Project and writeups

tethux is the active project here. The rest of this page groups older school writeups about networking and security so they are easier to browse.

In development · network emulation · Go · Linux

tethux

An in-development network emulator intended to grow into a scalable GNS3-style replacement for programmable Ethernet topologies spanning containers, virtual machines, and physical hosts.

Current work covers Ethernet switching, Linux network namespaces, TAP interfaces, UDP tunnels, raw sockets, PCAP transports, container runtimes, reproducible NixOS test environments, and observability.

  • Ethernet
  • namespaces
  • PCAP
  • Docker · Podman · containerd

School writeups

Older networking and security exercises from my time at HTL Donaustadt, kept here as writeups rather than presented as current projects.

Distributed Anti Hardening assignment topologyDistributed systems securityAnti HardeningAn HTL assignment extended into a distributed application that we designed, deployed, deliberately weakened, attacked, and then hardened across a k3s cluster, a Go API, PostgreSQL, Docker Swarm secrets, JWT authentication, Tailscale, and Windows Server backups.The writeup covers authentication bypasses, CSP and XSS, secret management, database exposure, encrypted service connectivity, access control, backup design, and the tradeoffs between insecure and hardened deployments.