Peter Winter-Smith

Principal Security Consultant @Mdsec

London, GB
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Feb 2020 — Present

Principal Security Consultant @Mdsec

View department →

London, GB

Joined as an application security consultant and to help develop custom tooling for assessments; currently leading research & development for MDSec’s Nighthawk command and control software product.Areas of expertise include:Security code reviewWeb application/services security assessmentCompiled application assessmentThick client security assessmentBrowser plugin/extension assessmentCryptography assessmentThreat modellingWindows exploit developmentDevelopment of custom tooling

EDUCATION

2013

The Open University

BSc (Hons), Mathematics

SKILLS

Computer SecurityReverse EngineeringSecurity AuditsMalware AnalysisVulnerability ScanningInformation Security ManagementVulnerability AssessmentInformation SecuritySecurity Architecture DesignSecurityCode ReviewPenetration TestingCryptographyVulnerability ManagementWeb Application SecurityApplication SecurityNetwork Security

ABOUT PETER WINTER-SMITH

Primary skills:• Software security assessment• Vulnerability discovery• Web application/web services assessment• Security code review• Native code reverse engineering for security• Development of testing tools, fuzzers and extension scriptsProgramming Languages:• Developed software in C/C++, C# and Python• Code review in JavaScript, Java, PHP, Go, and others• Developed code in x86 and x64 assembler for low level softwareOperating Systems:• WindowsOther:• Understand and have implemented cryptographic algorithms from first principles (RSA, DH, several elliptic curve algorithms)• Exploit developmentPublic Advisories (Partial):• libssh authentication bypass (CVE-20•••••93)• Adobe PDF Reader browser plugin remote code execution• NVidia Display Driver service privilege elevation• PGP Desktop RPC remote code execution• Microsoft Active Directory Denial of Service (MS07-039)• Microsoft RRAS Service remote code execution (ms06-025)• Microsoft Excel remote code execution (ms06-012)• Microsoft Install Engine remote code execution (ms04-038)• Microsoft Task Scheduler remote code execution (ms04-022)• Microsoft Word Wordperfect Converter remote code execution (ms04-027)• Microsoft Internet Information Server RCE and Denial of Service (ms07-041)• Microsoft Common Controls AVI file remote code execution• Microsoft DirectShow remote code execution (ms07-064)• Microsoft Winsock remote code execution (ms06-041)• Microsoft Internet Explorer remote code execution (ms11-050)• Microsoft Netware Client remote code execution (ms06-066)• Microsoft HTML Help remote code execution (ms05-026)• Microsoft Windows Media Player remote code execution (ms09-047)• Microsoft GDI+ remote code execution (ms08-052)• Novell eDirectory remote code execution• Redhat/Fedora/Sun Directory & Certificate Server remote code execution• LSoft ListServe remote code execution• Lexmark Printer RPC remote code execution• Quicktime, Realplayer & Winamp multiple remote code executionI no longer do public vulnerability research so the above advisories are dated but still give indication of my key areas of focus in this capacity.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.