Posts on cybersecurity
43 posts on cybersecurity. Notes from public sources and my own test lab.
The Silent Danger Hidden Between JSON Packets: API Logic Errors and Mass Assignment
In the modern web, the real danger isn't always a complex script; sometimes it's just an extra field in a JSON packet. Let's explore Mass Assignment and how to secure your APIs.
Whose Shoulders Are You Standing On? The Supply Chain Nightmare
You trust your code, but do you trust your dependencies? A deep dive into why shifting left also means looking at the libraries you invite into your house.
Trojan Horses in Our Pockets: Mobile App Security Blunders We Swear We'd Never Make
From mistaking public API keys for crown jewels to the 'allowBackup' trap, let's dive into some common mobile security pitfalls I've seen in the field—and how to avoid them.
You’ve Got a Shell, Now What? Navigating the Labyrinths of Internal Networks Silently
Initial access is just the beginning. The real game starts with staying under the radar, moving laterally, and understanding the defensive gaps that let attackers roam free.
Smart Bulbs, Dumb Passwords: The IoT Backdoor Reality
A deep dive into why IoT devices remain the ultimate 'pivot points' for attackers and how a $20 smart plug can compromise an entire corporate network.
Görünmeyeni Avlamak: Zero-Day Efsanesi ve Otomatize Taramaların Sefaleti
Otomatik tarama araçlarının sahte güvenine kapılanlara kötü bir haberim var: Zero-day'ler o raporlarda gözükmez. Bu yazıda, bilinmeyenin peşine düşüyoruz.
When Your Safety Net Becomes a Trap: How Library Dependencies Betray You
Ever wonder who actually wrote the 100,000 lines of code running in your 'small' microservice? Let's talk about the fragility of the software supply chain and how Red Teamers exploit it.
Making Sense of the Data Heap: Moving to Actionable Threat Intel
Why hoarding threat feeds is useless and how we can climb the Pyramid of Pain using behavioral detection and Sigma rules instead of just chasing IPs.
Before You Double-Click That File: Becoming a 'Plague' Hunter in the Lab
A deep dive into the fundamentals of malware analysis, featuring personal stories from the field and practical tips on static and dynamic analysis without compromising your host machine.
It's Not Just About the Patch: The Invisible Side of Vulnerabilities and Our 'Margin of Error'
A deep dive into why relying solely on automated scanners is a trap, the reality of business logic flaws, and a walk down memory lane regarding a production incident.
The Trojan Horse Inside the Fortress: Why Network Segmentation is Always Misunderstood
A deep dive into why 'flat networks' are a Red Teamer's dream and how proper segmentation is more than just VLANs—featuring a cautionary tale from my early days in the field.
From Cat and Mouse Games to Collective Intelligence: Why Purple Team?
A deep dive into why breaking the silos between Red and Blue teams is crucial for modern cybersecurity, featuring a technical look at Kerberoasting detection gaps.