Cool people doing cool things, check them out!
The Man The Myth The Lemmon
An old school Phreaker, Phriend and mentor:
Technology At Work
Full stack web development wizard
A fullstack wizard friend and mentor:
The Trove of Gems
About Me
Self-proclaimed nerd, technologist, gamer, & avid learner who has an addiction to two wheels.
An organized chaos of my work, interests, & accomplishments.
Interests
Technology
My passion for technology began early, fueled by a love of video games and an insatiable curiosity that led me
to take apart anything I could get my hands on. This interest eventually guided me into the IT industry, where
I landed my first tech role at a small startup in sunny Orange County, California. I started in technical support
and soon transitioned into manual QA and automation testing. When the startup was acquired by Scotts Miracle-Gro,
I relocated to Colorado shortly after. There, I realized I thrive in smaller companies where I can wear multiple hats
and make a meaningful impact. This led me to a PBX manufacturer and telecom company, where I deepened my understanding
of the IT industry, rapidly expanded my skill set, and built lasting professional relationships.
Video Games
Video games have always been more than just a hobby, they’ve shaped who I am. It all started with a Game Boy Color and Pokémon,
then progressed through the Nintendo 64, GameCube, Xbox, PlayStation, and eventually PC gaming. Building my first gaming rig
(the same machine I’m typing this on today) was a turning point. World of Warcraft became a huge part of my life; I sank countless
hours into it, formed incredible friendships across the globe, and even met one of my best friends to this day, Dustin, through
the game. Those experiences taught me collaboration, problem-solving, and the joy of connecting with people over shared passions. Skills
that still serve me in tech.
Cooking
Cooking has been another lifelong love, one that turned into a necessity when I moved out on my own. I owe almost everything I
know in the kitchen to my incredible friend Dustin who patiently taught me the fundamentals and beyond, and I’ll always be grateful
for his guidance. These days I’m especially proud of my mapo tofu, Sichuan eggplant, street-style tacos, and anything pan-seared—fish,
steaks, chops, you name it. If it can go in a hot pan or the oven, I’m confident I can make it delicious.
Plants & Bio-tech
Plants have fascinated me since I was a kid. Over the years I’ve explored horticulture and gardening, experimented with hydroponics and
aeroponics, and dove deep into earthen-building techniques. My long-term dream is to one day own a piece of land and build a fully self-sustaining
earthship with my own hands. An off-grid home that grows its own food, recycles its water, and runs on renewable energy. Everything I learn, from
IT to cooking to growing plants, feels like it’s leading me toward that goal.
Motorcycles
I've got a small collection of bikes, but my absolute favorite is the 2023 Harley-Davidson Low Rider S. There's simply nothing like cracking the throttle
open and letting that Milwaukee-Eight 117 torque pull you forward. California is a rider's paradise, and my favorite stretches are in San Diego, Orange County,
and the Beach Cities. Whether it's cruising down the PCH with the ocean on one side or carving through twisty mountain roads, the year round perfect weather makes every ride memorable.
The next few motorcycles I'd like would be an old shovelhead or sportster chopper as a project bike, a early 2000s Dyna (if you know you know, looking at you Dyna bros), and a Honda CBR just for the Hell of it.
Accomplishments
Education
- B.S Cybersecurity and Informtion Assurance
Licenses & Certifications
- CompTIA PenTest+ ce
- CompTIA CySA+ ce
- CompTIA Project+
- CompTIA Security+ ce
- CompTIA Network+ ce
- CompTIA A+ ce
- CompTIA IT Operations Specialist – CIOS
- CompTIA Secure Infrastructure Specialist – CSIS
- CompTIA Security Analytics Professional – CSAP
- CompTIA Network Vulnerability Assessment Professional - CNVP
- CompTIA Network Security Professional - CNSP
- Certified Cloud Security Professional (CCSP)
- Systems Security Certified Practitioner (SSCP)
- Certified Encryption Specialist (EC-Council ECES)
- ITIL® Foundation
Employment History
Lead Technical Support and QA Engineer
Level 3 VoIP Engineer
CISO/Platform Engineer (Current)
Lead VoIP and Network Engineer (Current)
The Chaos and Learning
CompTIA A+ Notes
CompTIA Network+ Notes
CompTIA Security+ Notes
CompTIA CySA+ Notes
CompTIA Pentest+ Notes
Encryption Notes
Networking
Architecture
Tunneling
VPNs
Troubleshooting
Tips and Tricks
PBX/VoIP
Architecture
In my own personal experience, when it comes to installation PBX servers there are generally two scenarios you will run into, at least in my line of work in Hotel/SOHO PBX environments, which, in all fairness is going the way of the Dodo. Nevertheless, let's dive in!
