Posts on red-team
53 posts on red-team. Notes from public sources and my own test lab.
Smart Devices or Trojan Horses in Your Home? IoT Security Needs More Than Just Shodan Tourism
Scanning for open IPs on Shodan isn't real IoT security. Join Payten's Red Team Lead, Sedat Özdemir, as he dives into firmware analysis, hardcoded backdoors, and why your smart toaster might be a bigger risk than you think.
The Silent Betrayal of the Cache: Web Cache Poisoning via Unkeyed Headers
Ever wonder how a performance booster like Varnish or Cloudflare could be turned against your users? Let's dive into the world of unkeyed headers and see how a simple X-Forwarded-Host can lead to a full-scale JavaScript injection.
The Silent Danger Hidden Between JSON Packets: API Logic Errors and Mass Assignment
In the modern web, the real danger isn't always a complex script; sometimes it's just an extra field in a JSON packet. Let's explore Mass Assignment and how to secure your APIs.
Whose Shoulders Are You Standing On? The Supply Chain Nightmare
You trust your code, but do you trust your dependencies? A deep dive into why shifting left also means looking at the libraries you invite into your house.
When the PLC Heartbeat Stops: Red Teaming Industrial Systems and the Harsh Reality
In the world of ICS/OT, a single hex code can be the difference between a smooth operation and physical disaster. Here's why security in the field is a completely different ballgame.
You’ve Got a Shell, Now What? Navigating the Labyrinths of Internal Networks Silently
Initial access is just the beginning. The real game starts with staying under the radar, moving laterally, and understanding the defensive gaps that let attackers roam free.
Smart Bulbs, Dumb Passwords: The IoT Backdoor Reality
A deep dive into why IoT devices remain the ultimate 'pivot points' for attackers and how a $20 smart plug can compromise an entire corporate network.
Patching the Human Factor: Vulnerability Scanning in Social Engineering
When a user clicks a malicious link, millions of dollars in security investment can turn into expensive paperweights. Let’s talk about how social engineering exploits 'wetware' and how we can defend against it.
Görünmeyeni Avlamak: Zero-Day Efsanesi ve Otomatize Taramaların Sefaleti
Otomatik tarama araçlarının sahte güvenine kapılanlara kötü bir haberim var: Zero-day'ler o raporlarda gözükmez. Bu yazıda, bilinmeyenin peşine düşüyoruz.
When Your Safety Net Becomes a Trap: How Library Dependencies Betray You
Ever wonder who actually wrote the 100,000 lines of code running in your 'small' microservice? Let's talk about the fragility of the software supply chain and how Red Teamers exploit it.
Who’s in the Sandbox? The Labyrinths of Malware Analysis and the Eternal Game of Cat and Mouse
Signature-based detection is a relic of the past. Today's malware is context-aware and built to evade analysis. Let's dive into how we dissect these sneaky payloads without losing our minds.
WAF Won't Save You: The Illusion Behind Firewalls and the Harsh Truths
Think your 'premium' WAF makes your web application invincible? Think again. Let's talk about why defense starts in the code, not at the perimeter.