N E T H R A N. W E D A G E

Loading

Cybersecurity undergraduate and web developer based in Sri Lanka, passionate about penetration testing, VAPT, and ethical hacking.

ls -la ~/projects/ — real work, real results

My work &
projects

A collection of penetration tests, CTF writeups, web builds, and security tooling — built hands-on, documented thoroughly.

16 Total
7 Categories
3+ Yrs Active
Showing 16 projects
HTB: Lame
01 Easy
HackTheBox 2024

HTB: Lame

Classic Easy Linux box. Exploited a vulnerable Samba service to gain direct root access. Full walkthrough covering enumeration, exploitation and post-exploitation.

Linux Samba Metasploit
HTB: Blue
02 Easy
HackTheBox 2024

HTB: Blue

EternalBlue (MS17-010) exploitation on a Windows target. Manual exploit without Metasploit — using Impacket and custom Python scripts.

Windows EternalBlue MS17-010
HTB: Beep
03 Easy
HackTheBox 2024

HTB: Beep

Elastix / FreePBX server with multiple attack vectors. Exploited Local File Inclusion to grab credentials, then escalated to root via sudo misconfiguration.

Linux LFI FreePBX
HTB: Lise
04 Hard
HackTheBox 2024

HTB: Lise

Elastix / FreePBX server with multiple attack vectors. Exploited Local File Inclusion to grab credentials, then escalated to root via sudo misconfiguration.

Linux LFI FreePBX
THM: Advent of Cyber 2023
05 Mixed
CTF 2024

THM: Advent of Cyber 2023

Multi-day Capture The Flag — 24 challenges spanning web exploitation, OSINT, digital forensics, reverse engineering, and cryptography.

Web Crypto Forensics
THM: Mr Robot CTF
06 Medium
CTF 2024

THM: Mr Robot CTF

Mr Robot themed room — three hidden flags using WordPress exploitation, dictionary attack and SUID binary privilege escalation.

WordPress Brute Force PrivEsc
Dreamway Education Website
07 Client Project
Web Dev 2024

Dreamway Education Website

Full company website for Dreamway Education — responsive design, PHP backend, contact form with mail integration, and SEO-optimised pages.

PHP MySQL Bootstrap
Inventory Management System — Timex
08 Internal Tool
Web Dev 2024

Inventory Management System — Timex

Internal inventory tracking system built for Timex Garments. Role-based access control, stock management, PDF report generation, and audit logs.

PHP MySQL RBAC
Web App VAPT — Sample Target
09 High Severity
VAPT 2024

Web App VAPT — Sample Target

Full web application vulnerability assessment. Identified SQL Injection, XSS, IDOR and broken authentication. CVSS-rated report with PoC and remediation steps.

SQLi XSS IDOR
Network VAPT — Internal Lab
10 Medium Severity
VAPT 2024

Network VAPT — Internal Lab

Internal network vulnerability assessment — open ports, weak protocols, unpatched services and misconfigured firewall rules identified and documented.

Network Nessus OpenVAS
Active Directory Lab Setup & Attack Simulation
11 Advanced
Network 2024

Active Directory Lab Setup & Attack Simulation

Built a full AD environment in VirtualBox — domain controller, workstations, and file server. Simulated Kerberoasting, Pass-the-Hash and BloodHound enumeration.

Active Directory Kerberoasting BloodHound
OSINT Investigation — Target Profiling
12 Intermediate
OSINT 2024

OSINT Investigation — Target Profiling

Full OSINT reconnaissance on a consenting test target — email enumeration, social media mapping, domain/WHOIS analysis, and breach data correlation.

OSINT theHarvester Maltego
Phishing Campaign Simulation
13 Intermediate
OSINT 2024

Phishing Campaign Simulation

Simulated phishing engagement using the Social Engineering Toolkit. Crafted pretexting scenario, credential harvesting page, and awareness gap report for the client.

Phishing SET Social Engineering
Port Scanner — Custom Nmap Wrapper
14 Intermediate
Python 2024

Port Scanner — Custom Nmap Wrapper

Python script that wraps Nmap for automated recon — service version detection, OS fingerprinting, and outputs a formatted HTML/JSON report.

Python Nmap Recon
CTF Auto-Solver — Crypto Challenges
15 Intermediate
Python 2024

CTF Auto-Solver — Crypto Challenges

Toolkit of Python scripts for common CTF crypto challenges — Caesar, Vigenère, Base64 chaining, XOR bruteforce, and RSA weak key exploitation.

Python Cryptography CTF
Network Inventory Script — Timex
16 Practical
Python 2024

Network Inventory Script — Timex

Bash/Python automation that scans the local network, identifies active hosts, pulls MAC addresses and hostnames, and logs results to a CSV for IT audit.

Python Bash Network

No projects yet

Nothing in this category — check back soon.

— Open to Work

Got a project
in mind?

Whether it's a pentest, web build, VAPT, or a security audit — let's talk about what you need.