You will typically see Host based and Premise based PBX installs, there's also an interesting host+proxy install you can run into as well but we will touch on that at the end, also please keep in mind this is not an exhaustive list of ways to do this, these are just typically what I work in on the daily. :)
Host based PBX solution:
The companies I worked for will use AWS but ultimately it doesn't matter which cloud provider you wish to use, that will boil down to what your needs and experience are. So in the cloud you will have an Asterisk/FreePBX/insertFlavorOfPBXYouWantHere.
On premise you will typically have a firewall, switch, SIP Phones (hardware based or software based), Analog phones, NVT Phybridge Analog to SIP converters for connecting your SIP phones RJ45 port to an RJ11 2-pair port, and Analog to SIP gateways for true analog devices. This is not an exhaustive list as you will obviously have further materials and components, this is a very high level overview.
How will this somewhat look like and how will this all connect you might ask? Great question!
In short it will look something like this top down in a server rack:
Patch Panel - Neat and manageable cable management
Firewall - Routing and remote access
Switch - VLAN support prefably to connect all your components together
PBX - Call routing, Trunks, Queues, Ring Groups, the heard of the setup essentially!
NVT Phybridge - Allows you to run SIP phones over 2-pair cross connect wire
Analog Gateways - Allows you to connect analog phones to the PBX via SIP registartion
PDU and UPS - Protects equipment in event of brownouts/hard shutdowns
Troubleshooting
Troubleshooting section
Tips and Tricks
Tips and tricks section
Cybersecurity
SO MUCH TO PUT HERE
Home Lab
PFSense Notes
1. Overview
This section describes the physical and logical network design for my home lab environment The lab hosts a mix of personal and company owned equipment, separated by role and ownership.
The primary goals are hands on learning, network segmentation testing, self hosted services, and a safe sandbox for enterprise grade equipment.
1.1 Scope
- Personal equipment: Modem, PFSense firewall (fw00), two FortiGate 60E firewalls (fw001 & fw002), Zyxel distribution switch, Zyxel APs, Asterisk PBX, Proxmox server, SIP end points.
- Company supplied equipment: FortiGate 40F, Ruckus AP, Ruckus switch which is all logically isolated from personal network items.
1.2 Design Goals
- Maintain clear separation between personal and company owned gear
- Provide multi-firewall architecture for routing and policy testing
- support VoIP services via Asterisk PBX
- enable controlled wireless access
2. Network Topology
2.1 High-Level Architecture
The network follows a hierarchial design with the ISP DMARC as the upstream boundary. Traffic flows from the ISP through the modem, then to the PFSense firewall (fw00) acting as the network headend.
fw00 distributes WAN connectivity downstream to both FortiGate 60E firewalls (fw001 and fw002), creating a duel-firewall segment for testing and redundancy.
Topology Summary
ISP DMARC → Netgear Modem → pfSense FW00 (headend)
FW00 → FortiGate FW001 (172.16.0.30)
FW00 → FortiGate FW002 (172.16.0.40)
FW00 → Zyxel GS1920-24HP Distribution Switch
Distribution Switch → Proxmox (172.16.0.10), Asterisk PBX, Zyxel APs
Company Segment: FortiGate 40F, Ruckus Switch, Ruckus AP [isolated]
2.2 Tier Device(s) Role Ownership
Tier 0 – Edge Modem ISP Termination/NAT Personal
Tier 1 – Core FW pfSense SG-1100 (FW00) Headend Firewall/rOUTER Personal
Tier 2 – Dist FW FortiGate 60E (FW001) Downstream Firewall/Segment A Personal
Tier 2 – Dist FW FortiGate 60E (FW002) Downstream Firewall/Segment B Personal
Tier 2 – Company FortiGate 40F Company Test Segment Company
Tier 3 – Access Zyxel GS1920-24HP Distribution Switch Personal
Tier 3 – Access Ruckus Switch Company Wireless Distribution Company
Tier 4 – Hosts Dell Proxmox Virtualization Host Personal
Tier 4 – Hosts Asterisk PBX VoIP / Telephony Personal
Tier 4 – Wireless Zyxel APs Personal Wireless Access Personal
Tier 4 – Wireless Ruckus AP Company Wireless Access Company
