Kai Glauber
Matthias Göhring
Modern web applications require pentesters to manage multiple accounts, roles, and tenants while dealing with short-lived sessions, multi-step logins, and MFA. This complexity regularly breaks authenticated tooling and slows down assessments, forcing testers into repetitive manual re-authentication.
Our open-source tool, session-chains, addresses this challenge by automatically creating and maintaining authenticated sessions for any number of users. Testers define reusable authentication flows, while the tool keeps sessions valid in the background and exposes them to other tools.
It integrates with Burp Suite and CLI tools like sqlmap, enabling consistent authenticated testing even in complex environments. This allows security professionals to spend less time on authentication hurdles and more time identifying impactful vulnerabilities.
Kai Glauber
Consultant IT Security at usd AG
Kai Glauber is a senior security consultant and penetration tester at usd AG with experience in web application pentests, SSO assessments and Kubernetes security. With a background in software development, his early work in software testing led him to specialize in the security domain. He's passionate about workflow automation and making pentesting more efficient.
Matthias Göhring
Security Consultant & Head of usd HeroLab // usd AG
Matthias Göhring is security consultant and penetration tester at usd AG, an information security company based in Germany with the mission #moresecurity. He is Head of usd HeroLab, the division of usd specialized in technical security assessments. In addition, he holds lectures at Technical University Darmstadt and University of Applied Sciences Darmstadt on ethical hacking and penetration testing. In previous scientific work, he focused on network and communication security as well as software security.
Previous publications:
- Catching the Clones – Insights in Website Cloning Attacks, Risk Connect Conference, 2021
- Path MTU Discovery Considered Harmful, IEEE 38th International Conference on Distributed Computing Systems (ICDCS), 2018
- Tor Experimentation Tools, IEEE Security and Privacy Workshops, 2015
- On randomness testing in physical layer key agreement, IEEE 2nd World Forum on Internet of Things (WF-IoT), 2015