Heshie B.

Heshie B.

Brooklyn, New York, United States
11K followers 500+ connections

About

I'm currently a Technical Lead at Morgan and Morgan PA (America's largest personal injury…

Services

Experience

  • Morgan & Morgan, P.A. Graphic

    Morgan & Morgan, P.A.

    Brooklyn, New York, United States

  • -

    Brooklyn, New York, United States

  • -

    New York City Metropolitan Area

  • -

    New York, NY, United States

  • -

    Brooklyn

Education

  • Flatiron School Graphic

    Flatiron School

    -

    Activities and Societies: Ruby on Rails, React, Redux, Node.

    Full Stack Software Engineering Program

  • -

    Activities and Societies: 75-Hour Salesperson Licensing Course

    75-Hour Salesperson Licensing Course
    A Real Estate Salesperson (Agent) is hired to facilitate a property purchase, sale or rental transaction on behalf of their client for compensation under the guidance and supervision of a sponsoring Broker.

  • -

Licenses & Certifications

  • NYS Licensed Real Estate Salesperson

    NYS Department of State

    Issued
  • MLO

    NYS Department of Tax & Finance

    Credential ID 1229914

Publications

  • https://www.oracle.com/security-alerts/cpuapr2020.html

    Oracle Critical Patch Update Advisory

    Really exciting to be acknowledged by Oracle on discovering a hole on their Opower API which allowed unauthorized users to access electricity meter data.

    I discovered this while I was studying at the Flatiron School and had that week learned about API’s and user authorization so I thought I’ll poke around Con Edison’s website to see if everything was locked down all right and to my surprise discovered this open API endpoint.

    Make sure to pentest your APIs by a fresh pair of eyes…

    Really exciting to be acknowledged by Oracle on discovering a hole on their Opower API which allowed unauthorized users to access electricity meter data.

    I discovered this while I was studying at the Flatiron School and had that week learned about API’s and user authorization so I thought I’ll poke around Con Edison’s website to see if everything was locked down all right and to my surprise discovered this open API endpoint.

    Make sure to pentest your APIs by a fresh pair of eyes since sometimes easy to miss/fix vulnerabilities can cause a great deal of headaches and can make you lose customer trust which is hard to get back.

    See publication

Projects

  • Ship-Matix

    - Present

    Shipmatix.com will be a shipping tool that downloads and processes orders via the Shipstation API. It saves hundreds of hours of employee time by automatically selecting the cheapest shipping option available.

    See project
  • Driven Work

    -

    A social style site that helps people find companies by technologies or innovations they're passionate about.
    Use case: Employment, research etc.

    See project

Languages

  • English

    Full professional proficiency

  • Yiddish

    Full professional proficiency

  • Hebrew

    Native or bilingual proficiency

Recommendations received

View Heshie’s full profile

  • See who you know in common
  • Get introduced
  • Contact Heshie directly
Join to view full profile

Other similar profiles

Explore collaborative articles

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Explore More