get into the Certificate Transparency (CT) logs &lt;a href="https://certificate.transparency.dev/"&gt;https://certificate.transparency.dev/&lt;/a&gt;, which are a Merkle tree that allows the rest of the world to see them. With this, anyone can access internal finance, upcoming products that had code names, etc.&lt;/p&gt;</description></item></channel></rss>