Welcome to Nerdweb. Let's hax, learn & share pews!

Cybersecurity Practitioner · Penetration Tester

prof_pic.jpg

Lagos, Nigeria

Hey, I’m Chuks Clinton (Nerdy007) — a cybersecurity practitioner with a passion for breaking things ethically and understanding how systems fail so they can be built better.

My focus is web application penetration testing. I spend my time hunting vulnerabilities, chaining exploits, and documenting findings. I practice through hands-on CTF labs where I’ve worked through real-world attack scenarios including:

  • SQL Injection — boolean-based and time-based blind, manual exploitation and automated with custom Python scripts
  • Broken Object Level Authorization (IDOR/BOLA) — chaining JWT manipulation, host-header routing, and credential extraction across multi-service architectures
  • XML External Entity (XXE) — reflected and blind out-of-band exfiltration using PHP wrappers
  • File Upload Bypasses — polyglot files, magic byte validation bypass, extension filter evasion leading to RCE
  • Path Traversal — PHP filter bypass and wrapper abuse
  • Stored XSS + CSP Bypass — JSONP callback injection chained with cookie theft via admin bot

I work with Burp Suite, sqlmap, ffuf, and write custom exploitation scripts in Python when off-the-shelf tools don’t cut it.

I’m currently preparing for professional certifications and actively building my skills through structured lab environments and CTF competitions.

When I’m not breaking web apps I’m writing about what I’ve learned — check out my blog posts for writeups and notes from the field.

“The best way to understand how to defend systems is to learn how they’re attacked.”