
Founder at Bonsai Information Security
Argentina

Founder at Bonsai Information Security
Argentina
Senior penetration tester, researcher and developer. Project leader of w3af (web application attack and audit framework). Particularly interested in web application security and automated tools to ease up the job of performing penetration tests. Always interested in learning about new technology, tools and techniques.
- Web application security
- IPS device evasion
- Networking
- Information security research in general
- Programming
(Information Technology and Services industry)
January 2009 — Present (7 months)
(Non-Profit; 1-10 employees; Internet industry)
February 2005 — Present (4 years 6 months)
w3af is an open source web application attack and audit framework, the goals of the project are to create a software that can find and exploit most web application vulnerabilities, and to create a community of experts that interact and share ideas.
(Non-Profit; Computer Software industry)
May 2009 — May 2009 (1 month)
Gave a presentation about the latest improvements in w3af in Owasp Europe, Krakow, Poland.
(Information Technology and Services industry)
May 2009 — May 2009 (1 month)
I helped with the organization of the Capture the Flag game for the CONFidence conference in Krakow, Poland.
(Internet industry)
November 2005 — December 2008 (3 years 2 months)
(Privately Held; 1-10 employees; Internet industry)
March 2008 — March 2008 (1 month)
I presented the latest features of the w3af framework.
(Educational Institution; 501-1000 employees; Internet industry)
December 2007 — December 2007 (1 month)
(Internet industry)
July 2007 — November 2007 (5 months)
I trained a small group of information security enthusiasts, the classes were practical and theoretical with a lot of emphasis in secure programming, web application and linux security.
(Partnership; 501-1000 employees; Banking industry)
September 2007 — September 2007 (1 month)
I gave a talk about home banking security to CIOs and some other management level employees of the most important banks in Argentina.
(Internet industry)
2007 — 2007 (less than a year)
(Educational Institution; 51-200 employees; Internet industry)
July 2007 — July 2007 (1 month)
I gave a two hour talk about w3af; where I presented beta4 features.
(Privately Held; Telecommunications industry)
2003 — 2005 (2 years)
I managed the IDS and IPS devices for Impsat's clients using a centralized management console. The work consisted in configuring the devices, creating new rules and reporting events.
(Educational Institution; 51-200 employees; Non-Profit Organization Management industry)
December 2003 — December 2003 (1 month)
I gave a talk about layered security in GNU/Linux systems.
Sports, traveling and programming.