Steve Campbell

Hack All The Things

Role
Technical Lead at CDW
Location
Chesapeake, VA, US
LinkedIn followers
500 followers
Information TechnologyView LinkedIn profile

About Steve Campbell

I’m the author of the book “Bash Shell Scripting for Pentesters”: https://a.co/d/cZhrRqAI\'m a retired Navy veteran, Security Consultant, and a researcher with over 20 years of experience in information technology and security. I specialize in Web Application, Internal, External, and WiFi network pentests, mobile application and API assessments, and Industrial Controls Security assessments. I have planned, scoped, lead, and performed penetration testing engagements on various major enterprises, such as: Fortune 500, government institutions, banking, finance, healthcare and insurance, ecommerce, legal, and energy sector clients. These engagements provided deep insights to the organization on their weak points, how they can be connected to a full attack vector, how they can be monitored, detected, quarantined, and remediated.I\'m a Technical Lead and mentor on an offensive security consultant team. These days I\'m focused on application security and have an active role in creating team training and methodology. Visit my blog at: repositories: https://github.com/sdcampbell and https://github.com/cylentsecCVE\'s and Exploit Code- CVE-20•••••94, CVSS Score 9.8, Critical: Incorrect Access Control in Hospital Management System EMR password reset in versions before 3.11.11- Developed the first public exploit code and Metasploit module for CVE-20•••••22- Developed private team tools using C# to bypass antivirus and EDR detection to load assemblies and shellcode- CVE-20•••••54, CVSS Score 6.5, Medium: There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances version 9.0.146- CVE-20•••••36, CVSS Score 6.1, Medium: Multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist in Nakivo Backup and Replication before 10•••••27- CVE-20••••48, CVSS Score 8.7, High: LDAP bind credential exposure in Barracuda Email Security Gateway, Web Application Firewall- CVSS Score 6.1, Medium: Epson AirPrint reflected XSS- CVE-20•••••08, CVSS Score 9.8, Critical: Unauthenticated Remote Code Execution as root in Western Digital MyCloud- CVE-20•••••07, CVSS Score 9.8, Critical: Unauthenticated Remote Code Execution as root in Western Digital MyCloud- Insecure Direct Object Reference (IDOR)- 2005. IDOR vulnerability which exposed the PII of Navy and Marine Corps personnel to the Internet.

Experience

  1. Technical Lead

    CDW

    Mar 2022 — Present

    Leads and mentor pentesters on the Offensive Security team* Creates methodology documentation, training material, and tools to enable team operations* AppSec Engineering Team Lead* Technical resource for Sales and Field Solution Architects

Education

  • ECPI University

    Bachelor of Science (B.S.), Networking and Security Management

    2006 — 2009

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Steve Campbell — Technical Lead at CDW in Chesapeake, VA, US | Unifers