VULNEX, up & running

[Español] Por fin VULNEX, el proyecto en el que llevo meses trabajando, ha visto la luz aunque sin duda estamos en los comienzos y queda mucho trabajo duro por delante pero con gran ilusión.

[English] Finally VULNEX, the project I’ve been working on for the past few months, has seen the light but undoubtedly we are at the beginning and much hard work remains ahead but with great enthusiasm.

VULNEX nace con la aspiración de ser un proveedor de servicios y formación ofensivos y defensivos altamente especializados para cubrir las necesidades actuales de nuestros clientes. Los tiempos han cambiado y demasiada gente no entiende las nuevas necesidades de seguridad pero VULNEX está para ayudar. Un factor diferenciador es que VULNEX se caracteriza por un fuerte I+D que poco a poco iremos publicando.

VULNEX was created with the aspiration to be a provider of highly specialized offensive and defensive services and training to meet the current needs of our clients. Times have changed, and too many people do not understand the new security needs but VULNEX is here to help. A differentiating factor is that VULNEX is characterized by a strong R&D that we will start publishing soon.

Creemos que VULNEX ofrece algo más a nuestros clientes por lo que os invitamos a visitar la página Web y por supuesto a contactarnos. Nos encantaría colaborar contigo!

We believe that VULNEX offers something else to our customers so we invite you to visit the website and of course contact us. We are looking forward to working with you!

— Simon Roses Femerling

Posted in Business, Pentest, SDL, Security, Technology | Tagged , , , , | Leave a comment

Infiltrate 2012 Report

[Español] El pasado 12 y 13 de enero tuvo lugar la segunda edición del congreso ofensivo Infiltrate organizada por ImmunitySec, en cuya primera edición ya estuvimos. A pesar que no todas las charlas fueron tan espectaculares como el año pasado sigue siendo un congreso altamente ofensivo y de cita obligada para cualquier experto en seguridad.  
[English] The second edition of Infiltrate, the offensive conference organized by ImmunitySec, was held last 12 and 13 of January, which first edition we attended as well. Despite the fact that not all talks were as spectacular as  last year it is still a must for any security professional since it is a highly offensive conference.  
 
El primer día comenzó con un divertido keynote sobre dos temas: conferencias de seguridad y ciberguerra
(ambas temáticas cubiertas en este blog 1 y 2), y la verdad es que coincido en muchos aspectos con las conclusiones  del ponente. Algunas charlas destacadas del primer día fueron sobre explotación de heap y sandboxing. 
The first day started with a funny keynote on two issues: security conferences and cyber war (both thematics covered in this blog 1 and 2), and the truth is that I agree in many respects with the presenter’s conclusions. Some outstanding talks on the first day were about heap exploitation and sandboxing. 
   
El segundo día el nivel de todas las presentaciones fue altísimo y me gustaron todas. La mejor sin duda fue la de atacar sistemas de tarjetas de acceso por su innovación, aunque recomiendo verlas todas. Las charlas fueron filmadas por lo que creo que estarán disponibles próximamente.  
The second day the level of all the presentations was amazingly high and I liked them all. The best no doubt was attacking proximity card access systems, so innovative, but I recommend watching them all. The talks were filmed so I think they will be available soon. 
 
  Además  qué decir de la ciudad de Miami, un sitio genial para salir de fiesta con otros hackers y pasarlo bien J
 
Sin duda uno de los mejores congresos por sus charlas técnicas y la posibilidad de conocer personas  interesantes, me llevo buenas amistades ;) 
 
Kudos a todo el equipo de ImmunitySec por una excepcional organización y su disposición para que todo salga bien. 
 
  N os vemos en la tercera edición! 
 
In addition what to say of Miami city, a great place for partying with other hackers and have fun J 
Undoubtedly one of the best conferences for their technical talks and the possibility of meeting interesting people, I’ve made good friends ;)
 
  Kudos to all ImmunitySec team for an exceptional organization and their availability to make sure that everything goes well. 
 
  See you in the third edition!
 
   — Simon Roses Femerling
Posted in Conference, Hacking, Pentest, Security, Technology | Tagged , , , , , , , , , | Leave a comment

New Year, New Ideas, New Job

[Español] Como muchos lectores saben tras varios años en Microsoft he abandonado el equipo de seguridad de la compañía el pasado mes de diciembre en busca de nuevos retos y oportunidades. Este cambio me permite enfocarme a un rol de I+D en seguridad de aplicaciones.

[English] As many readers know after several years in Microsoft I have left the security team last December to pursue new challenges and opportunities. This move allows me to focus on a R&D role in application security.

Empiezo una nueva etapa profesional como emprendedor con muchas ideas en la cabeza que muy pronto os iré mostrando, así que atentos al blog y Twitter ;)

Mis servicios siguen disponibles :)

I start a new professional stage as entrepreneur with many ideas in mind that very soon I’ll be showing, but for the moment stay tuned with the blog and Twitter ;)

My services are still available :)

— Simon Roses Femerling

Posted in Business, Security, Technology | Tagged , , , , | Leave a comment