Upcoming Events

Talks, workshops, and meetups I will host or am scheduled to attend.

March, 18th Remote
Training

SSO Security Workshop

The next SSO Security Workshop will take place on March 18th, from 11:00 to 16:00, remote. In this workshop, we will explore the security aspects of Single Sign-On (SSO) systems, including common vulnerabilities and best practices for securing SSO implementations.

Registration required Info & RSVP
Past Events 5
February, 14th - 22nd Remote
Meetup

Bug Bounty Meetup vol. 5

The fifth Hacking Meetup of the HackerOne Club Germany was fully-remote again. We hacked on two live targets, connect via a WorkAdventure virtual space, collaborated, and learned a lot.

September 10th - 20th, 2025 Essen
Meetup

Bug Bounty Meetup vol. 4

For our fourth meetup we gathered in Essen and scored almost 15k $ in bounties on a fresh target. We had a great time connecting, collaborating, and learning together!

June 2nd - 15th, 2025 Remote
Meetup

Bug Bounty Meetup vol. 3

Our third meetup was ground-breaking: We had a record-breaking 95k $ in bounties on Exness. 🤯 This was our first remote meetup, but we still gathered virtually for our Show&Tell session and collaborated a lot throughout the event.

February 15th - 22th, 2025 Bochum
Meetup

Bug Bounty Meetup vol. 2

New year, new meetup! We had a great time connecting, collaborating, and learning together in Bochum. Partner program was Grab and we scored over 15k $ in bounties.

May 21st - 26th, 2024 Bochum
Meetup

Bug Bounty Meetup vol. 1

The beginning of something great: Our first meetup was a blast! We had a great time connecting, collaborating, and learning together in Bochum. We hacked on ToolsForHumanity and scored over 10k $ in bounties.

Recent Advisories

Recent research and write-ups on relevant web security topics.

All Advisories
Jun 19, 2024 OpenID Connect

Sign-in with World ID: XSS and ATO via OIDC Form Post Response Mode

Recently, Tools for Humanity partnered with the German HackerOne Club to run a one-week virtual and in-person Hacking Meetup. In the course of the meetup, a critical vulnerability within the Sign-in with World ID implementation was found, which affected the OpenID Connect form_post Response Mode and could allow malicious actors to take over end-user accounts at third-party applications that utilize the Sign-in with World ID mechanism. The vulnerability was addressed within a few hours after triage.

4 min read
read more
Jun 18, 2022 Asana

Personal Access Token Disclosure in Asana Desktop Application

This post gives an insight into a sensitive data exposure vulnerability in Asana for Mac that was rated as P1 and was awarded a bounty. This was the very first report of that kind for me. Still, I think this type of deployment and build chain issue is more common than one may think.

5 min read
read more
Dec 18, 2021 OpenID Connect

Flickr Account Takeover

This post gives a deep dive into a critical security flaw that was present in Flickr’s login flow. The authentication at identity.flickr.com is implemented using AWS Cognito. By exploiting configuration issues and violations of the OpenID Connect specification, it was possible to takeover any Flickr account without user interaction.

8 min read
read more