
Michele Orru'
System administrator and Security Engineer

Connect with Michele Orru' to Send Message
Connect
Connect with Michele Orru' to Send Message
ConnectTimeline
About me
Phishing Connoisseur
Education
.webp)
University of Bergen (UiB)
2006 - 2007Erasmus information technologyActivities and Societies: Develop Secure Net-based Applications - In-depth study of Security Patterns (RBAC, DMZ, I&A, front door, nonrepudiation, risk determination and management, threat assesment) and Web application vulnerabilties (XSS, blind SQL injection, buffer overflows, weak encryption, MITM attacks, spoofing and sniffing). Creation of video-based attack demonstrations about cookie stealing/injection, ssl/tls certificate injection and IE browser remote exploits. Advanced Topics in Java and Security Systems- Really advanced topics about Java 1.6 Concurrency (Thread Safety, JMM,Liveness, Performance, Thread Pools) and Generics (Wildcards, Reification,Reflection, Sets, Lists and Maps). Research project: Enforcing default securitybehavior of Java 2 Applications through reflection. I was arrived to really goodresults, writing also an Eclipse plugin.

Alma Mater Studiorum – Università di Bologna
2004 - 2008Bachelor information technologyActivities and Societies: My thesis (lead by professor Babaoglu) has been focalized on research about Web Session Management: Analisi hacker del "Session Management" nelle applicazioni Web, with emphasis on real world attack cases on the main web application used by my university to manage student careers (with bugs discovered by me).
Experience

Det Akademiske Kvarter
Aug 2006 - Feb 2007System administrator and Security EngineerSystem administrator and Security Engineer- Build a secure IDS server with FreeBSD and OpenBSD;- Penetration Testing of the remotely exposed servers and the eticketapplication [https://intern.kvarteret.no/ticket/] used by allthe students(700 c.a.).Skills: *BSD, Debian, arpwatch, Snort, Postgresql, pf, OpenLDAP,Apache, Exim, BIND, MySQL, Paros, nmap, amap, webscarab.

Fantoft Studentboliger Network Group
Sept 2006 - Nov 2006System administrator and Security EngineerSystem administrator and Security EngineerHelp the Network Group to mitigate and prevent arpspoofing/sniffing into the Fantoft network, managing HP and Dlinkswitches with SNMP and implementing IDS sensors tostatically monitor the arp:IP association of main servers.Skills: OpenBSD, Snort, SnortSam, MySQL, iptables, Acid, dsniff,ettercap.

Hakin9
Nov 2006 - Feb 2011Writer and beta-testerWriter and beta-tester (http://en.wikipedia.org/wiki/Hakin9) Official writer, reviewer and beta-tester of articles in english anditalian. I've written three articles by now:1. Introducion to Firewalls: from ISO/OSI stack to DMZ(published in english and italian)2. Gentoo Hardened: portare la sicurezza di Linux all'estremo(published in italian, November 2007);3. Sniffing SSL/TLS connections through fake certificate injection(published in english, January 2008).

University of Bergen
Feb 2007 - May 2007Teaching Assistant in Computer Networks courseTeaching assistant in the course of Computer Networks at HighTechnology Center. My work was help the students during labs withexercices and in-depth explanations about security topics relatedwith the course.

IntegratingWeb
May 2007 - Nov 2010Network and Security ManagerBuild a secure, reliable and powerful Linux based platform forIntegratingWeb with CentoOS 5. Admin and check regularly thehealth of the system.- Official developer of the OpenSource project Opentaps (www.opentaps.org), and contributor of Apache Ofbiz (security)- Implement and Manage the security of the web applications withAcegi Security and JAAS.- Threat Assesment and Penetration testing on the system and thewebsite.- Threat Assesment and Penetration Testing on the IT structure ofmiller.it (and his first product, streamit.it).Skills: Gentoo Hardened, Grsecurity, Sun AP, Glassfish, Jetty, Tomcat, Apache, Postgresql, Postfix, Cyrus-SASL, ProFTP, vsftp, Snort, Base, iptables, Cisco ASDM, tripwire, Nessus, hping, amap, Metasploit,Paros, Burp, Spring Security, JAAS. Show less

Miller s.r.l
Sept 2007 - Dec 2007Penetration TesterI did some penetration tests on the network infrastructure, especially black box testing on mail and web servers, and on Flash applications.

Logital S.P.A
Nov 2008 - Apr 2009Programmer and AnalystManaging software development in legacy products using Visual Basic 6 for the biggest Italian companies. Linux and Java reference person. Java development for Real time access control systems and Real Time media content distribution Bologna buses.

