
Exploit Writer Sr at Core Security
Argentina

Exploit Writer Sr at Core Security
Argentina
Argentine born, I like computers.
Programming: c, c++, assembler, Unix, Linux, Java, J2ME, Embedded devices.
Security, reversing, cryptography, computer science.
(Privately Held; Computer & Network Security industry)
September 2006 — Present (3 years 3 months)
FreeBSD, OpenBSD and Linux platform manager
(Privately Held; Computer & Network Security industry)
September 2006 — Present (3 years 3 months)
Non-exhaustive list of published advisories:
* ProFTPD "mod_ctrld" privilege scalation
* Synce Remote command Injection
* Firebird Multiple Vulnerabilites (Togheter with Damian Frizza)
* MPlayer 1.0rc2 buffer overflow vulnerability (Together with Damian Frizza)
* GNU ED heap buffer overflow
* Vinagre "vinagre_utils_show_error()" Format String Vulnerability
* Qemu and KVM VNC server remote DoS
* OpenBSD's IPv6 mbufs remote kernel buffer overflow
* Multiple vulnerabilities in Google's Android SDK
* NASA CDF stack overflow
* NASA BigView stack overflow
(Computer & Network Security industry)
August 2007 — July 2009 (2 years )
I was selected as a speaker at the Following Security conferences:
* BlackHat 2007, Defcon 15 conferences at Las Vegas, Ekoparty 2007, Buenos Aires, "Remote Exploit on OpenBSD".
* Ekoparty 2008, "Smartphones (in) Security"
* CanSecWest 2009 Vancouver, Syscan 2009 Singapore, "Persistent BIOS Infection"
* BlackHat 2009, "Deactivate the Rootkit"
(Privately Held; Computer Software industry)
August 2003 — September 2006 (3 years 2 months)
Delphi senior programmer, OpenGL, ActiveX, etc.
(Computer Networking industry)
January 1998 — April 1999 (1 year 4 months)
Part-time Webmaster and Network administrator for Universidad Nacional de la Patagonia San Juan Bosco
PhD , Computer Science, Security , 2007 — 2011 (expected)
Current research field: Spread Spectrum over optical fiber
Major , Computer Science , 2001 — 2003
Final work: PICix, a hybrid microkernel for PIC-18 Devices:
http://sourceforge.net/projects/picix/
Analyst , Computer Science , 1997 — 2001
This is not a middle title of my "Major on Computer Science" (Or "Licenciado" as it's called here in Argentina), but in fact a different career sharing much of the courses but adding a deeper knowledge of algebra and calculus.
Técnico electrónico , Electronics,levanting , 1990 — 1996
Final work: 3d software spectrometer. Hardware/Soft solution with adaptive ADC.
Electricist , Electricity, installations , 1990 — 1993
As part of my electronic technician courses, i have a permit as electrician in my country.
My main interest are embedded programming, reverse engineering and security research. I have found (and most of the time, also exploited) several security bugs. A complete list and description is on my web page. Also I like fun stuff like hardware synthesis and error correction codes.
Security Industry
In addition to the BlackHat and Defcon papers, I have presented alone and in a research groups up to 9 reviewed full papers in Computer Science academic conferences:
http://catalogo.info.unlp.edu.ar/cgi-bin/koha/opac-searchresults.pl?criteria=keyword&searchinc=alfredo+ortega&se.x=0&se.y=0&se=Buscar