August 2026 State of the Union
Kept ya waiting, huh?#
Howdy everyone, it’s Justis “Jaym0” Murray back with another riveting blog post! It’s been a little over 9 months since I’ve created a new post. I apologize for that; life has been busy with what I’m going to be highlighting here in a bit. Thank you for your patience and I hope you’re doing well, dear reader :D
3rd year of undergrad done, onto the final one.#
A good chunk of my time has been dedicated to my undergrad education. For a quick reminder. I am now a 4th-year university student at the University of Arizona following the Cyber Operations (Engineering Specific) track. From January 2026 -> July 2026, I spent most of my time legitimately on classwork. Some of the classes to highlight:
- CYBV 400: Active Cyber Defense
- CYBV 470: System Programming (C-heavy course)
- NETV 379: Intro to Cloud Computing
- BASV300: Intro to Discrete Mathematics for Security Professionals
There are 4 other classes I took, but the 4 listed are the ones I spent the most time in and took the most interest in. Just don’t ask me anything regarding the Discrete Math class. I couldn’t tell ya anything, as I took poor to no notes. But, I have a dope book to always go back too. (For the math nerds, the book is “Book of Proof” by Richard Hammack)
Intro to Cloud Computing was a very fun class. The environment took place in an AWS VPC that students ran on a free plan. I did have a cloud course in my associate’s program (sorry Mr.Chenoweth). But it wasn’t as in-depth as the one I took at the U of A. Most of the classwork consisted of setting up WordPress sites, securing WordPress sites, setting up GuardDuty, working with firewall rules for a VPS, and many more smaller things. As some of you AWS heads know, it gets in-depth fast since AWS has a unique name for everything. But this class gave me my first “I get it now” thoughts regarding the cloud.
Systems Programming was VERY awesome; I wish I had saved my projects from this one. This entire course consisted of writing functional programs that all did something relatively simple in C. These little execrises where used to learn the ins and outs of C. For example, functions, pointers, arrays, the dreaded preprocessor, creating and using custom libraries, linked lists, FIFO, C debugging, and more. For this class, I picked up the ANSI C written by Brian W. Kernighan and Dennis M. Richie. I like picking up the physical textbooks for these classes as they always act as a quick reference in case I need to do something real fast.
Finally, I have my Active Cyber Defenses class. This class mostly focused on defensive work (name literal) It mostly went through IDS/IPS systems such as Suricata, EDR systems such as Wazuh, Threat Hunting (TI) platforms such as OpenCTI, Threat modeling frameworks, and many other things.
That’s pretty neat. Did you have fun?#
Honestly, I thought a lot of the class content was fun. But at the time, I had a lot going on and put too much pressure on myself. It’s cool and all to get A’s in classes, but is it even productive when you force knowledge that you then later forget because you only needed it for that moment?
Loneliness, burnout, and sadness.#
Now that my 3rd year has passed, I want to highlight something very important to me that isn’t very discussed amongst sec folk, especially ones who’re trying to be the next gen.
During this time, I was unbearably tired; my Spring 2026 semester consisted of 6 classes in total (18 credits or so). This led to a lot of classwork. In addition, I was (and still am!) working for the U of A Information Security Office as a work-study analyst roughly 20-25 hours a week. All my time was focused on security and learning security.
For most, that sounds like a dream, and I’m damn lucky to be living it debt-free due to working my ass off for scholarships. But somewhere along the way, I forgot that I am human. Humans need rest just like any organic organism. Additionally, I was being unreasonably hostile to myself. I chose the word “hostile” as being “mean” or “harsh” on myself doesn’t suffice for how I was treating myself at the time. Nothing to the point of self-harm, but to the point where my family and friends (the ones I’d talk to online) would notice and comment on it.
I’d isolate myself for days at a time, and I mean isolate. Rarely leaving my room to eat, let alone bathe or do anything else. My life at this point was quite literally:
- Wake up
- Get in my chair for work
- Turn 180 degrees in my chair for school
- Go to bed
That’s it. For a solid 6 or so months, it was this.
I started to feel extremely conflicted with my educational journey and began to doubt myself about my future. Of course, I’m not ignorant of the fact of the current job hellscape and economy we’re in. But, seeing my 10th LinkedIn post of fully capibile senior cyber folks begging for a job or going homeless really makes you think about what the fuck you’re walking into.
Thankfully, in the end, I had the wherewithal to not let that distract me from what I want to do and who I want to become, not only as a person but as a professional.
Around the end of my semesters, I found a little bit of time to pick up my passion project again. My beloved (and sometimes hated) homelab.
My Homelab and the hell of setting up a fully virtualized OPNSENSE setup#
As some of you know, my homelab consists of a Dell R720 and a T320. Both of these are jam-packed with DDR3 (thank god I bought some before that Sam Altman fella got to em), giving me a good amount of horsies to work with in my homelab.
One of the biggest hurdles I faced for a long time was setting up OPNsense in a non-double-NAT’d state. For the folks who don’t know what double NATting is, it’s when two routers that’re performing Network Address Translation create their own individual private networks. This is a common headache and one that I really wanted to get around. Additionally, I wanted complete control of my network from my end. A simple double NAT and calling it a day was NOT going to suffice.
