SSH Security Researcher & Python Developer · Austria
I research SSH security and build open source tools for security audits. Based in Austria — creator of SSH-MITM, currently also working on malware analysis tooling.
Man-in-the-middle SSH server for security audits — supporting public key authentication, session hijacking, and file manipulation.
CVE Research: CVE-2021-36367 · CVE-2021-36368 · CVE-2021-36369 · CVE-2021-36370 · CVE-2022-38336 · CVE-2022-38337 · CVE-2026-60000 (OpenSSH GSSAPI auth bypass, credited by OpenSSH 10.4)
Talk: SSH MITM attacks & trivial authentication — DeepSec 2021 · Slides
Package Python applications as self-contained AppImages — bundles a complete Python distribution with your app and all its dependencies into a single executable file.
Dynamically verify that systemd sandboxing/hardening directives on a unit actually take effect — catch hardening configs that look strict on paper but do nothing at runtime.




