NEROTEK01
v1.0.0
init nerotek-core v1.0.0000%
click · tap · any key to skip
Full-stack developer · 5+ years

Nerotek01

01 · first and last

I build, break, and harden software. My focus is Minecraft development, distributed systems, and offensive security.

5+
years
12+
languages
blocks placed
01Origin

Forged in anger. Sharpened by betrayal.

Nerotek01 wasn't born — it was carved out of a grudge. Five years ago I was a quiet kid building Minecraft plugins for communities that promised loyalty and paid in contempt. Servers I poured months into were stolen. Credit was erased. The people I trusted turned out to be the same people who left the backdoors open on purpose.

I stopped trusting. I started reading. Every leaked source, every deobfuscated jar, every CVE writeup, every reversing challenge I could find. The anger didn't go away — it became a craft. I learned to read code the way an attacker reads it: not for what it does, but for what it lets you do. Once you see systems that way, you can't unsee it.

Now I build things that don't break, and I break things that other people build. The two halves feed each other. Every plugin I write is a plugin I know how to exploit. Every audit I run teaches me a new way to defend the next one. The grudge never settled — I just pointed it at the work. Build it like you'll break it. Break it like you built it.

Build
systems · APIs · plugins
Harden
audits · CSP · hardening
Break
pentest · exploit dev
02Arsenal

What I carry into the work.

Not exhaustive — just the tools I reach for first. I learn from source code and writeups, not tutorials. The offensive side is where I spend most of my curiosity now.

Minecraft Dev

Core

Plugins, server arch, anti-cheat, performance.

proficiency95%

TypeScript / JS

Language

Node, React, Next.js, Bun, runtime internals.

proficiency92%

Java / Kotlin

Language

JVM internals, bytecode, Paper/Bukkit APIs.

proficiency88%

Reverse Engineering

Offensive

Ghidra, IDA, javap, deobfuscation, RCE chains.

proficiency86%

Exploit Development

Offensive

Memory corruption, ROP, JVM deserialization, PoCs.

proficiency82%

Pentest / Audit

Offensive

Black-box, white-box, threat modeling, recon.

proficiency80%

Packet & Protocol

Offensive

Netty pipelines, MITM, custom protocol fuzzing.

proficiency84%

SQL · NoSQL

Data

Schema design, injection, query optimization.

proficiency85%

Systems Design

Infra

Sharded backends, 1k+ concurrent, failover.

proficiency87%

Distributed Sys

Infra

Proxy meshes, state replication, consensus.

proficiency82%

Realtime / WS

Infra

Socket.io, Netty, custom binary protocols.

proficiency84%

Bash · Rust · Go

Language

CLI tools, automation, low-level utilities.

proficiency78%
03Minecraft

Where the grudge started.

This is where I learned that code is never just code — it's a contract, and contracts get broken. I started young, building plugins for small servers, and watched those servers get stolen, leaked, hijacked. The lesson stuck: every system you build will eventually be attacked by someone who understands it better than you do. So I became that someone.

Plugin Development

Bukkit · Spigot · Paper · Folia — custom mechanics, anti-cheat, performance tuning.

Server Architecture

BungeeCord · Velocity · multi-proxy sharding for 1k+ concurrent players.

Realtime Systems

Netty pipelines, packet-level optimizations, custom protocol bridges.

World Engines

Chunk streaming, custom generators, anvil-level data manipulation.

01

Craft

Every plugin is built like a hand tool — with intent, with purpose, with character.

02

Scale

From 10 to 10,000 concurrent players — the difference is architecture, not code.

03

Secure

Every input is a potential threat. Every packet might be an attack. Always.

live · mc.hypeland.org
04Offensive

The other half of the work.

Breaking things is the fastest way to learn how they actually work. I spend as much time reading other people's code with hostile intent as I spend writing my own. Not to cause harm — to understand. The PoCs stay private. The lessons go into everything I build.

01

Reverse Engineering

Static and dynamic analysis of JVM bytecode, native binaries, and obfuscated plugins. Ghidra, IDA, javap, custom deobfuscation pipelines.

GhidraIDAjavapASM
02

Exploit Development

Memory corruption, ROP chains, JVM deserialization gadgets, logic flaws. Every PoC is a lesson; every lesson is a defense.

ROPdeserPoCfuzzing
03

Protocol & Packet

Custom Netty pipelines, MITM on game protocols, packet-level fuzzing, replay attacks, state-machine breaking.

NettyMITMfuzzreplay
04

Audit & Hardening

Black-box and white-box audits, threat modeling, CSP design, sandboxing. The flip side of breaking — making it not break.

auditCSPsandboxthreat model

every system I can break, I can also defend. the rest is just a question of time.

05Optimize

Slow code is a bug.

Most performance problems are inherited, not designed. I trace them down to the allocation, the syscall, the lock contention — then I kill them. Real numbers, real flame graphs, no cargo-cult optimization.

p99 < 50ms

Profiling First

Async-profiler, async-profiler, async-profiler. Never optimize without a flame graph in hand.

0 GC pauses

Memory Discipline

Object pools, allocation hotspots, GC tuning. A server that GCs less serves more.

10k pkt/s

Packet-Level

Custom Netty pipelines, zero-copy, batched flushes. The kernel is not your friend.

5x throughput

Measure, Don't Guess

JMH, jmh, jmh. Microbenchmarks lie less than intuition. Always cold + warm runs.

if you can't measure it, you can't make it faster.

06Connect

If you have something worth breaking.

I take select work — Minecraft architecture, security audits, exploit development for authorized targets. If you're building something that needs a build-break-harden mindset, I'm listening.

Available for select projects
Copy ID