Cybersecurity Portfolio

Jun Han Ong

Cybersecurity student with real data center experience. I build practical security tools, break things in legal labs, and document everything.

OSCP Track Python Linux Data Center Ops

About

I'm Jun Han, a cybersecurity student at UOW/SIM with a background that's a bit different from most — I started in a data center. Running cables, managing racks, troubleshooting hardware at Equinix and Alibaba Cloud taught me that uptime isn't a dashboard metric; it's sweat and procedure.

That operations foundation shapes how I approach security. I don't just run tools — I understand the systems underneath. I'm building OSCP-track fundamentals through legal labs (HTB, THM, PG Practice), writing Python automation for repetitive security workflows, and keeping notes clean enough to survive contact with real incidents.

I'm currently open to junior cybersecurity, cloud security, infrastructure-security, and security-engineering roles where I can put both the operations and security skills to work.

10+Public Projects
2Data Centers
โˆžCuriosity

Projects

Real code, real tests, real documentation. No filler repos.

๐Ÿ”

Auto OSCP Recon Notes

A Python CLI that turns Nmap XML from authorized labs into structured plain-text notes, service checklists, and a report template. Built for my own OSCP workflow.

PythonNmapCLIOSCP
๐Ÿ”

Lamport OTP

Hash-chain one-time password scheme in standard-library Python. Builds SHA-256 chains, discloses in reverse, and verifies against a moving anchor — with tests for replay, forgery, and exhaustion.

PythonCryptographySHA-256
๐Ÿ“Š

Intrusion Detection System Simulation

Anomaly-based IDS that builds a statistical baseline from activity data and flags deviations using weighted scoring. University project where I owned the activity engine and logs modules.

PythonDetectionAnomaly
๐Ÿง 

Targeted Adversarial Attacks on CIFAR-10

Coursework exploring targeted attacks on a VGG-11 CIFAR-10 classifier: grey-box transfer, universal perturbations, and an adaptive EOT attack against a randomised defence.

PythonPyTorchAdversarial MLCIFAR-10
๐Ÿ›ก๏ธ

ARP Security Toolkit

A Scapy-based Python toolkit that pairs passive ARP spoofing detection with an authorized-lab demonstration of ARP cache poisoning.

PythonScapyARPNetwork Security
๐Ÿ”’

Envelope Encryption

An OpenSSL and Python demonstration of hybrid encryption, combining AES data encryption with RSA-OAEP key wrapping and verify-before-delete safeguards.

PythonOpenSSLCryptographyRSA-OAEP
๐Ÿ”

Python Reverse Shell

A minimal TCP listener and client that demonstrate reverse-shell mechanics with a JSON protocol in controlled, authorized lab environments.

PythonTCPNetworkingLab Only
๐Ÿงฉ

UDP Service CTF Write-up

A controlled CTF lab walkthrough covering UDP service discovery, raw service interaction, targeted MD5 recovery, and result verification.

CTFUDPNmapHashcat
โฑ๏ธ

TOTP Simulator

RFC 6238 time-based one-time passwords in standard-library Python — the scheme behind authenticator apps. Verified against official test vectors with SHA-1, SHA-256, and SHA-512.

PythonRFC 6238Cryptography
๐ŸŒ

Portfolio Site

This site. Plain HTML, CSS, and JavaScript — no frameworks, no build step, no bloat. Responsive, accessible, and hosted on GitHub Pages.

HTML/CSSGitHub PagesWeb
๐Ÿงช

Security Lab Workflow

Structured methodology for legal lab practice — enumeration checklists, web testing notes, privilege-escalation templates, and post-box reflections. Turns practice into evidence.

MethodologyHTBTHMOSCP

Skills

What I bring to the table right now — honest levels, no inflation.

Security

  • Nmap & EnumerationBuilding
  • Burp Suite & Web TestingBuilding
  • Linux Privilege EscalationExploring
  • SQL Injection ConceptsExploring

Infrastructure & Systems

  • Data Center OperationsComfortable
  • Linux AdministrationComfortable
  • Networking FundamentalsBuilding
  • Troubleshooting & UptimeComfortable

Programming & Automation

  • PythonComfortable
  • Bash & Shell ScriptingBuilding
  • Git & CI/CDBuilding
  • C++ / SQLExploring

Experience

The path that got me here — from data center floors to security labs.

Now

Cybersecurity Student

UOW/SIM cybersecurity program. Building public projects that demonstrate practical skills rather than just collecting certificates.

Current Track

OSCP-Oriented Practice

Structured lab time across enumeration, web testing, privilege escalation, and documentation. Building the methodology before the exam.

Before

Data Center Operations

Equinix & Alibaba Cloud — hardware, racks, structured cabling, incident response, and the kind of troubleshooting you learn when something is down at 3 AM.

Earlier

SAF Artillery Operator

Built discipline, pressure handling, teamwork, and respect for clear operating procedures. These translate directly to security operations.

Contact

Open to junior cybersecurity, cloud security, and infrastructure-security roles. Let's talk.