Blog posts by Hans-Martin Münch
CEO at MOGWAI LABS
| 12 min read
Exploiting deserialization vulnerabilities in Java 17 and beyond, using JDBC connections
| 8 min read
Vulnerability Spotlight: RCE in Ajax.NET Professional
Vulnerability / exploitation details for CVE-2021-23758
| 8 min read
Vulnerability notes: Log4Shell
Everything you should know about the Log4Shell vulnerability (CVE-2021-44228)
| 13 min read
Vulnerability digging with CodeQL
Using CodeQL based variant analysis to find vulnerabilties
| 14 min read
A closer look at the RMI Registry whitelist bypass gadget from An Trinhs Blackhat Europe 2019 presentation
| 7 min read
How to use a SNMP write community to gain (remote) code execution as root on Linux systems
| 17 min read
Attacking RMI based JMX services
An attack primer on how to hack into RMI based JMX services
| 24 min read
Attacking Java RMI services after JEP 290
An attack primer on how to attack Java RMI services using Java deserialization
| 5 min read
A quick and easy guide for binary patching and repacking iOS apps during security audits