Menu

Youssef MANAR

TIZNIT

En résumé

Information security is very complex field of research with a lot of unknown and unexplored areas and my own interest in this field started 5 years ago and during these years I had the opportunity to work with leading companies, in Morocco also in other countries. I have worked as a freelance with Government, Security, Telecom, Banking and Private Sectors, providing them consultancy as well as managing multiple penetration testing projects I have been also involved in vulnerability research and I have published multiple advisories for multiple affected systems and solutions.

The following is the list of some references to the advisories that I researched and submitted through international security portals and magazines:


- Sentinel, Safety Information Management System :
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1913
- SABI Mobile :
http://archives.zataz.com/news/21217/vulnerabilite--faille--0day--sabi-mobile.html
- Collabtive - Project Management Software :
http://archives.zataz.com/news/21119/Collabtive--faille.html
- Virtual NewsRoom - Press Software :
http://archives.zataz.com/news/21092/VNR--Virtual-NewsRoom.html
- Groupware Software :
http://archives.zataz.com/news/21087/0day--vulnerability--Groupware.html
- SimplyTrack - Geoloc System :
http://archives.zataz.com/news/20844/Traceur-GSM-facilement-tracable-par-les-pirates.html
- OCS InventoryNG :
http://archives.zataz.com/alerte-securite/20778/0Day-pour-le-syst%C3%A8me-OCS-Inventory-NG.html
- Sabre AirCentre Crew - GDS Solution :
http://archives.zataz.com/news/20366/donnees-aeroports-compagnies-aeriennes.html
- Acunetix WVS Software :
http://archives.zataz.com/news/20315/Faille-pour-le-logiciel-Acunetix.html
- InfraCentral - Network Monitoring Appliance :
http://archives.zataz.com/alerte-securite/20168/0Day-pour-la-solution-InfraCentral.html
- Rodopi OSS :
http://archives.zataz.com/alerte-securite/19917/rodopi-vulnerability.html
- Desknow - Mail and Collaboration server :
http://archives.zataz.com/alerte-securite/19692/Vulnerabilite-pour-DeskNow.html
- Cadic ExLibris - DMS Software :
http://archives.zataz.com/news/19631/protocole-alerte-haided-certa.html

For obvious reasons of confidentiality this list is not exhaustive I also found a critical bugs in famous websites in the world.

Entreprises

  • Sahara Net - a Belgacom Company - Chief Hacking Officer

    2011 - maintenant
  • CERT-NETpeas - VRT - Vulnerability Research Team Leader

    2011 - 2012
  • BSSI Conseil et Audit - IT Security Consultant - Freelance

    Versailles 2011 - 2012
  • Netpeas - IT Security Researcher

    2010 - 2012
  • IT-Secure - IT Security Consultant - Freelance

    2010 - 2012
  • Sahara Net - IT Security Advisor/Ethical Hacker

    2010 - 2011
  • MTDS - IT Security Advisor/Ethical Hacker

    Rabat 2010 - 2013
  • F2S - IT Security Consultant - Freelance

    2010 - 2010
  • Eversys - IT Security Consultant - Freelance

    2010 - 2010
  • IT6 - IT Security Consultant

    2009 - 2011

Formations

Pas de formation renseignée

Réseau

Annuaire des membres :