top of page
mascon-icon.png
mascon.png

Tobias Hamann

Penetration Tester/IT-Security Consultant
usd
greg-fawson-foto.1024x1024 Kopie.jpg

Tobias Hamann is a security researcher and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity.

As part of the SAP penetration testing team at the usd HeroLab, Tobias is contributing mainly to the development of new analysis tools and the research of new attack vectors. Beyond that, he is interested in reverse engineering and vulnerability research in general.

Outside the SAP domain, Tobias has a strong interest on mobile security. He has published several research papers in security-focused scientific conferences.

Turning your App into our Spy - Android App Vulnerabilities in Practice

Lightning talk

Mobile apps often handle highly sensitive data and expose powerful device capabilities - this makes them prime targets for attackers. Even minor flaws can escalate into full compromise, leaking location data or enabling covert camera and microphone access.

We present a real-world pentest case that uncovered a zero-day vulnerability in the Element X Android application. By exploiting it, we injected malicious web content into the app’s trusted context, demonstrating how subtle weaknesses can have severe impact.

Building on this case, we share key lessons from targeted mobile penetration testing, highlight recurring vulnerability classes, discuss the unique challenges of securing modern mobile ecosystems and show how taking the attacker's mindset can aid secure app development.

Fabian and Tobias are experienced mobile pentesters combining academic expertise with extensive project experience across diverse customer environments.

bottom of page