Vulnerability research on widely used software.
I examine widely used software for security flaws, report them to the vendor and, once a fix is out, publish an advisory with the formal details.
Research
All testing happens on my own instances in my own lab. Nothing is published before coordinated disclosure with the vendor.
- CVE research Vulnerabilities I have reported, with identifier and disclosure status. Currently four, all in ILIAS, all fixed.
- Advisories My own security advisories, published after coordinated disclosure. Until then, deliberately without details.
- Writeup series “Poking on ILIAS” How I take a learning platform apart on my own test VM, documented step by step. One post, on PHP object injection, is available. More will follow.
About
I am André Schweigert, owner of schweigertIT. Computers have fascinated me since I was a child. What stayed is an interest in systems: how well can one be secured, and how do you break it anyway?
So far my attention has gone mostly to ILIAS, a learning platform widely used at universities and public authorities. I am based in Münchsteinach, Middle Franconia, Germany.
Contact
If you would like to talk — about my research or about your systems — write to me. I usually reply within two working days.
kontakt@schweigertit.de