Because I’m a cheap guy and didn’t want to buy more hardware, I decided to set up a VM inside of Proxmox running OPNSENSE. The initial setup isn’t too hard; you add a WAN interface, then you add a LAN interface. You have the option to add more interfaces or to create VLANS. But for the initial setup. All I needed was the two.
oh no oh no oh no#
Needless to say, I redid my initial config like 5 times. I have this thing when learning a new technology where I just throw stuff at a wall and hope it works. Needless to say, I stopped doing that after I got OPNSENSE set up and running (spoiler lol).
Some of the issues that I faced are the following:
Having 3 interfaces ALL NAMED DIFFERENTLY WITH DIFFERENT NUMERICAL VALUES TO SHOW WHICH ONE IS WHICH. One in IDRAC, one in Proxmox, and one in OPNsense. Thankfully, good ole writing down which interfaces were actually what across the 3 areas fixed this
My ISP being a meanie-head and doesn’t have proper info on bridge mode. This was fixed by setting my WAN interface to DHCP. From there, it just picked it up. Would be nice for the COX customer support folks to just tell me that, but nope.
Losing iDRAC access midway through as I disabled the subnet it was on. Thankfully, I just walked to the other side of my room and changed the iDRAC access IP physically rather than wiring in.
Losing internet access. This one was just DNS LOL, guess how long it took me to figure that one out (hint, I’ll never tell you!)
Setting up firewall rules and locking myself out even with the anti-lockout in place. This one also was a simple fix; I just wired into my server directly and logged into Proxmox. Needless to say i’m not doing a block any any rule and deleting the lockout rule EVER again.
Setting up L2 port tags on my switch. Thankfully, I didn’t need to tag ALL my ports. But setting my trunked port up was a little bit of a pain. TP-LINKS UI for 802.1Q-based VLAN setup is a bit confusing if you aren’t using a walkthrough.
Thankfully, it wasn’t all painful. The fun parts were breaking into VLAN isolation and figuring out how that works. Creating an alias for RFC1918 (which is the req for comment for all private allocation subnet types) and setting a blanket rule to block communication from each private -> private VLAN on certain VLANs is fun. (This will be referenced in my future malware lab writeup! Maybe even my AD pentesting writeups.)
Cool homelab stuffs#
Past all of that, I did the usual fun homelab stuff of setting up storage stuffs, media stuffs, streaming stuffs, and privacy stuffs.
One cool project was setting up Tailscale for DEFCON 34. For those who don’t know, Tailscale is an overlay network that sits above your main network. You connect a couple of machines you want to Tailscale, and blamo, you’re done. But I didn’t like that setup. I wanted to prepare a Tailscale instance for hacker summer camp, also known as DEFCON.
For this, I had two VM’s running inside of Proxmox. I had a Kali image (so haxor of you, Jaym0) and an Ubuntu instance acting as my exit node.
You might be thinking, Justis “Jaym0” Murray, why didn’t you set up your exit node on a VPS somewhere?
My answer? I already pay for Mullvad occasionally for VPN stuff; why not use the resources that I have to point my Ubuntu exit node to Mullvad and have my traffic route out through Mullvad? Not only that, what if I do funny stuff on my Kali instance? Do I really want to throw my public home IP around at DEFCON? NO!
This, my amigos and amigas, is a concept called “Split Tunneling,” where some data goes directly to the internet using a VPN and letting other stuff act as if there isn’t a VPN in place (for this instance, allowing me to still interact with my homelab stuff while allowing me to send stuff out to the internet, masking my public address)
In Tailscale itself, in this instance I set the Ubuntu box to act as an exit node. Meaning, any traffic while connected to Tailscale is routed out through that Ubuntu box.
The REAL issues begin with Mullvad. First and foremost, Mullvad isn’t aware of Tailscale’s CGNAT range by default (which is 100.64.0.0/10). The fix here was adding an nftables forward req which then explicitly accepted the CGNAT range.
Using TCPDUMP, I then found out that Mullvad was just eating the tailscale0 traffic and disappearing. The fix to this was explicitly telling Mullvad that this IP table (52) by doing:
sudo ip rule add to 100.64.0.0/10 lookup 52 priority 100
Then to made it persistent via systemd that just auto added that previous line upon boot (which, thank goodness, I did, the power went out while I was gone.) Now that I explained my DEFCON setup, its time for…
DEFCON 34, what a great time#
Funnily enough, this was not my first DEFCON. This was my second. My first DEFCON was DEFCON 31. This is where I met my ride or die buddies at. At DEFCON 31, I walked in as a NOOB, met some awesome people (who’re probably reading this post! Love ya Obi, Justus, S0lidStat3, Neko. Without y’all, DEFCON 31 and 34 wouldn’t have been as fun.) I had to skip other DEFCONS as I simply can’t afford the ticket price.
