Schweigert IT · Einzelunternehmen · Defensive IT-DienstleistungenSchweigert IT · sole proprietorship · defensive IT services
Lernplattformen absichern und betreiben — aus der Betreiberperspektive. Learning platforms — secured and operated, from an operator's perspective.
Sicherheitsaudits, Plugin-Entwicklung und Infrastruktur für ILIAS. Nicht aus dem Consulting-Lehrbuch, sondern von jemandem, der solche Systeme im Hochschulbetrieb selbst produktiv verantwortet — inklusive Prüfungsbetrieb, in dem Ausfall keine Option ist. Security audits, plugin development and infrastructure for ILIAS. Not from the consulting textbook, but from someone who runs these systems in university production himself — including exam operation, where downtime is not an option.
$ audit --target ilias --mode white-box → Quellcode · Plugins · Schnittstellen (SOAP/REST)Source code · plugins · interfaces (SOAP/REST) → Befund → Patch-Vorschlag → koordinierte OffenlegungFinding → patch proposal → coordinated disclosure $
$ systemctl status lernplattform.target ● aktivactive — hochverfügbar, repliziert, überwachthighly available, replicated, monitored → Härtung · Monitoring · TLS-Automatisierung · PluginsHardening · monitoring · TLS automation · plugins $
Leistungsfeld 1Field of work 1
Security: Schwachstellen finden, bevor es andere tun. Security: finding vulnerabilities before anyone else does.
White-Box-Audits mit vollem Quellcode-Zugriff statt oberflächlicher Scans. Der Unterschied zur reinen Pentest-Dienstleistung: Befunde kommen mit Patch-Vorschlägen, weil die Codebasis aus der eigenen Betriebs- und Entwicklungspraxis vertraut ist. White-box audits with full source code access instead of surface-level scans. The difference to a plain pentest service: findings come with patch proposals, because the codebase is familiar from day-to-day operations and development.
Audits & AnalyseAudits & analysis
für ILIAS-Installationenfor ILIAS installations
- White-Box-Sicherheitsauditssecurity audits Quellcode-Analyse von Kern, Plugins und Eigenentwicklungen — statisch und dynamisch.Source code analysis of core, plugins and in-house developments — static and dynamic.
- SchnittstellenprüfungInterface testing SOAP-, REST- und Import/Export-Pfade: die Stellen, an denen Lernplattformen erfahrungsgemäß verwundbar sind.SOAP, REST and import/export paths: the places where learning platforms are, in practice, most vulnerable.
- Plugin-Reviews Sicherheitsbewertung von Dritt- und Eigen-Plugins vor dem Produktiveinsatz — besonders relevant im Prüfungskontext.Security assessment of third-party and in-house plugins before production use — especially relevant in the exam context.
Responsible Disclosure
verantwortungsvoll, koordiniert, dokumentiertresponsible, coordinated, documented
- Koordinierte OffenlegungCoordinated disclosure Meldung an Hersteller bzw. Projektträger nach etabliertem Disclosure-Prozess, mit nachvollziehbarer Dokumentation.Reports to vendors or project maintainers following an established disclosure process, with traceable documentation.
- Laufende Vulnerability-ResearchOngoing vulnerability research Kontinuierliche, eigenständige Analyse der ILIAS-Codebasis — nicht nur auf Zuruf.Continuous, self-directed analysis of the ILIAS codebase — not just on request.
- CVE-KoordinationCVE coordination Begleitung von der Meldung bis zur formalen Zuordnung und Veröffentlichung.Guidance from initial report through formal assignment and publication.
