Quick Links

Sunil Yadav

Sunil Yadav is a Senior Security analyst at NII. He has performed Security Audits, Penetration Test, Source Code Review, Threat Modeling, Social engineering, Reverse Engineering and Ethical Hacking Trainings etc. for some of NII’s premier customers. He has consistently impressed clients with his ability to think out of the box, and creatively attack systems and applications. He is well-versed with the OWASP, WASC and SDL like methodologies.

 

His technical abilities span a very wide range of technologies across networks, operating systems, databases, web servers, and applications; however his specialization is web applications research on new hacking tools, web application development etc. He possesses strong analytical skills and is a part of the research activities undertaken at NII.

Profile
Educational Qualification
  • Master Degree in Computer Science (Advance)
    University of Mumbai, India
  • Bachelors Degree in Computer Science
    University of Mumbai, India
Detailed Experience & Expertise
  • Application Security
    • Well versed with OWASP – Top Ten, WASC Threat Classifications and other Application security Forums
    • Expertise in Vulnerability Assessment and Penetration Testing of Web Applications
    • Business-Logic based execution and testing of various threat scenarios.
    • Code Reviews for .Net and Java Based Applications
  • Network Security
    • Worked on security for a range of operating systems, databases, web servers and applications
    • Experience with an extensive range of security systems and solutions.
Technical Skills
  • Operating Systems: Windows 9x/NT/2000/XP/2003/2008/Vista, Linux
  • Servers: Domain controllers (Active Directory), DNS (Microsoft DNS, BIND), DHCP, Web Servers (Microsoft IIS, Apache), FTP (Microsoft FTP, vsftp, wu-ftp)
  • Databases:MS-SQL 2005/2008
  • Network components: Firewalls, Routers, VPN, Switches, WLAN access points
  • Security tools: Nmap, Nessus, WebScarab, Superscan, Achilles,Acunetix, Burp Suite, AppScan, etc.
  • Technology:SharePoint 2007/10, ASP.NET, C#, IIS, Web services, AJAX, XML, WCF, Silverlight, SQL 2008/05, LINQ, Workflow, JQuery, JSON, and Windows Azure.
  • Languages:C#, ASP.NET, Java, SQL, HTML, XML and JavaScript
Tools Developed
  • Developed following products at NII :
  • NX27K(www.niiconsulting.com/products.html)
  • Enterprise Security Portal –Enhanced version of NX27K
Internalpersonal Skills
  • Have good communication skill by virtue of being an alumni & conducting workshops & demonstrations at various seminars.

  • Experience in product development and client interactions. Experience in leading a team & dealing with senior and middle management, system administrators, auditors, clients, customers, etc. Very strong commitment to quality of deliverables

Significant InfoSec projects
  • Penetration and Web Application & Network  Pen testing for:

    • Banking & Financial Services
    • Insurance Companies
    • Health Care
    • Trading Applications
    • Telecom Providers
    • Core Banking Applications
Hands on Experience in InfoSec Domains

 

    • Conducted numerous trainings for Developers on Secure Coding & Ethical Hacking
    • Insurance Companies
    • Source Code Review for technologies like .Net and JAVA.
    • Web Application Security Assessments and Audits
    • Vulnerability Assessments & Penetration Tests for Network
    • Kiosk assessment as per PCI DSS compliance