Jakob Steeg
Jakob Steeg is a security consultant and penetration tester at usd AG with several years of experience in planning and executing penetration tests across web applications, APIs, cloud environments, Kubernetes, Windows/Active Directory, mobile platforms, and native/thick client applications. He specializes in the security assessment of desktop clients and proprietary or binary protocols, applying his strong software development background to build custom testing tools and analyze complex systems. His expertise includes cryptographic mechanisms, secure software development, public key infrastructures, and modern network architectures. Jakob holds a Master’s degree in IT Security from TU Darmstadt, is OSCP and OSWE certified, and has published multiple CVE-listed vulnerabilities.
Session
Desktop applications, also known as fat or thick clients, remain a business-critical attack surface in many enterprise environments, especially in finance, insurance, and pharmaceuticals. Testing them requires a different approach than classic web application testing: reverse engineering client-side functionality, understanding proprietary protocols, and analyzing backend communication. This hands-on training introduces a practical methodology for assessing Java desktop applications from initial analysis to backend exploitation. Participants will reverse engineer a demo application, inspect its network communication, build a custom pentest client, and use it to identify and exploit server-side vulnerabilities.