About
๐ Hello!
Iโm Nguyแป n Giรกp Anh Khoa, a third-year Information Security student at Ho Chi Minh City University of Industry and Trade (HUIT), expected to graduate in 2027.
My primary interest is Offensive Security, especially Web Application Penetration Testing. I enjoy learning by solving real-world security labs, participating in CTF competitions, and building home labs to understand both attack techniques and defensive mechanisms.
My goal is to become a professional Penetration Tester capable of identifying vulnerabilities and helping organizations improve their security posture.
๐ฏ Areas of Interest
- Web Application Penetration Testing
- Network Penetration Testing
- Active Directory Security
๐ Technical Skills
Programming
- C/C++
- C#
- Basic Python
Security
- Burp Suite
- Nmap
- Wireshark
- Metasploit
- Gobuster
- SQLMap
- FFUF
- John the Ripper
- Hashcat
Operating Systems
- Kali Linux
- Ubuntu
- Windows
Knowledge
- TCP/IP & Networking
- Linux Fundamentals
- OWASP Top 10 (2021)
- Web Security
- Basic Active Directory
๐ฉ Practical Experience
I continuously improve my practical skills through security labs and Capture The Flag (CTF) competitions.
Some of the topics I have worked on include:
- SQL Injection
- Cross-Site Scripting (XSS)
- Authentication & Authorization flaws
- Local File Inclusion
- File Upload vulnerabilities
- Reconnaissance & Enumeration
- Privilege Escalation (Linux)
- Basic Active Directory attacks
I have also participated in CTF competitions such as BKISC CTF 2026 and THCon CTF 2026, where I solved beginner Web and OSINT challenges.
๐ Learning Platforms
Iโm learning, and developed my self by involve in these learing platfoms
- Hack The Box Academy
- TryHackMe
- PortSwigger Web Security Academy
- picoCTF
- Cisco Ethical Hacker
๐ Featured Projects
๐น Phishing Simulation Lab
Built a phishing laboratory using:
- OWASP Juice Shop
- Nginx Reverse Proxy
- Evilginx2
- GoPhish
Studied phishing techniques including Browser-in-the-Browser, Clickjacking, Homograph attacks, and Proxy Phishing.
๐น DoS / DDoS Home Lab
Built a virtual lab consisting of Kali Linux, Ubuntu and Windows machines to simulate DoS/DDoS attacks.
Used Wireshark to analyze attack traffic and evaluated mitigation techniques including firewall rules, monitoring and IP blocking.
๐ Current Learning
Currently focusing on:
- Hack The Box Academy Penetration Tester Path
- Web Application Security
- Active Directory Exploitation
- Privilege Escalation
- Malware Analysis
- Report Writing
๐ Profiles
- Blog: https://melodickat.github.io
- Hack The Box: https://profile.hackthebox.com/profile/019dd773-0480-72a9-918b-6f84c2e96be1
- TryHackMe: https://tryhackme.com/p/GekkoGecko
- OSINT Industries: https://ctf.osint.industries/users/4244
๐ซ Contact
- ๐ง favcolbun@gmail.com
- ๐ Bien Hoa, Dong Nai, Vietnam