3. Device Inventory & IP Addressing
IP Addressing Scheme
Network: 172.16.0.0/16
Subnet: 172.16.0.0 – 172.16.255.255
Range: 65,534 hosts
Purpose: Primary lab subnet
Network: 172.16.0.x
Subnet: 172.16.0.1 – 172.16.0.99
Range: Static assignments
Purpose: Infrastructure devices
Network: 172.16.0.x
Subnet: 172.16.0.100+
Rage: DHCP pool (TBD)
Purpose: Dynamic client assignment
ProxMox Lab Setup Notes
1. Downloaded ProxMox VE ISO
2. Used Rufus to format USB stick for ISO install
3. Plugged USB into old Dell server
4. Booted into BIOS and booted from USB stick
5. Chose graphical install
6. Set Target Harddisk to the single SSD 1TB drive in the Dell server using an XFS file system (if multiple drives/redundant setup I would have used ZFS)
7. Setup region
8. Setup admin password and email address
9. Set static IP
10. Rebooted and completed the install
11. loaded my kali ISO under my local storage on node localhost and added and ISO image, under "ISO Images"
12. Went to top right hand corner of ProxMox and clicked on Create VM
13. Went through the standard setup options to configure hardware
14. Started my install
NOTE: To anyone else - if you see your image install continue to loop, don't forget to change the boot order/remove the ISO image from the CD/ROM under your VMS hardware :)
15. Logged into kali and updated and upgraded my packages
16. Created a baseline snapshot
17. Loaded my ubuntu iso under my local storage on node localhost and added ISO image under "ISO images"
Followed roughly the same steps for kali
Rinsed and repeated for Windows 10 eval. However, I also had to install virtio-win.iso by putting it into the hardware CD/ROM and then locating it in my Windows 10 VM and installing it.
For metasploitable, slightly different, had to upload the .vmdk via scp to proxmox server:
C:\iso files>scp Metasploitable.vmdk root@172.16.0.10:/root/
The authenticity of host '172.16.0.10 (172.16.0.10)' can't be established.
ED25519 key fingerprint is SHA256:xRVqOhKSPKc3291TvsXAU3O+tNAqnwcu4zYZeaH+MxU.
This key is not known by any other names.
Are you sure you want to continue connecting (yes/no/[fingerprint])?
Warning: Permanently added '172.16.0.10' (ED25519) to the list of known hosts.
root@172.16.0.10's password:
Permission denied, please try again.
root@172.16.0.10's password:
root@localhost:~# qm importdisk 103 /root/Metasploitable.vmdk local-lvm --format qcow2
importing disk '/root/Metasploitable.vmdk' to VM 103 ...
format 'qcow2' is not supported by the target storage - using 'raw' instead
Logical volume "vm-103-disk-0" created.
Logical volume pve/vm-103-disk-0 changed.
transferred 8.0 GiB of 8.0 GiB (100.00%)
Shut down the VM if it's still running (force stop from Proxmox GUI if needed).
Go to VM 103 → Hardware tab.
Look for your SCSI Controller line (likely VirtIO SCSI or VirtIO SCSI single — this is the default when importing/attaching disks).
Select it → Edit (or Remove if needed, then re-add).
Change to LSI 53C895A (also called "Default (LSI 53C895A)" or just "LSI").
This emulates an old-school SCSI controller that Metasploitable 2's kernel understands natively (no extra modules needed).
unused0: successfully imported disk 'local-lvm:vm-103-disk-0'
root@localhost:~#
Metasploitable.vmdk 100% 1856MB 112.7MB/s 00:16
C:\iso files>
Rust Desk Setup Notes
Self-Hosting RustDesk on Vultr VPS
In this project, I set up a self-hosted RustDesk server on a Vultr VPS for secure, private remote desktop access. RustDesk is an excellent open-source TeamViewer/AnyDesk alternative.
So why Self-Host RustDesk?
- Full privacy and control
- No usage limits or recurring fees
- Runs very lightweight (ideal for small teams or personal use)
1. VPS Selection (Vultr)
Location: Los Angeles, CA (closest to me)
Type: Shared CPU → High Frequency Compute (recommended over Dedicated CPU or Bare Metal for my particular workload)
Specs: 1–2 vCPU / 2 GB RAM (more than sufficient)
OS: Ubuntu 24.04 LTS
Cost, roughly $6–12/month
2. Initial Server Setup
Deployed the instance and retrieved the temporary root password from the Vultr dashboard.
Logged in via SSH using password.