| JahrYear | Advisory | KomponenteComponent | KlasseClass | Status | Write-up |
|---|---|---|---|---|---|
| 2026 | il_sa_2026_XXX | Komponentenname | Schwachstellenklasse | in Koordination · geschwärzt bis Advisoryunder coordination · redacted until advisory | — |
| 20XX | il_sa_20XX-XXX | [Komponente] | [Schwachstellenklasse] | gepatchtfixed · CVE angefragtCVE requested | AnalyseAnalysis → |
| 20XX | il_sa_20XX-XXX | [Komponente] | [Schwachstellenklasse] | gepatchtfixed · CVE angefragtCVE requested | AnalyseAnalysis → |
| 20XX | il_sa_20XX-XXX | [Komponente] | [Schwachstellenklasse] | gepatchtfixed · CVE angefragtCVE requested | — |
| 20XX | il_sa_20XX-XXX | [Komponente] | [Schwachstellenklasse] | gepatchtfixed · CVE angefragtCVE requested | — |
| 20XX | il_sa_20XX-XXX | [Komponente] | [Schwachstellenklasse] | gepatchtfixed · CVE angefragtCVE requested | — |
| … insgesamt ca. 8 in den offiziellen ILIAS-Security-Advisories namentlich genannte Befunde · Meldungen in laufender Koordination erscheinen nur geschwärzt und werden erst nach Veröffentlichung des Advisories entschwärzt · Analysen erscheinen frühestens 90 Tage nach Advisory-Veröffentlichung… approx. 8 findings credited by name in the official ILIAS security advisories · reports under active coordination appear redacted only and are unredacted after the advisory is published · analyses appear no earlier than 90 days after the advisory | |||||
Leistungsfeld 2Field of work 2
Betrieb & Entwicklung: Infrastruktur, die Prüfungslast aushält. Operations & development: infrastructure that withstands exam load.
Lernplattformen im Hochschulbetrieb haben zwei Betriebsmodi: Alltag und Prüfung. Der zweite verzeiht nichts. Aufbau und Härtung orientieren sich deshalb an dem Szenario, das wirklich weh tut — hunderte gleichzeitige Prüflinge, keine Toleranz für Ausfälle. University learning platforms have two operating modes: everyday use and exams. The second one forgives nothing. Setup and hardening are therefore built around the scenario that actually hurts — hundreds of concurrent examinees, zero tolerance for downtime.
Infrastruktur & HärtungInfrastructure & hardening
vom Setup bis zur Hochverfügbarkeitfrom setup to high availability
- Aufbau & HärtungSetup & hardening Webserver-, PHP- und Systemkonfiguration nach Least-Privilege-Prinzip; Lastverteilung über mehrere Knoten.Web server, PHP and system configuration following least privilege; load balancing across multiple nodes.
- DatenbankarchitekturDatabase architecture Replikationstopologien, Performance-Tuning und Wiederherstellungsstrategien für MariaDB/MySQL unter Prüfungslast.Replication topologies, performance tuning and recovery strategies for MariaDB/MySQL under exam load.
- Monitoring, Logging & TLS Zentrales Logging mit auswertbaren Pipelines, Metriken mit Aussagekraft, vollautomatisierte Zertifikatsverwaltung (ACME) auch über Load-Balancer-Setups hinweg.Central logging with actionable pipelines, metrics that mean something, fully automated certificate management (ACME) — including across load-balanced setups.
- LasttestsLoad testing Realistische Prüfungssimulation vor dem Ernstfall statt Hoffnung am Prüfungstag.Realistic exam simulation before the real thing, instead of hoping on exam day.
Plugin-EntwicklungPlugin development
ILIAS, mit Fokus auf E-AssessmentILIAS, focused on e-assessment
- PrüfungsszenarienExam scenarios Entwicklung von ILIAS-Plugins, die reale Anforderungen aus dem elektronischen Prüfungsbetrieb abbilden — entstanden aus dem eigenen Bedarf, nicht am Reißbrett.ILIAS plugins built for real requirements from electronic exam operation — born from actual need, not the drawing board.
- ExtendedTestSettings-Suite Modulares Produkt für den Prüfungsbetrieb, siehe unten.Modular product for exam operation, see below.
- IndividualentwicklungCustom development UIHook-, PageComponent- und Repository-Object-Plugins nach Anforderung — mit Sicherheitsreview inklusive, nicht als Extra.UIHook, PageComponent and repository object plugins to spec — with a security review included, not as an extra.
