initializing system
0%
available for work · lagos, nigeria

penetration tester & ctf player

VincentIwuno

alias 0xVince# { offensive security }

$

I research attack surfaces, exploit vulnerabilities responsibly, and build tools that make the web harder to break — for everyone else.

// about me

Who am
I?

I'm Vincent Iwuno, a cybersecurity enthusiast and ethical hacker based in Lagos, Nigeria. I'm passionate about understanding how systems work — and how they break.

I specialize in penetration testing, network security, and security awareness. When I'm not doing CTFs, I'm building tools, writing about security, or setting up lab environments on Kali Linux.

Currently sharpening my skills and working towards professional certifications in offensive security.

10+
Projects
5+
Categories
2+
Platforms
Vincent Iwuno — 0xVince

// technical skills6 categories

My Arsenal

⚔️
01

Offensive Security

MetasploitNmapBurp SuiteSQLmapGoPhishHydra
🔒
02

Network & Infrastructure

WiresharkPostfix/SMTPDNSTcpdumpFirewall RulesDKIM/SPF
💻
03

Programming & Scripting

PythonBashSQLJavaScriptHTML/CSS
👁️
04

OSINT & Recon

MaltegoShodantheHarvesterGoogle DorkingSocial Engineering
🐧
05

Operating Systems

Kali LinuxUbuntuWindows ServerTerminalDual Boot
🌐
06

Web Application Security

XSSSQLiCSRFLFI/RFIOWASP Top 10Recon-ng

// experience3 entries

My Journey

Work
CTF
Research
Education
2026 — present
Researchcurrent

Independent Security Researcher

Self-employed · Lagos, Nigeriaview ↗

Independently researching offensive security techniques and building real-world infrastructure to test attack and defence scenarios. Focus areas include email security, phishing simulation, and network-layer exploitation.

key highlights

  • Architected a production-grade SMTP mail server using Postfix + Brevo with full SPF, DKIM, and DMARC authentication on a custom domain
  • Deployed and operated GoPhish phishing simulation labs — designed realistic lure templates and tracked campaign metrics to study human attack vectors
  • Built a Python + Nmap recon automation pipeline that auto-emails formatted scan reports to a custom domain inbox on completion
  • Actively documenting research as technical blog posts to contribute back to the security community
PostfixGoPhishPythonNmapDNSKali LinuxSMTPDKIM/SPF/DMARC
2025 — 2026
CTF

CTF Competitor & Security Student

TryHackMe · HackTheBox

Immersed in competitive Capture the Flag events spanning web exploitation, privilege escalation, network forensics, binary analysis, and cryptography. Treated every challenge as a real-world attack scenario.

key highlights

  • Solved challenges across 5+ categories: web, pwn, forensics, crypto, and OSINT
  • Completed structured learning paths on TryHackMe covering networking, Linux, and ethical hacking fundamentals
  • Documented and published writeups — building a personal knowledge base of attack techniques and mitigations
  • Consistently progressed to harder difficulty tiers on HackTheBox through methodical enumeration and exploitation
Burp SuiteGDBWiresharkCyberChefSQLmapJohn the RipperGobuster
2024 — 2025
Education

Foundations: Networking & Ethical Hacking

Self-directed · Kali Linux Lab

Dedicated a full year to building the technical foundation of a security career — not through courses alone, but through hands-on lab work, building broken things intentionally, and understanding why they break.

key highlights

  • Mastered TCP/IP, DNS, HTTP, and core networking protocols through packet-level analysis with Wireshark
  • Set up and administered a personal Kali Linux lab environment for safe exploitation practice
  • Learned Python scripting with a focus on security tooling: port scanners, brute-force scripts, and log parsers
  • Studied the OWASP Top 10 in depth — reproducing each vulnerability class in controlled web environments
NetworkingLinux CLIPythonWiresharkOWASPVirtualBoxHTTP/DNS
more on LinkedIn ↗

// projects5 total · 2 in progress

What I've Built

Live
Active
Lab
In Progress
01
Live

Custom SMTP Mail Server

Deployed a full production-grade mail server on Kali Linux using Postfix and Brevo as the relay provider. Configured SPF, DKIM, and DMARC records on a custom domain (vincentiwuno.me) — the same authentication stack used by enterprise mail systems to prevent spoofing.

Fully authenticated outbound email with 0 spam-folder delivery on major providers.

PostfixBrevoDNSKali LinuxDKIMSPFDMARC
project 01view ↗
02
Lab

Phishing Awareness Lab

Set up a controlled GoPhish deployment to simulate end-to-end phishing campaigns — from lure design and domain spoofing to landing page capture and credential harvesting analysis. Built to study how attacks work, not to run them.

Revealed how small design decisions dramatically affect click-through and credential submission rates.

GoPhishSMTPHTML/CSSPython
project 02private repo
03
Active

Network Recon Automation Toolkit

Python scripts that wrap Nmap with smart defaults, parse XML output into readable reports, and auto-email findings to a designated inbox via the custom SMTP server. Designed to cut down repetitive recon work during lab sessions.

Reduced manual recon documentation time significantly — scan-to-report in one command.

PythonNmapBashSMTPXML parsing
project 03view ↗
in the lab
soon
04
In Progress

CTF Writeup Platform

A personal writeup site for documenting CTF solutions — structured by category, difficulty, and platform. Built to solidify my own understanding and give back to the community.

🔧 under active development — details coming soon.
Next.jsMarkdownTailwind
in development🔒 locked
soon
05
In Progress

Recon Dashboard

A web UI for visualizing Nmap scan output — turns raw XML into a clean, searchable interface with port timeline views and host maps.

🔧 under active development — details coming soon.
PythonFlaskNmapSQLite
in development🔒 locked

more coming as I build in public —follow along on GitHub ↗

actively building

// ctf writeups

Capture The Flag

TryHackMe
Rooms completed
Active
HackTheBox
Machines pwned
Active
Categories
Web · Pwn · Crypto · Forensics · OSINT
5+
Techniques
XSS · SQLi · LFI · PrivEsc · RCE
10+

writeups dropping soon — follow @0xvince for updates

// blog

Latest Posts

smtp · infrastructure

Building a production mail server on Kali Linux from scratch

A full walkthrough: Postfix setup, Brevo relay configuration, DKIM key generation, SPF/DMARC record publishing, and testing deliverability — all on a custom domain.

coming soon · 2026
phishing · red team

GoPhish lab: simulating a phishing campaign end-to-end

Setting up GoPhish, crafting convincing lure emails, building credential-capture landing pages, and what the data tells you about human vulnerability.

coming soon · 2026
dns · email security

SPF, DKIM, DMARC — what they actually do and how to break them

Not just definitions — a practical look at how email authentication works at the packet level, and what happens when each record is misconfigured.

coming soon · 2026

// contact

Let's work
together.

Have a security concern, want to collaborate, or just want to talk hacking? Hit me up — I respond to every message.