penetration tester & ctf player
VincentIwuno
alias 0xVince# { offensive security }
$ breaking systems to build better ones.
I research attack surfaces, exploit vulnerabilities responsibly, and build tools that make the web harder to break — for everyone else.
// about me
Who am
I?
I'm Vincent Iwuno — I go by 0xVince online. Based in Nigeria, currently a CS student, but most of what I actually know I picked up outside class: breaking things on purpose, then figuring out why they broke.
Security is where most of my free time goes right now — pentesting, network stuff, setting up infrastructure the hard way on Kali instead of just reading about it. I'd rather spend a weekend debugging DNS records than watch another tutorial.
I also build full-stack apps — that's actually where I started, before security pulled me in. Reverse engineering scratches the same itch: take it apart, see what's actually happening under the abstraction.
Right now I'm grinding CTFs, building real (not toy) infrastructure projects, and working toward some offensive security certs.

// technical skills— 8 categories
My Arsenal
Offensive Security
Network & Infrastructure
Programming & Scripting
OSINT & Recon
Operating Systems
Web Application Security
Application Development
Reverse Engineering
// experience— 4 entries
My Journey
Independent Security Researcher
Building out real infra to actually test attack/defence stuff instead of just reading about it. Mail security and phishing sims mostly right now.
key highlights
- ▶Got a real SMTP server running with Postfix + Brevo — SPF/DKIM/DMARC took way longer than I expected, kept landing in spam until I actually understood how domain verification works
- ▶Ran GoPhish campaigns against myself basically, to see what makes people click
- ▶Wrote a script that runs Nmap and emails me the report so I stop manually copy-pasting scan output
MCP Server Developer — SecureOps AI
Local security auditing server using MCP so an LLM can scan your codebase without your source code ever leaving the machine. Probably the most over-engineered thing on this page, honestly.
CTF Competitor & Security Student
The grind year. TryHackMe and HackTheBox almost every night — web exploitation, privilege escalation, forensics, crypto, and binary stuff I still mostly hate. Every box was a real-world scenario, just with a flag at the end.
Foundations: Networking & Ethical Hacking
A full year spent learning security the hands-on way — no bootcamp, just a Kali box, a lot of intentional breakage, and the patience to figure out why things broke. This is the year everything else on this page builds on.
// projects— 6 total · 2 in progress
What I've Built
Custom SMTP Mail Server
A mail server that actually delivers. Postfix + Brevo on Kali, with SPF, DKIM, and DMARC all configured on vincentiwuno.me. The auth records took forever to get right — kept landing in spam until I properly understood how domain verification works.
Real authenticated email that doesn't hit spam folders on Gmail, Outlook, ProtonMail.
Phishing Awareness Lab
A controlled GoPhish deployment for studying how phishing actually works end to end — lure design, spoofed domains, landing pages, credential capture analysis. Only ever run against myself. The point was to understand the attack, not to run one.
Watching the numbers change when I tweaked a lure template or landing page — tiny design decisions move click-through rates more than you'd think.
Network Recon Automation Toolkit
Python scripts that wrap Nmap with sensible defaults, parse the XML output into a readable report, and email it to my inbox over my own SMTP server. Built because I got tired of manually formatting scan output during recon.
Scan to report in one command — stopped copy-pasting scan output into notes by hand.
SecureOps MCP
A local security auditing server built on the Model Context Protocol — an LLM can trigger scans of your codebase without the source code ever leaving your machine. 14 rules, 39 regex patterns, AST checks, SARIF output, path-traversal protection.
LLM-driven security audits with zero source code leaving the machine.
CTF Writeup Platform
A personal writeup site for documenting CTF solutions — structured by category, difficulty, and platform. Built to solidify my own understanding and give back to the community.
Recon Dashboard
A web UI for turning raw Nmap output into something you can actually search — port timeline views, host maps, and a clean list instead of a wall of XML. Early stage, still fleshing it out.
more coming as I build in public —follow along on GitHub ↗
// capture the flag— ongoing
CTF & Hacking Labs
$ whoami
→ security researcher · ctf player · offensive security student
$ cat philosophy.txt
→ I don't just read about vulnerabilities — I reproduce them, document how they work, and understand why defences fail.
$ status
actively solving · writeups incoming
Structured learning paths, room-based labs, beginner to advanced.
Real-world machine exploitation — Linux & Windows privilege escalation.
Ranked cyber-skills platform — labs and challenges benchmarked across a global leaderboard.
Web · Pwn · Crypto · Forensics · OSINT
skill breakdown
self-assessed proficiency across lab environments — not benchmark scores.
writeups in progress
Exploiting SSRF to reach internal AWS metadata
Manual SQLi bypass on a WAF-protected login
Privilege escalation via SUID misconfiguration
Decoding a multi-layer crypto challenge (RSA+XOR)
writeups dropping on @0xvince ↗ and this site — follow to be notified.
// blog— 3 posts · 1 published
Writing & Research
GoPhish Lab: Simulating a Phishing Campaign End-to-End
Setting up GoPhish, crafting convincing lure emails, building credential-capture landing pages, and what the data tells you about human vulnerability.
SPF, DKIM, DMARC — What They Actually Do and How to Break Them
Not just definitions — a practical look at how email authentication works at the packet level, and what happens when each record is misconfigured.
get notified
First to read when posts drop
Writeups, walkthroughs, and deep dives on real security topics — straight to your inbox. No fluff.
view all posts ↗·follow @0xvince ↗
// contact
Let's work
together.
Have a security concern, want to collaborate on a CTF, or exploring a hire? I read every message and reply within 24 hours.
available for work
open to security roles, freelance pentesting, CTF teams & internships · remote
$ ping 0xvince@vincentiwuno.me
→ response time: < 24h
$ best for
→ security consulting · collaborations · opportunities