
Ethical Hacker
Rome Area, Italy

Ethical Hacker
Rome Area, Italy
アンドレア 「ブンケル」 プリフィカト
Ethical Hacker and Computer Security Enthusiast.
In these years, I've discovered many 0day vulnerabilities and developed different exploit codes for commercial and opensource products, revealed to public by common accord with the respective product owners.
I've published exploits codes and tools on my personal website and international security portals such as Securityfocus, Securiteam, milw0rm and more (CVE-2007-2791, CVE-2007-0805, CVE-2007-0876, CVE-2008-0589 and others).
Upcoming alerts are scheduled for a future Oracle CPU: ref. ID 10846253, 10903225
Penetration test activities were performed with excellent results for Italian telecommunication companies and Institutions.
I don't like to perform audit using automated commercial tools and prefer thinking "out of the box" to solve any problem. Today, penetration test and vulnerability research are my main activities.
I have advanced knowledge of GNU/Linux, *BSD, SUN Solaris, HP-UX, Tru64, AIX and Windows operating systems.
My programming skills include good knowledge of Perl, C, C++, Assembly (x86, MIPS), web-oriented languages (PHP, XHTML, CSS), shell scripting and Java (some survival skills).
Specialties: Penetration Test, Vulnerability Assessment, Security Research, Risk Analysis, PCI-DSS and SOX certs.
Penetration Test, Vulnerability Assessment, Security Research, Advanced/Technical Security Audit, Networking, Programming, PCI-DSS, SOX
(Privately Held; TI; Telecommunications industry)
July 2008 — Present (1 year 5 months)
Performing Advanced Security Audit and Penetration Test activities as SOC (Security Operation Center) Tiger Team member.
Performing Technical Security Assessment - Vulnerability Assessment for Sarbanes-Oxley (SOX).
PDR integration for Risk Analysis process.
(Information Technology and Services industry)
May 2006 — Present (3 years 7 months)
Member of Unidata Tiger Team for Technical Security Audit activities, Penetration tests and Vulnerability Research.
(Privately Held; 10,001 or more employees; TI; Telecommunications industry)
May 2006 — June 2008 (2 years 2 months)
Performing Technical Security Audit as Tiger Team member for
C.C.S.F. (Security Fraud Control Centre) in Telecom Italia Mobile.
Main targets: check the possibility of stealing phone traffic,
performing business frauds and revealing sensible data.
(Information Technology and Services industry)
October 2007 — October 2007 (1 month)
Worked as penetration tester for italian Judicial Institution "Accounting Court" (Corte dei Conti)
(Information Technology and Services industry)
September 2005 — April 2006 (8 months)
Administration of GNU/Linux machines and network (L1 room) at So.Ge.Ne.
(Information Technology and Services industry)
January 2005 — December 2005 (1 year )
Trainer for a "Free software and GNU/Linux" course.
(Information Technology and Services industry)
September 2004 — September 2004 (1 month)
Stage for Ismaco Srl. System administrator and web developer.
Computer Science Expert degree , Information Technology, Electronics , 1997 — 2002
Music Theory and Solfege licence , Musical Dictation, Trasposition, Sight-reading solfege, Sight-singing Solfege , 1999
Information Technology, Computer Science, Engineering 2003
ICT Security, Vulnerability Research, Penetration Test, Piano, Hammond, Jazz, Blues, Aikido, Iaido, Nihonto, Japanese Traditional Martial Arts, Photography