Updated the system:Bashapt update && apt upgrade -y
3. SSH Key Authentication (Security Hardening)
Generated an Ed25519 SSH key on Windows using PowerShell:PowerShellssh-keygen -t ed25519
Added the public key to ~/.ssh/authorized_keys on the server.
Disabled password login in /etc/ssh/sshd_config:BashPasswordAuthentication no
systemctl restart ssh
Tested key-based login from new sessions.
4. Docker Installation
wget -qO- https://get.docker.com
5. RustDesk Server Deployment (Docker Compose)
Created directory:
Bashmkdir -p ~/rustdesk/data && cd ~/rustdesk
Used this compose.yml:
YAMLservices:
hbbs:
container_name: hbbs
image: rustdesk/rustdesk-server:latest
command: hbbs -r YOUR_SERVER_IP:21117
volumes:
- ./data:/root
network_mode: "host"
restart: unless-stopped
hbbr:
container_name: hbbr
image: rustdesk/rustdesk-server:latest
command: hbbr
volumes:
./data:/root
network_mode: "host"
restart: unless-stopped
Started the services:
Bashdocker compose up -d
6. Firewall Configuration (UFW)
Bashapt install ufw -y
ufw allow OpenSSH
ufw allow 21114:21119/tcp
ufw allow 21116/udp
ufw --force enable
7. Verification & Key Retrieval
Checked logs: docker logs hbbs and docker logs hbbr
Retrieved the server public key: cat ~/rustdesk/data/id_ed25519.pub(Key: hehexd)
8. Client Configuration
On every client device:
Download RustDesk from rustdesk.com
Go to Settings → ID/Relay Server
Set:
ID Server: nope*nope*nope*nope
Key: hehexd
Tested successful remote connections.
9. Useful Maintenance Commands
Restart: cd ~/rustdesk && docker compose restart
Update: docker compose pull && docker compose up -d
Backup: tar -czf rustdesk-backup-$(date +%Y%m%d).tar.gz ~/rustdesk/data
Logs: docker logs -f hbbs
Final Result
A fully functional, secure, self-hosted RustDesk instance running on a low-cost Vultr VPS. Direct connections work when possible, with automatic fallback to the hosted relay. Perfect for light IT work, remote troubleshooting, and personal use.
Misc. Stuff
Desktop Setup
I recently upgraded my desktop rig from an aging GTX 1080 to a beastly NVIDIA GeForce RTX 5070 Ti (TUF edition).
What makes this setup truly unique is that the heart of the system is a compact mini PC connected to the GPU via
a PCIe dock delivering massive performance in a surprisingly small footprint.
Current Desktop Specs:
- Operating system: Microsoft Windows 11 Pro, Version 10.0.26200
- CPU: Intel(R) Core(TM) Ultra 9 285H
- RAM: 96.0 GB
- Storage (2): SSD - 931.5 GB,SSD - 931.5 GB
- GPU: NVIDIA GeForce RTX 5070 Ti
- CUDA cores: 8960
- Graphics clock: 2588 MHz
- Memory data rate: 28.00 Gbps
- Memory interface: 256-bit
- Memory bandwidth: 896.064 GB/s
- Total available graphics memory: 65245 MB
- Dedicated video memory: 16303 MB GDDR7
- Bus: PCI Express x8
- Display (1): Samsung Odyssey G93SC
- Resolution: 5120 x 1440
- Refresh rate: 240 Hz
- Desktop color depth: Highest (32-bit)
Paired with the setup is my all-time favorite keyboard: the Happy Hacking Keyboard (HHKB) Professional Hybrid Type S topre switches, compact layout, pure bliss.
For the mouse, I run the Zowie EC2-DW 4K wireless, which delivers incredibly satisfying clicky feedback and precision. Audio duties are handled by the Audeze
Maxwell headset whcih offer phenomenal sound and comfort for long sessions. And last but not least the Samsung Odysey G9 OLED driving the front end of things.
Laptop Setup
For daily work in networking, VoIP, and cybersecurity, I'm running Linux on my go to machine whcih is a System76 laptop running Pop!_OS,
offering a rock-solid, encrypted environment that's fast and distraction free.
Laptop Specs:
- Operating System: Pop!_OS 22.04 LTS with full disk-encryption
- Display: 14" Matte Full HD+
- Processor: 5.1 GHz Intel Core Ultra 7 255H (16 Cores)
- Networking: WiFi 7 + Bluetooth 5.4
- Memory: 32 GB DDR5 5600 MHz (2x16)
- OS Drive: 1 TB PCIe4 M.2 SSD
|