Pandora’s Box: Another New Way to Leak All Your Sensitive Data

We began enumerating for sub-domains of other company’s Box accounts through standard open source intelligence. These can be easily verified by going to If the link returns the company’s logo, they have a paid account and are probably susceptible.

Image courtesy of: Jordan Potti