Information security is very complex field of research with a lot of unknown and unexplored areas and my own interest in this field started 5 years ago and during these years I had the opportunity to work with leading companies, in Morocco also in other countries. I have worked as a freelance with Government, Security, Telecom, Banking and Private Sectors, providing them consultancy as well as managing multiple penetration testing projects I have been also involved in vulnerability research and I have published multiple advisories for multiple affected systems and solutions.
The following is the list of some references to the advisories that I researched and submitted through international security portals and magazines:
- Sentinel, Safety Information Management System :
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1913
- SABI Mobile :
http://archives.zataz.com/news/21217/vulnerabilite--faille--0day--sabi-mobile.html
- Collabtive - Project Management Software :
http://archives.zataz.com/news/21119/Collabtive--faille.html
- Virtual NewsRoom - Press Software :
http://archives.zataz.com/news/21092/VNR--Virtual-NewsRoom.html
- Groupware Software :
http://archives.zataz.com/news/21087/0day--vulnerability--Groupware.html
- SimplyTrack - Geoloc System :
http://archives.zataz.com/news/20844/Traceur-GSM-facilement-tracable-par-les-pirates.html
- OCS InventoryNG :
http://archives.zataz.com/alerte-securite/20778/0Day-pour-le-syst%C3%A8me-OCS-Inventory-NG.html
- Sabre AirCentre Crew - GDS Solution :
http://archives.zataz.com/news/20366/donnees-aeroports-compagnies-aeriennes.html
- Acunetix WVS Software :
http://archives.zataz.com/news/20315/Faille-pour-le-logiciel-Acunetix.html
- InfraCentral - Network Monitoring Appliance :
http://archives.zataz.com/alerte-securite/20168/0Day-pour-la-solution-InfraCentral.html
- Rodopi OSS :
http://archives.zataz.com/alerte-securite/19917/rodopi-vulnerability.html
- Desknow - Mail and Collaboration server :
http://archives.zataz.com/alerte-securite/19692/Vulnerabilite-pour-DeskNow.html
- Cadic ExLibris - DMS Software :
http://archives.zataz.com/news/19631/protocole-alerte-haided-certa.html
For obvious reasons of confidentiality this list is not exhaustive I also found a critical bugs in famous websites in the world.
Pas de formation renseignée