Rootfox nine-tailed kitsune
Offensive security · Adelaide

Rootfox

I break things I own, on infrastructure I built, and write down exactly how. Web application exploitation, wireless attacks, and the hardware to run them.

0Projects
0Focus areas
0Certifications
Scroll
Currently Cert IV in Cybersecurity
Next upSEC0 → SEC1
Based inAdelaide, SA
Open toJunior security roles
Latest work
Who I am

Built it, broke it,
wrote it down

I'm a cybersecurity student working through the Certificate IV in Cybersecurity at TAFE SA, with SEC0 and SEC1 lined up next. Most of what I actually know came from building things and then taking them apart.

I run a segmented home lab on a three-node Proxmox cluster, deliberately isolated from everything else on the network. That's where the work happens — web app exploitation chains, wireless attacks, service enumeration, privilege escalation — against targets I own, on infrastructure I built.

I build the hardware too. Raspberry Pi cyberdecks, handheld terminals, ESP32 RF tools, a NetHunter phone. If a tool didn't exist the way I wanted it, I made one.

Every project here is documented: what I tried, what worked, what didn't. Findings are only useful if someone else can follow them.

Web application exploitation

SQL injection through to shell — union-based extraction, hash cracking, file upload abuse, post-exploitation enumeration. Full chains, start to finish.

Wireless attacks

WPA2 handshake capture and cracking, evil twin and captive portal setups, monitor mode and packet injection on supported adapters.

Hardware & RF

Software-defined radio, sub-GHz and NFC tooling, custom builds on ESP32 and Raspberry Pi — including portable platforms I designed and assembled.

Linux & infrastructure

A three-node Proxmox cluster on an isolated lab network. VM and container management, segmentation, self-hosted services.

Networking

Subnetting, routing, access control lists, packet analysis in Wireshark. Lab topologies built and hardened rather than read about.

Writing it up

Every engagement documented — method, evidence, remediation. The technical work is half the job; explaining it is the other half.

Projects

Everything below was built, exploited, or broken in my own lab. Newest first.

Infrastructure

rootfox.dev

This site. Static Astro build on Cloudflare Workers, with a content-security policy generated from build-time script hashes.

AstroCloudflareCSP
Hardware & RF

PocketTerm35

Handheld Linux terminal. Solved a persistent audio fault with a GPIO-switched MOSFET circuit so the speaker only powers on demand.

Raspberry PiGPIOElectronics
Hardware & RF

ClockworkPi uConsole

Portable terminal running a CM5 with SDR and LoRa hats. Fixed charging via a PMIC udev rule; still tracing a device-tree conflict on boot.

SDRLoRaLinux
Offensive

Network recon from a phone

Mapped a lab network from an unrooted Android handset — six live hosts discovered and services enumerated, then documented where the platform hits its ceiling.

nmapTermuxRecon
Infrastructure

Self-hosted LLM agent

Local language model running in an LXC container against a separate inference backend, with no data leaving the lab network.

LXCOllamaSelf-hosted
Hardware & RF

Cluster monitor display

ESP32 display board pulling live CPU, memory, disk and network stats from the Proxmox API over a scoped token, cycling nodes on a button press.

ESP32APIMonitoring
Offensive

DVWA — SQL injection to root

Complete chain against a deliberately vulnerable app: union-based injection, credential hash dump, offline cracking, upload to reverse shell, then privilege escalation enumeration.

SQLihashcatPrivesc
Hardware & RF

ESP32 sub-GHz tool

Custom firmware on a cheap display board, wired to sub-GHz, NFC and infrared modules for RF signal capture and analysis.

ESP32RFNFC
Infrastructure

Segmented Proxmox lab

Migrated a three-node cluster onto its own isolated network so exploitation work can't touch anything I rely on. Separate router, separate subnet, no bridge.

ProxmoxSegmentationClustering
Offensive

Evil twin credential capture

Stood up a rogue access point against my own network and captured test credentials through a captive portal, then documented the detection signals that give it away.

WirelessRogue APCaptive portal
Offensive

WPA2 handshake capture & crack

Full wireless workflow on my own access points — monitor mode, deauthentication, handshake capture, GPU-accelerated cracking against a wordlist.

aircrack-nghashcatWPA2
Hardware & RF

NetHunter phone build

Custom Android ROM with root and a mobile pentesting environment. Established the internal chipset can't do monitor mode and specified the adapter needed for injection.

NetHunterAndroidMobile
Hardware & RF

Pi-Edge cyberdeck

Portable Raspberry Pi 5 field unit — UPS hat, 18650 cells, touchscreen, compact keyboard, battery telemetry over I2C, running a full offensive Linux distribution.

Raspberry PiCyberdeck3D printing
Contact

Say hello

Hiring, collaborating, or just want to talk about a build — send it through. I read everything.