-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathcv.tex
More file actions
81 lines (71 loc) · 5.92 KB
/
Copy pathcv.tex
File metadata and controls
81 lines (71 loc) · 5.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
\begin{cv}{Curriculum Vitae of Dr. Mario Heiderich}
\begin{cvlist}{Contact Data}
\item[Address] Auf dem Aspei 32a\\44801 Bochum
\item[Date of Birth] 8th of July, 1981
\item[Born in] Marburg a. d. Lahn
\item[Nationality] German
\item[E-Mail] mario.heiderich{@}rub.de
\end{cvlist}
\begin{cvlist}{Education and Civilian Service}
\item[2000] University Admission, Christian Rauch Schule, Bad Arolsen.
\item[2000--2001] Civilian Service\\Deutsches Rotes Kreuz, Wolfhagen.
\end{cvlist}
\begin{cvlist}{Academic Experience}
\item[2001--2005] Academic Studies and \emph{Graduate Engineer in Media Informatics}, University of Applied Sciences, Friedberg.
\item[since May 2010] PhD Candidate at Prof.~Dr.~Jörg Schwenk, Chair for Network and Data Security, Ruhr-University Bochum.
\item[June 2012] Successfully completed PhD studies at the Chair for Network and Data Security, Ruhr-University Bochum.
\end{cvlist}
\begin{cvlist}{Professional Experience}
\item[2004] University Intern, Editworks GmbH, Marburg a. d. Lahn.
\item[2005--2007] Developer, DocCheck Medical Services GmbH, Cologne.
\item[2007--2009] Security Developer, Ormigo GmbH, Cologne.
\item[2009--2011] Technical Lead / CTO, Business In Inc., New York, USA / Cologne.
\item[since Jan. 2011] Security Researcher, Chair for Network and Data Security, Ruhr-University Bochum.
\item[since Jan. 2011] Security Researcher, Microsoft, Redmond, USA.
\item[since Jul. 2011] Penetrationtester, Deutsche Post AG, Bonn.
\end{cvlist}
\subsection*{Publications}
\begin{enumerate}
\item Crouching Tiger -- Hidden Payload: Security Risks of Scalable Vectors Graphics, Mario Heiderich, Tilman Frosch, Meiko Jensen, Thorsten Holz - 18th ACM Conference on Computer and Communications Security (CCS), October 2011
\item All Your Clouds are Belong to us -- Security Analysis of Cloud Management Interfaces, Juraj Somorovsky, Mario Heiderich, Meiko Jensen, Jörg Schwenk, Nils Gruschka, Luigi Lo Iacono - 18th ACM ACM Cloud Computing Security Workshop (CCSW), October 2011
\item IceShield: Detection and Mitigation of Malicious Websites with a Frozen DOM, Mario Heiderich, Tilman Frosch, Thorsten Holz - 14th International Symposium on Recent Advances in Intrusion Detection (RAID), September 2011
\item The Bug that made me President -- A Browser- and Web-Security Case Study on Helios Voting, Mario Heiderich, Tilman Frosch, Marcus Niemietz, Jörg Schwenk - 3rd International Conference on E-Voting and Identity (VoteID 2011), September 2011
\item The Hare, the Hedgehog and his Wife: Preventing XSS Attacks with JavaScript and a Trusted DOM, Mario Heiderich, Gareth Heyes, Jörg Schwenk, Thorsten Holz - In Submision for 21rd International WWW Conference (WWW 2012), April 2012
\item LiveInspect and Verified Secure Markup: Preventing XSS Attacks with JavaScript and Early DOM Inspection, Mario Heiderich, Gareth Heyes, Jörg Schwenk, Thorsten Holz - In Submision for 17th European Symposium on Research in Computer Security (ESORICS 2012), September 2012
\item Scriptless Attacks -- Stealing the Pie Without Touching the Sill, Mario Heiderich, Marcus Niemietz, Jörg Schwenk, Felix Schuster, Thorsten Holz - In Submision for 19th ACM Computer and Communications Security Conference (CCS 2012), October 2012
\end{enumerate}
\subsection*{Conference Talks}
\begin{enumerate}
\item Got Your Nose -- How Attackers steal your precious Files without using JavaScript, Mario Heiderich, HackInParis 2012, Paris, France
\item The Image that called me -- Active Content Injection with SVG Files, Mario Heiderich, Bluehat 2011, Seattle, USA
\item Locking the Throne Room 2.0 -- How ES5+ will change XSS and Client Side Security, Mario Heiderich, Bluehat 2011, Seattle, USA
\item Locking the Throne Room -- ECMA Script 5, a frozen DOM and the eradication of XSS, Mario Heiderich, Hack In Paris 2011, Paris, France
\item Dev and Blind -- Attacking the Weakest Link in IT Security, Mario Heiderich, Johannes Hofmann, CONFidence 2010 2.0, Prague, Czech Republic
\item The Presence and Future of Web Attacks -- Multi-Layer Attacks and XSSQLI, Mario Heiderich, CONFidence 2010, Krakow, Poland
\item JavaScript from Hell -- Advanced Client Side Injection Techniques of Tomorrow, Mario Heiderich, OWASP AppSec Germany 2009 Conference, Nuremberg, Germany
\item The Ultimate IDS Smackdown -- How red vs. blue situations can influence more than one might assume, Mario Heiderich, Gareth Heyes, OWASP Chapter Meeting 2009, London, UK
\item I thought you were my friend -- Malicious markup, browser issues and other obscurities, Mario Heiderich, CONFidence 2009, Krakow, Poland
\item PHPIDS -- Monitoring Attack Surface Activity, Mario Heiderich, OWASP AppSec Europe 2008, Ghent, Belgium
\end{enumerate}
\subsection*{Projects and Work}
\begin{itemize}
\item Penetration-Testing for various international companies
%\item Penetrationtesting for RWE AG, Essen, Germany
%\item Penetrationtesting and Security Consultancy for Allianz SE, München, Germany
%\item Penetrationtesting and Security Consultancy for XING AG, Hamburg, Germany
%\item Penetrationtesting and Security Consultancy for DocCheck AG, Cologne, Germany
%\item Penetrationtesting and Security Consultancy for AdCloud GmbH, Cologne, Germany
\item Further references can be requested
% Extend !!!
\end{itemize}
\subsection*{Further Activities}
\begin{itemize}
\item Co-founder and Lead Developer PHPIDS, \url{http://phpids.org/}
\item Founder and Maintainer of the HTML5 Security Cheatsheet, \url{http://html5sec.org/}
\item Invited Speaker on international Conferences (CONFidence 2009, 2010, 2011, 2012; Hack In Paris 2011, 2012; OWASP AppSec Research 2010, 2011)
\item Co-Chair on international Web Application Security Summits (OWASP Summit, 2011, Portugal)
\item Captain of Team RUB - Winner of the E-POSTBRIEF Security Cup, 2010
\item Published Author (Sichere Webanwendungen: Das Praxisbuch, Galileo Press, 2008; Web Application Obfuscation, Syngress, 2010)
% Extend !!!
\end{itemize}
\end{cv}