Warum das zusammengehörtWhy these belong together
Wer die Systeme betreibt, prüft anders. Wer sie prüft, betreibt anders. Operating the systems changes how you audit. Auditing them changes how you operate.
betrieb → security
Ein Audit von jemandem, der die Plattform produktiv verantwortet, findet die Schwachstellen, die in der Praxis ausgenutzt werden — nicht nur die, die ein Scanner listet. An audit by someone who runs the platform in production finds the vulnerabilities that get exploited in practice — not just the ones a scanner lists.
security → betrieb
Infrastruktur, die von jemandem mit Angreiferblick gebaut wird, ist ab Tag eins gehärtet — statt nachträglich abgedichtet. Infrastructure built by someone with an attacker's eye is hardened from day one — not patched up after the fact.
beides → prüfungsbetriebboth → exam operation
Elektronische Prüfungen sind der härteste Anwendungsfall: hohe Last, hohe Sensibilität, null Fehlertoleranz. Genau dafür ist beides ausgelegt. Electronic exams are the hardest use case: high load, high sensitivity, zero fault tolerance. Both are built for exactly that.
ProduktProduct
ExtendedTestSettings — modulare Plugin-Suite für den ILIAS-Prüfungsbetrieb. ExtendedTestSettings — modular plugin suite for ILIAS exam operation.
Erweiterungen rund um das ILIAS-Testobjekt, die im echten Prüfungsbetrieb entstanden sind. Modular: Einrichtungen setzen nur ein, was sie brauchen. Extensions around the ILIAS test object, created in real exam operation. Modular: institutions deploy only what they need.
Details, Modulübersicht und Lizenzmodell auf Anfrage — die Suite wird kontinuierlich weiterentwickelt. Details, module overview and licensing on request — the suite is under continuous development.
Über michAbout
André Schweigert
Hauptberuflich betreibe und entwickle ich als Systems Administrator und Entwickler die zentrale E-Learning- und E-Prüfungsplattform der Friedrich-Alexander-Universität Erlangen-Nürnberg — eine ILIAS-Umgebung, auf der jedes Semester elektronische Prüfungen mit hohen Anforderungen an Verfügbarkeit und Integrität laufen. In my main role, I operate and develop the central e-learning and e-assessment platform of Friedrich-Alexander-Universität Erlangen-Nürnberg as a systems administrator and developer — an ILIAS environment running electronic exams with high demands on availability and integrity every semester.
Als Security Analyst der ILIAS e.V. koordiniere ich Schwachstellenmeldungen und Responsible Disclosure für die Plattform. Berufsbegleitend studiere ich IT-Sicherheit (B.Sc.) an der Ostfalia Hochschule. As a security analyst for ILIAS e.V., I coordinate vulnerability reports and responsible disclosure for the platform. Alongside work, I am studying IT security (B.Sc.) at Ostfalia University of Applied Sciences.
Schweigert IT bündelt meine unabhängige Sicherheits- und Entwicklungsarbeit: Forschung, Audits, Plugins und Beratung — für Betreiber, die wissen wollen, wo sie wirklich stehen. Schweigert IT bundles my independent security and development work: research, audits, plugins and consulting — for operators who want to know where they actually stand.
- RolleRole
- Inhaber, Schweigert ITOwner, Schweigert IT
- Security
- Security Analyst, ILIAS e.V.
- HauptberufDay job
- Sysadmin & Developer, FAU Erlangen-Nürnberg
- AusbildungEducation
- B.Sc. IT-Sicherheit (i. A.), Ostfalia
- FokusFocus
- ILIAS · E-Assessment · AppSec
KontaktContact
Direkter Draht. Kein Formular, kein Vertrieb. A direct line. No form, no sales team.
Anfragen zu Audits, Infrastruktur oder Plugins gehen direkt an den Inhaber — und werden auch von ihm beantwortet. Enquiries about audits, infrastructure or plugins go straight to the owner — and are answered by him, too.
Kurze Schilderung des Anliegens genügt — ILIAS-Version, Größenordnung, Zeitrahmen. Antwort in der Regel innerhalb von zwei Werktagen. A short description is enough — ILIAS version, scale, timeframe. Replies usually within two working days.
pgp — für vertrauliche Meldungenpgp — for confidential reports
Sicherheitsrelevante Anfragen und Schwachstellenmeldungen gerne verschlüsselt: Security-related enquiries and vulnerability reports are welcome encrypted:
key: schweigert-it.de/pgp.asc · Fingerprint-Platzhalter — vor Go-live ersetzenfingerprint placeholder — replace before go-live