Advertisement · 728 × 90

Posts by Matthias Kaiser

Post image

And smalidea-ng gets initial renaming support 👍!

1 month ago 0 0 0 0

Looking so much forward to have a lot of time soon to work on exciting projects I always wanted to work on full-time 😎🍀

1 month ago 3 0 0 0
Post image

smalidea-ng now supports line mapping between Smali and Java thanks to JADX. This also works while debugging of Smali code.

4 months ago 1 0 0 0
Post image

And finally smalidea-ng gets initial decompiler support (thanks to @Skylot for JADX). Still some work ahead👍

4 months ago 1 0 0 0
Pointer leaks through pointer-keyed data structures Posted by Jann Horn, Google Project Zero Introduction Some time in 2024, during a Project Zero team discussion, we were talking about how...

Super cool potential ASLR leak involving dictionary hashes! googleprojectzero.blogspot.com/2025/09/poin...

6 months ago 10 6 0 0
Post image

smalidea-ng: The moment your method references are indexed and your call-hierarchy returns within a second.

7 months ago 1 0 0 0

Arrived in Berlin for @offensivecon.bsky.social. Don’t be shy and say hi! Looking forward to meet old and new friends👍

11 months ago 1 0 0 0
Post image

After many hours of development my Smalidea fork supports:
- parameters and variables with type information
- conditional breakpoints
- change parameters and variables via "expression" or "setValue". Quite happy with the results 😀

1 year ago 1 0 0 0
Post image

3. Parameters and Variables in Debug View 😍

1 year ago 0 0 0 0
Advertisement

I guess I'm the only single person working on an IntelliJ plugin using Eclipse😀

1 year ago 3 0 0 0
Post image

2. Type Hierarchy

1 year ago 0 0 2 0
Post image

Look Mom, smalidea (github.com/JesusFreke/s...) has new features: 1. Call-Hierarchy

1 year ago 3 1 1 0
Preview
Bypassing Authentication Like It’s The ‘90s - Pre-Auth RCE Chain(s) in Kentico Xperience CMS I recently joined watchTowr, and it is, therefore, time - time for my first watchTowr Labs blogpost, previously teased in a tweet of a pre-auth RCE chain affecting some ‘unknown software’. Joining th...

My first watchTowr post is out! It was my first take on a CMS solution and I was able to get some interesting pre-auth RCE chains on Kentico Xperience. 😎

labs.watchtowr.com/bypassing-au...

1 year ago 7 3 0 0
Preview
Sign in as anyone: Bypassing SAML SSO authentication with parser differentials Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

If you're using ruby-saml or omniauth-saml for SAML authentication make sure to update these libraries as fast as possible! Fixes for two critical authentication bypass vulnerabilities were published today (CVE-2025-25291 + CVE-2025-25292).

github.blog/security/sig...

1 year ago 11 10 1 0

Finally had some time to put together a new blog post. It’s not groundbreaking, but it could still be interesting if you're into application security.

1 year ago 2 2 0 0

I tried VSC Java debugging once and immediately gave up. Debugging Ghidra with Eclipse works perfectly. And probably IDEA as well.

1 year ago 0 0 1 0
Windows Bug Class: Accessing Trapped COM Objects with IDispatch Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...

New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...

1 year ago 65 41 2 0
Advertisement

Congrats 👏 🎉 Looking forward to the upcoming RCEs😎

1 year ago 1 0 0 0

I'm happy to announce that I have recently joined watchTowr as a Principal Vulnerability Researcher. The break is over, it's time to do some new research 🫡

1 year ago 8 2 1 0

Congrats! All the best 🥳

1 year ago 1 0 0 0

Thx!

1 year ago 0 0 0 0
Remote Code Execution with Spring Properties Recently a past student came to me with a very interesting unauthenticated vulnerability in a Spring application that they were having a hard time exploiting...

I just wrote a new blog post! This is how I (ab)used a jailed file write bug in Tomcat/Spring. Enjoy!

Remote Code Execution with Spring Properties :: srcincite.io/blog/2024/11...

1 year ago 76 36 1 2

👍 and Hi :-)

2 years ago 0 0 1 0