Arrived in Berlin for @offensivecon.bsky.social. Donβt be shy and say hi! Looking forward to meet old and new friendsπ
15.05.2025 14:06 β π 1 π 0 π¬ 0 π 0@matthiaskaiser.bsky.social
Java/Android Vulnerability Researcher. 0xACED. Ex-Apple. Posts are my own.
Arrived in Berlin for @offensivecon.bsky.social. Donβt be shy and say hi! Looking forward to meet old and new friendsπ
15.05.2025 14:06 β π 1 π 0 π¬ 0 π 0After many hours of development my Smalidea fork supports:
- parameters and variables with type information
- conditional breakpoints
- change parameters and variables via "expression" or "setValue". Quite happy with the results π
3. Parameters and Variables in Debug View π
23.03.2025 12:41 β π 0 π 0 π¬ 0 π 0I guess I'm the only single person working on an IntelliJ plugin using Eclipseπ
21.03.2025 13:53 β π 3 π 0 π¬ 0 π 02. Type Hierarchy
21.03.2025 13:46 β π 0 π 0 π¬ 2 π 0Look Mom, smalidea (github.com/JesusFreke/s...) has new features: 1. Call-Hierarchy
21.03.2025 13:45 β π 3 π 1 π¬ 1 π 0My first watchTowr post is out! It was my first take on a CMS solution and I was able to get some interesting pre-auth RCE chains on Kentico Xperience. π
labs.watchtowr.com/bypassing-au...
If you're using ruby-saml or omniauth-saml for SAML authentication make sure to update these libraries as fast as possible! Fixes for two critical authentication bypass vulnerabilities were published today (CVE-2025-25291 + CVE-2025-25292).
github.blog/security/sig...
Finally had some time to put together a new blog post. Itβs not groundbreaking, but it could still be interesting if you're into application security.
28.02.2025 09:56 β π 2 π 2 π¬ 0 π 0I tried VSC Java debugging once and immediately gave up. Debugging Ghidra with Eclipse works perfectly. And probably IDEA as well.
08.02.2025 18:22 β π 0 π 0 π¬ 1 π 0New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
30.01.2025 18:37 β π 66 π 42 π¬ 2 π 0Congrats π π Looking forward to the upcoming RCEsπ
07.01.2025 13:17 β π 1 π 0 π¬ 0 π 0I'm happy to announce that I have recently joined watchTowr as a Principal Vulnerability Researcher. The break is over, it's time to do some new research π«‘
07.01.2025 13:08 β π 8 π 2 π¬ 1 π 0Congrats! All the best π₯³
01.01.2025 15:17 β π 1 π 0 π¬ 0 π 0Thx!
02.12.2024 06:21 β π 0 π 0 π¬ 0 π 0I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy!
Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...
π and Hi :-)
21.12.2023 14:04 β π 0 π 0 π¬ 1 π 0