← back to terminal

Resume snapshot

Jun Han

Cybersecurity student · Data center experience · OSCP-track learner

Profile

Cybersecurity student with hands-on data center experience and a practical approach to security. Focused on Linux, penetration-testing fundamentals, infrastructure hardening, automation, and clear technical documentation. I build small, tested, public projects that show how I think and work.

Core strengths

  • Infrastructure operations mindset from real data center environments.
  • Security fundamentals: enumeration, web testing basics, SQL injection concepts, Burp Suite, Nmap, Linux privilege-escalation basics.
  • Automation with Python, Bash, output parsing, and repeatable reporting workflows.
  • Operating discipline carried over from SAF Artillery Operator experience.

Tools

  • Python, Bash, C++, SQL, Git, Linux
  • Nmap, Burp Suite, basic web-exploitation workflows
  • Plain-text notes, HTML/CSS/JS, GitHub Pages, documentation systems
  • HTB / THM-style lab practice and structured notes

Experience

Data Center Operations

Equinix & Alibaba Cloud environments

Hands-on experience in physical infrastructure: hardware, racks, operational constraints, troubleshooting, and reliability-focused procedures where uptime is non-negotiable.

Artillery Operator

Singapore Armed Forces (SAF)

Developed discipline, teamwork, precise procedure-following, and the ability to perform under pressure.

Education & learning

  • Cybersecurity student at UOW / SIM.
  • Studying cybersecurity and system-security topics.
  • Preparing for OSCP through legal lab practice, structured notes, and project-based learning.

Selected projects

  • Auto OSCP Recon Notes: Python CLI that turns local Nmap XML from authorized labs into plain-text recon notes, service checklists, and a report template (pytest + CI).
  • Lamport OTP: standard-library Python implementation of a hash-chain one-time password scheme with replay-rejection tests.
  • TOTP Simulator: RFC 6238 time-based OTP implementation verified against official test vectors.
  • Intrusion Detection System Simulation: anomaly-based IDS using baselines, weighted deviations, and alerting logic.
  • ARP Security Toolkit: Scapy-based ARP spoofing detection paired with an authorized-lab demonstration of ARP cache poisoning.
  • Envelope Encryption: OpenSSL and Python hybrid-encryption demo using AES data encryption and RSA-OAEP key wrapping.
  • Python Reverse Shell: controlled-lab TCP listener and client demonstrating reverse-shell mechanics with a JSON protocol.
  • UDP Service CTF Write-up: isolated-lab walkthrough of UDP service discovery and targeted MD5 recovery.
  • Cybersecurity Portfolio Site: responsive plain HTML, CSS, and JavaScript site hosted on GitHub Pages.