DEFCON 34 I was initially planning on skipping as well, only due to not having enough money to justify the price and not enough money for lodging. This is where a friend of mine, Stoner (who works with the Red Team Alliance) messaged me. For context, I brought him to his first-ever con, which was CACTUSCON. He remembered that and thanked me uberly for bringing him to that event. (shoutout to you Stoner, I don’t give ya enough credit where it’s due. Additionally you can find his youtube channel here: https://youtube.com/@stoner.n.friends?si=kZaF3kWLU04LOwYz)
Anywho, Stoner gave me an awesome proposition. “We need volunteers for DC34 for the Red Team Tools Booth; if you volunteer, we can get you a ticket, and you can stay at my place.”
My reaction: HELL YEAH!
I booked my ticket, aligned logistics, then flew out.
The first couple of days were a bit lackluster, as I arrived on the Monday before DEFCON while BLACKHAT was going on. I did the usual Vegas things, losing 130 bucks on blackjack (felt like Johnny Silverhand after the fact, iykyk), buying insanely overpriced beers, and dying in the 110 deg heat.
Additionally, I tried sneaking into Black Hat, which, as many of you can guess. Did not work lol. My social engineering skills and lack of equipment to sneak my way in really faltered. Shoutout to the security tho they were nice and understanding. Will I do it again? Wouldn’t you like to know ¯_(ツ)_/¯
But as time progressed, DEFCON got closer, which mean’t time to volunteer and time to have some fun. While volunteering, I met some really cool folks. Notably, Vertigo is into PCB and electronics design. He showed me some dope stuff he’s worked on and is extremely knowledgeable on PCB design. He also gave me some cool other tips for flying with media luggage and other things of that nature. Here is a link to his GitHub! https://github.com/KyleKulhanek
While volunteering, I got to learn about a ton of physical security tools and how to use them. Not only that, I got to meet a lot of dope people from the RTA along with the legendary Babak and Deviant.
Past the volunteering angle, DEFCON itself was really awesome within itself. During the con, I purposely didn’t have much of a plan on what talks or things I wanted to do. I wanted to be a floating person doing whatever looked fun in the moment. Thank goodness I did that as I ran into and talked to so many folks from all across the industry. A special shoutout goes to the T-MOBILE engineers that I met. Of course, they’d like to stay anonymous.
The most memorable part of DEFCON wasn’t any of the talks or activities I did (minus sitting in the Social Engineering Village for roughly 4 hours and watching the awesome phish execrises.) It was my friends I got to meet up with again and friends I’ve met IRL for the first time.
Obi, S0lidStat3, and Neko, of course, I met up with again, getting into our hijinks (1 AM trying to figure out how to spread trollware via the badges lol and getting pretty drunk, shoutout to Obi and our deep talks on life, S0lidStat3 for hitting me with the non-stop barrage of “yo momma” jokes, and Neko getting absolutely blasted at hacker jeporady.)
I mentioned meeting some friends IRL for the first time. This itself was the best experience of them all. I can’t dive into all of the stories, but getting invited to a hacker house where all my buddies where staying at and meeting them was legit a once in a life time experience I had the pleasure being apart of. Real quick, I want to give a shoutout to the following people I met IRL for the first time and who’ve really inspired me over my time talking with them.
- TipsyBacchus
- glidepixel
- :D
- shareware
- voltamage
- panda
- babybat
- zzgoon
- Shikata
- Nitro24
- chilaxan
- Weston
- Ser3n1ty
There are a handful of folks i’m forgetting. But, a special shoutout to the folks I forgot.
DEFCON wouldn’t be fun without the community that is there, and to be apart of such an awesome community has put so much determination into my heart. Especially coming out of a dark place as mentioned earlier.
From here forward#
Now that I’m home from DEFCON, writing this post a couple of weeks later. Beginning my final Fall semester of my undergrad. I want to highlight some things I plan on working on and some shenanigans I want to get into.
I’m going to finish this semester with flying colors like the rest, but with more emphasis on retention of information rather than short-term only.
Project-wise, I plan on building out a full isolated malware lab. Setting up a custom homebrewed honeypot (not homelab connected), a full AD pentesting lab (writeups on this soon!), and getting into some fun stuff with this Zebra ZXP Series 1 i’ve aquired. That by itself might warrant a writeup of its own. During this time, I also plan on mass applying as my undergrad experience is ending within the year. If you’re an employer and want to take a shot with me, please refer to the about me section for contact!
Final thoughts#
To my peers, remember it’s ok to get overwhelmed by life. The human experience is surpassing the challenges that we ourselves might run into. How we react to that is the vital and most important aspect of it all.
It’s easy to feel doom and gloom in the modern internet age; heck, how do you think these companies make money? Not by showing puppies, sunshine, and the newest cancer cure. They get money for the doom and gloom as it gets verbose reactions and clicks.
Just remember, at the end of the day. Believe. Believe. Believe. We’re all going to make it. There are so many people supporting you and your endeavors; EVERYONE wants you to succeed, no matter how critical or rude it may come across.
Just:

With love,
Justis “Jaym0” Murray