Rahul Sasi

Rahul Sasi

About

Detail

Co-Founder CEO
United States

Timeline


work
Job

Résumé


Jobs verified_user 0% verified
  • CloudSEK
    Co-Founder CEO
    CloudSEK
    May 2022 - Current (4 years 3 months)
  • CloudSEK
    Founder CTO
    CloudSEK
    Sep 2015 - Apr 2022 (6 years 8 months)
  • Citrix
    Sr Cloud Information Security Engineer
    Citrix
    Oct 2013 - Apr 2015 (1 year 7 months)
    I was the first to get hired at Citrix India without an Engineering degree. Threat modelling, Code review, Fuzzing and security research on Citrix products , thereby making the products Hack proof.
  • iSIGHT Partners
    Technical Security Analyst
    iSIGHT Partners
    May 2010 - Oct 2013 (3 years 6 months)
    Acquired and now part of Google Cloud. I Dropped out of college to work for this promising startup. I was part of the global Technical Research team, where I coordinate with team members from 5 different continents to build research tools to improve the technical data collection capabilities.Also worked with the Infrastructure Monitoring team, extracting malware communication protocols, and analyzing malware controllers mainly via source code review and reverse engineering. Accomplishments • Analyzed multiple web browser exploits and exploit Kits. • Reverse Engineered un-documented tools and applications and made reports. • Assisted local Threat Team in various project providing technical support. • Strong understanding on various APT
  • GarageHackersGH
    Security Researcher
    GarageHackersGH
    Mar 2006 - Apr 2010 (4 years 2 months)
    I spent my college days researching, programming and contributing to this cyber security community.
Projects (professional or personal) verified_user 0% verified
  • M
    My projects and Blogs
    Most of the security work I have done between 2007-2014 is listed here.
Publications verified_user 0% verified
  • E
    Pentesting a DVB-C network .Hacking your cable TV, Die Hard Style
    Ekoparty Argentina Sep
    So in our talks we cover the various attacks we can do on DVB-C infrastructure. That will include the following topics. 1) Security Vulnerabilities in DVB-C middleware servers. [Hijacking a TV stream] 2) Implementation bugs in DVB-C network protocol .[Man in the Middle Attacks] 3) Fuzzing setup boxes via MPEG streams. [Shutting down Setup boxes] 4) Demo taking over your Cable TV BroadCasting. http://vimeo.com/113053663
  • N
    Pen-Testing Biometric Systems
    Nullcon India Feb
    We demonstrated how to find security vulnerabilities in Biometrics systems. We explained how to Reverse Engineer these devices and undocumented protocols and find security issues. We also demonstrated local security issues along with remote attack POC.
  • E
    Fuzzing DTMF Algorithms
    Ekoparty Argentina BlackHat Abu Dhabi Oct
    We demonstrated how it was possible to Fuzz a application that uses few common DTMF Detection algorithms and, how certain implementation could be remotely crashed using certain Fuzz values. We made a Fuzzer for testing these attack vectors. This same paper was selected at BlackHat Abudabi , Nullcon Delhi, Ruxcon Australia. http://www.ekoparty.org//2012/rahul-sasi.php
  • H
    Automating Static and Dynamic Analysis for Java exploits.
    HITB Malaysia CoCon Cochin Oct
    The entire talk is for the security industry [Threat, AV, Firewall, IPS/IDS] and putting forward a solution to mass analyse JAVA exploits. With the rise in APT attacks and malwares spreading via java, browser exploits , an intelligent system to automate Java exploits and attribute them is necessary. So the entire talk was on Java exploits and how to automate and attribute them. Am putting an outline of my presentation. 1) Status of no of exploits 2) The raise in Java exploits during 2012-2013. • Introduction to Java exploits. • Type of Java exploit seen during 2012-2013. • How java exploits can easily bypass AV/Firewall [video]. 3) Java Security architecture explained. • Default sandbox restrictions. • Java sandbox architecture. • Intro
  • H
    Web Server Exploit & Auditing Framework
    HITB Malasia Aug
    The paper mainly demonstrated our tool, that could scan Web Server for know security issues. We also demonstrated how some low level Webserver vulnerabilities could be made use for high impact damage. I Could not make this one.
  • C
    Fuzzing USB Internet Modems
    CanSecWest Canada Nullcon Goa Mar
    A USB modem used for mobile broadband Internet, referred to as a dongle is widely used these days. USB wireless modems use the USB port on the laptop to make it connect to a GSM/CDMA network there by creating a PPPoE(Point to Point protocol over Ethernet) interface to your computer. These devices are supplied with dialer software either written by the hardware manufacture or by the mobile supplier. They also come bundled with device driver. One of the interesting features that are added to these dialer software’s is an interface to read/sent SMS from your computer directly. This is mainly done for sending promotion offers and advertising. These SMS modules added to the dialers, simply check the connected USB modem for incoming SMS messages
  • B
    Remote Code Execution in IVR Applications
    BlackHat Europe Mar
    Demonstrated potential code execution scenarios in IVR Application and how attackers could Craft Voice Payload and attack these applications.
  • C
    PHP Obfuscation Techniques
    CCN Cochin
    We demonstrated how certain PHP obfuscation techniques could render undetected backdoors and how web application hackers could easily backdoor your applications with out getting caught by Firewall IDS.
  • B
    Fuzzing Graphics Libraries
    Blackhat Las Vegas
    An intelligent Fuzzer for image libraries [GDFuzz]. Currently adding modules to fuzz based on Code coverage. Could not make it up to this one.
  • H
    Automating Static and Dynamic Analysis for Document Exploits.
    HITcon Taiwan Jul
    With the rise in number of state sponsored APT attacks targeting government and private companies, their lies an improved requirement in automated exploit analysis and filtering document file formats. There are a huge no of security devices out there that promises to do most of the detection. Our talk would be on how to automate build a similar system. The aim of the talk would be to explain the intelligence that we have added on to our tool sandy automating Document exploits. I been working on an exploit analysis system named “Sandy” a free tool Exploit-Analysis.com. And in my talk I would pass on to the users the various techniques I have learned from my past 8 months of adventures I had with exploit analysis, that involves but not limit
  • C
    Download Deploy Shell Code & AV Evasion
    Clubhackpune Sep
    We implemented and demonstrated a new shell-code technique that could be used in attacks with zero Antivirus Firewall detection. f
  • C
    Fuzzing Web App Scripting Engines
    CoCon Trivandrum Sep
    We demonstrated how to Attack Web applications via it’s Scripting engines. We fuzzed PHP core functions that handles web inputs directly from a user like, image processing, file processing modules and found exploitable bugs.
  • H
    Sandy [ Static and Dynamic Analysis for exploits ]
    Honeynet Global Meet Dubai Feb
    Sandy is an online sandbox capable of doing both static and dynamic analysis of Malicious Office, PDF, Jar, Flash, HTML exploits.The input to sandy would be the above mentioned file formats and output would be extracted malwares, controllers, Urls. Current sand boxes performs Blackbox testing on exploits, the aim of sandy is to do intelligent exploit analysis by performing both static and dynamic analysis and process mass exploit samples.
  • H
    CXML/VXMLCode Auditing
    HITB Amsterdam May
    We explained CXML|VXML code and applications build using it, followed by source code review of these applications to find security issues.
This is a community-created genome.