Romain Carnus

Senior Cybersecurity Consultant | Ethical Hacker
Expertise
Analyst / Advisor, Project management / PCO
Availability date
Now
Keywords
Test d’intrusion, Sécurité de l'information, Recherche de vulnérabilité, Conception d'architectures de sécurité, Protocoles de sécurité
Regions
Other - International, Montreal, Other - Telework

Whether you are designing smart industrial products or managing sensitive data in your IT system, your business is facing unique security needs and challenges that keep you up at night. I can help you enhance your overall cybersecurity posture with a custom tailored approach, by evaluating the threats you are facing and helping you mitigate them. That way you will be able to continue enhancing your products and IT systems, and your organization can focus on its core business.

Cybersecurity researcher and independent consultant, I have been working in cybersecurity since 2011. Specialized in offensive security and vulnerability research, I am passionate about hacking things to help enhance the security posture of my customers. My approach is analytic, pragmatic and organized.

I particularly enjoy subjects related to IoT, Active Directory, OT/ICS technologies, kernel and hypervisors.

I have worked in various environments including intelligence administration, service companies and industrial products.

Some of the vulnerabilities I have been involved with:

CVE-2020-8218 - Authenticated RCE in pulse secure - https://www.gosecure.net/blog/2020/08/26/forget-your-perimeterrce-in-pulse-connect-secure-cve-2020-8218/

CVE-2020-1013 - Group Policy Elevation of Privilege Vulnerability - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1013

Wrong naming: WSUS privilege escalation - use of user web proxy AND use of user cert store for system process

CVE-2021-1694 - Windows Update Stack Elevation of Privilege Vulnerability - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1694

WSUS NTLM relay bug duplicate

CVE-2022-3682 - Authenticated RCE in HE SDM600 - Unrestricted Upload of File with Dangerous Type - https://publisher.hitachienergy.com/preview?DocumentID=8DBD000138&LanguageCode=en&DocumentPartId=&Action=Launch

CVE-2022-3683 - Applicative Privilege Escalation in HE SDM600 - Missing Authorization

CVE-2022-3685 - Excessive privileges for web application in HE SDM600

More to come 🙂

Blog posts:

https://gosecure.ai/blog/2021/11/22/gosecure-investigates-abusing-windows-server-update-services-wsus-to-enable-ntlm-relaying-attacks

Specializations

Analyst / Advisor (11 years of experience)

Project management / PCO (2 years of experience)

Specialization: Management – Project

To contact the consultant :

R C

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form

Restez à l'affût de nos actualités !

Abonnez-vous à notre infolettre pour être au courant de nos activités 🚀