Personal Website
Security research, identity & SAP security
I’m Martin Gallo, a hacker turned into cybersecurity professional, focused on product management, identity security, offensive security and security research.
This site collects my research and writing on offensive security, identity security and IAM — authentication, passkeys, phishing-resistant MFA — and SAP security: posts, conference talks, advisories, and tools.
Latest posts
The Rise of Consent and Other Application-based Phishing Attacks
August 2021
OAuth consent-based and other application phishing attacks: anatomy, variants, detection, and prevention.
Protecting Credentials in SAP HANA: The Client Secure User Store
April 2021
How the HANA client Secure User Store protects credentials, what can go wrong, and best practices.
Exploring the SAP HANA SQL Command Network Protocol – Federated Authentication
October 2020
HANA series part 3: federated authentication — SAML, logon tickets, JWTs, Kerberos, and session cookies.