INFN-CNAF
May 2009 - May 2010Researcher and DeveloperResearcher and Developer at INFN -CNAF (National Institute of Nuclear Phisycs, Bologna): - working with OGF-europe (www.ogfeurope.eu) on the OCCI cloud interface, and cloud computing use-cases collection - main Java developer of INFN-CNAF research on Cloud Computing (Spring, Hibernate, Restlet, Jetty, X.509, Kerberos, Shibboleth, Platform LSF, Xen/KVM, Eucalyptus) - penetration tester on some web application that monitor the Tier-1 Grid infrastructure (WMS monitor)

The BeEF Project
Oct 2010 - Oct 2018Core DeveloperAs Web Application Security is one of my main research fields, I couldn't continue without being part of a good open source project. I was using BeEF from many years during pentests and security seminars, and now I'm proud to be part of the core development team. Thanks to Wade for inspiration on many things.Some of my work: - Thin/Rack/Sinatra migration, RESTful API, core architectural and code development; - coaching other people to delve in the BeEF core and/or modules and extensions development; - A number of extensions: Social Engineering, Evasion, Tunneling Proxy, XssRays, etc.. - A number of droppers (Java, Firefox) and other exploits - many enhancements, command modules and general bug fixing. Show less

Royal Bank of Scotland Group
Mar 2011 - Mar 2012Penetration Testing SpecialistPenetration testing of worldwide banking systems. Vulnerability research activities.Main Areas:- Web Application Security- Infrastructure/Web penetration tests and build reviews on *NIX/Linux/Windows- BeEF

Trustwave SpiderLabs
Apr 2012 - Mar 2015Senior Security ConsultantProviding professional consulting services to clients in the following areas: - Application Penetration Testing, - Source Code Analysis and Secure Architecture/Code guidelines, - Social Engineering, - Secure Development and Pentesting live trainings, - Internal Products Pentesting and Code Review.

FortConsult | Part of NCC Group
Apr 2015 - Jun 2017Senior Security ConsultantProviding professional consulting services to clients in the following areas: - Application Penetration Testing, - Phishing and Social Engineering, - Source Code Analysis and Secure Architecture/Coding guidelines.

404 - Not Found
Jun 2017 - Jul 2022Professional Freelancer
Persistent Security Industries
Jul 2022 - nowPrincipal Security Engineer
Licenses & Certifications

Offensive Security Certified Professional (OSCP)
Offensive SecurityJan 2012
Languages
- itItalian
- enEnglish
- spSpanish
- frFrench
Recommendations

Líbera ribeiro nader
Gerente jurídico na Unimed Uberlândia | Liderança | Gestão de departamento jurídico | Direito Empres...Uberlândia, Minas Gerais, Brazil
Sayan datta
Relationship ManagerGreater Kolkata Area
Thomas findeisen
Gruppenleiter Risikoreporting bei HelabaFrankfurt, Hesse, Germany
Maurizio amato
Large Corporate Relationship Manager presso UniCreditMilan, Lombardy, Italy
Kevin wright
Enterprise Account Manager @ hireEZ | Dale Carnegie, Sandler SalesSan Francisco Bay Area
James barry apa
Senior Loan Officer at Savvi Credit UnionBaltinglass, County Wicklow, Ireland
Brittieka mckenzie
PR & Events Manager at VRG GRL (previously MECCA Brands)Gold Coast, Queensland, Australia
Maryam tayebi
Research Fellow at Mātai Medical Research InstituteGisborne, Gisborne, New Zealand
Joe deangelo, mba
VP of Operations at The ROOTS LogisticsLees Summit, Missouri, United States
Dawid machnicki
Technical Lead at Atos Research & InnovationGreater Madrid Metropolitan Area
Jonida flöer
Chief of Staff | Business Manager | COO | Member @ Chief of Staff Association | Certified Chief of S...Zurich, Zurich, Switzerland
Jorunn wessel
Senior kommunikasjonsrådgiver at NTNUTrondheim, Trøndelag, Norway
Kanishka mandal
On an endless quest of learningThane, Maharashtra, India
Murielle durant
Coiffure Murielle coiffeuse à domicileCharleroi Metropolitan Area
Nat chen
Technical Manager - Stark Technology Inc.Hsinchu City, Taiwan, Taiwan
Brooke english, lmsw
Social Work Counselor at MD Anderson Cancer CenterPearland, Texas, United States
Bhavya desai
Investment Research Analyst @ The Quantamental Investment Group| Data Science GradBloomington, Indiana, United States
Pierre-alexandre richit
EntrepreneurBoulogne-Billancourt, Île-de-France, France
Harsh pahariya
Sales Officer | Kellogg's | Ex DaburNew Delhi, Delhi, India
Otto julius herman stümke
ERJ135/140 First Officer at Airlink.City of Johannesburg, Gauteng, South Africa
...