Sign in

m1tz

@m1tzzz.bsky.social
747 followers 134 following 5 posts

Web Security Expert | Bug Hunter | Käferjäger

PostsRepliesMedia
Reposted by m1tz
Frycos @frycos.bsky.social · 23/09/2026
Happy announcement: My colleague and me will present a talk at hardwear.io NL 2026, "Vulnerabilities That Get Under Your Skin: Targeting the World’s Best-Selling Infusion Pumps". 100% human-brain VR 😛
hardwear.io
Join Hardwear.io NL 2026 – The Ultimate Hardware Security Event
Connect with hardware security experts and hackers at Hardwear.io NL 2026 in Amsterdam. Experience trainings, talks, CTFs, and the HardPwn challenge this November.
042
Reposted by m1tz
codewhitesec.bsky.social @codewhitesec.bsky.social · 23/01/2026
You like technical deep dives into binary exploitation and crazy heap wizardry? Then you'll like our blog post about unauth'ed RCE in NetSupport Manager aka CVE-2025-34164 & CVE-2025-34165 code-white.com/blog/2026-01...
code-white.com
CODE WHITE | Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive
NetSupport Manager is a remote control and support software that we find surprisingly often utilized in sensitive *Operational Technology (OT)* environments, such as production plant networks. Besides...
068
Reposted by m1tz
Frycos @frycos.bsky.social · 15/11/2025
Just sayin‘ 🤷
042
Reposted by m1tz
codewhitesec.bsky.social @codewhitesec.bsky.social · 29/10/2025
Latest ≠ Greatest? A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS from our very own @mwulftange.bsky.social who loves converting n-days to 0-days code-white.com/blog/wsus-cv...
code-white.com
CODE WHITE | A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS
How the n-day research for a suspected vulnerability in Microsoft WSUS (CVE-2025-59287) led to the surprising discovery of a new `SoapFormatter` vulnerability added by the Patch Tuesday updates of Oct...
086
m1tz @m1tzzz.bsky.social · 07/10/2025
Did you encounter the Supabase? Might wanna try my newest tooling or have a read about quickwins? There you go: blog.m1tz.com/posts/2025/1...
blog.m1tz.com
A Hands-On Edition: Will Supabase Be the Next Firebase (At Least in Terms of Security)?
It all started with my good colleague @schniggie who’s got my attention with an X post earlier that year. Until then I rarely heared of Supabase, but let us start from the scratch. Firebase changed th...
021
Reposted by m1tz
Frycos @frycos.bsky.social · 15/09/2025
Tired of dull, standard interviews? Talk to Kurt. Also, a few of my colleagues and I will be attending BruCON next week. Feel free to come and talk to us.
061
Reposted by m1tz
codewhitesec.bsky.social @codewhitesec.bsky.social · 05/08/2025
We've added a new demo to NewRemotingTricks that makes deploying a MarshalByRefObject (e.g., WebClient) even easier: System.Lazy<T> creates an instance of T on serialization, which is probably more likely to be allowed than a XAML gadget getting through. github.com/codewhitesec...
github.com
GitHub - codewhitesec/NewRemotingTricks: New exploitation tricks for hardened .NET Remoting servers
New exploitation tricks for hardened .NET Remoting servers - codewhitesec/NewRemotingTricks
044
m1tz @m1tzzz.bsky.social · 18/07/2025
Stumbled upon your next Firebase target? You might want to take a closer look at this. blog.m1tz.com/posts/2025/0...
blog.m1tz.com
Hacking Firebase Projects: Enumeration and Common Misconfigurations
After encountering multiple Firebase-related security issues through professional assessments at work and bug bounty hunting, I felt it was important to bring more visibility to the security implicati...
020
Reposted by m1tz
codewhitesec.bsky.social @codewhitesec.bsky.social · 13/05/2025
Yes, we're beating a dead horse. But that horse still runs in corporate networks - and quietly gives attackers the keys to the kingdom. We're publishing what’s long been exploitable. Time to talk about it. #DSM #Ivanti code-white.com/blog/ivanti-...
code-white.com
CODE WHITE | Analyzing the Attack Surface of Ivanti's DSM
Ivanti's Desktop & Server Management (DSM) product is an old acquaintance that we have encountered in numerous red team and internal assessments. The main purpose of the product is the centralized dis...
088
Reposted by m1tz
Frycos @frycos.bsky.social · 28/04/2025
My blog post on some vulns in GFI MailEssentials frycos.github.io/vulns4free/2...
frycos.github.io
GFI MailEssentials - Yet Another .NET Target
What is this product GFI MailEssentials all about? We’re living the future, right? So let’s ask the GFI AI.
077
Reposted by m1tz
Julien | MrTuxracer @mrtuxracer.bsky.social · 10/04/2025
I do have quite a backlog of blog posts, so let's start with this one 😎
0102
Reposted by m1tz
codewhitesec.bsky.social @codewhitesec.bsky.social · 28/03/2025
Our crew members @mwulftange.bsky.social & @frycos.bsky.social discovered & responsibly disclosed several new RCE gadgets that bypass #Veeam 's blacklist for CVE-2024-40711 & CVE-2025-23120 + further entry points after @sinsinology.bsky.social & @chudypb.bsky.social 's blog. Replace BinaryFormatter!
096
Reposted by m1tz
Frycos @frycos.bsky.social · 02/12/2024
Most of you know about Telerik or DevExpress but ever heard of Syncfusion as another big global player? I found some interesting vulnerabilities in it, fixed in version v27.1.55. Unfortunately, Syncfusion still tries to understand CVE assignments 😅
094
m1tz @m1tzzz.bsky.social · 24/11/2024
Another live hacking event with the #kaeferjaeger . This time with #Intigriti in Heidelberg and the awesome target #Allegro . Had a great time and found a couple of bugs. #lhe #bughunting #bugbounty
0100