doc-thumbnail
Video meeting . 30 mins
5

1:1 Mentorship #careerbuilding

Give it a try and see if it supports your security journey.
$1$27
Popular

Ratings and feedback

5/5
19 ratings
16
Testimonials
5/5
Very helpful and provided deep industry expertise which I was looking for.
5/5
Thank you Prajal for your time. Your insights are very helpful.
5/5
It was great talking to Prajal. Simple lines solved my doubt, which I was struggling to decide on.
5/5
Had a great and very insightful discussion with Prajal. Definitely it will help my career.

About me

• I was fortunate to be one of the early members which formed the Flipkart security team. Helped grow the team in several security verticals making it one of the most decorated security teams in Indian infosec ecosystem handling complex security problems for Flipkart and its group companies. • Associated with PayPal India Ltd as a Security Engineer, since October 2013. • Associated with PriceWaterhouseCoopers-SDC as a Software Engineer Core Security, Jan 2013 to October 2013. • Associated with Microland Bangalore as Analyst – Professional Services in the department of Vulnerability Assessment and Penetration Testing from October 2010 to Nov 2012. • CEH Certified security professional. • CVE-2012-4002, CVE-2012-4003 CVE-2012-4062, CVE-2013-1761. • In the Hall of Fame for Facebook, Twitter, Google, and Adobe/BugGinie/RedHat/Tuenti/Microsoft/GLPI/Ebay/Acquia/ConstantContacts/37Signals/Owncloud/Ifixit Acknowledgement pages. Skill Summary: • Discovered several vulnerabilities in Core components of GLPI (CVE-2012-4002, CVE-2012-4003), discovered several issues in OCS Inventory (CVE-2012-4062), discovered Local File inclusion vulnerability in one of the core components of Bug Ginnie. • Web Application and Infrastructure Vulnerability Assessment and Penetration testing tools [Acunetix vulnerability scanner, Nmap, Metasploit, Backtrack, Nessus, Nexpose, Paros Web Proxy, WebScarab, Burp Suite, Web Developer etc] Key Projects: Vulnerability Assessment, Penetration Testing, Wireless Network Security Assessment, Web Application Penetration Testing, Threat Modelling, Source Code Review, Vulnerability Research, Web application Firewall (ModSecurity, NAXSI), Log Analysis using Elastic Search/Logstash/Kibana. Security Trainings Delivered: NullCon 2015 - https://nullcon.net/website/goa-15/training/attack-monitoring-using-elasticsearch-logstash-kibana.php NullCon 2016 - https://nullcon.net/website/nullcon-2016/training/attack-monitoring-using-elasticsearch-logstash-kibana.php NullCon 2018 - https://nullcon.net/website/goa-2018/training/attack-monitoring-using-elastic-stack.php C0c0n 2018 - https://is-ra.org/c0c0n/workshop/pre-conference-workshop/#tab4 NullCon 2019 - https://archive.nullcon.net/website/goa-2019/training/building-an-attack-monitoring-solution.php NullCon 2020 - https://archive.nullcon.net/website/goa-2020/training/building-enterprise-grade-security-analytics-platform-using-elastic-stack.php