ozcanpng
was here
Penetration tester, CTF player and security researcher. Writing about what I find.
~/web-app-pentesting
Authenticated & unauthenticated web application assessments across modern stacks.
~/red-teaming
Adversary emulation, initial access, lateral movement and post-exploitation.
~/android-sec
Android app reversing, runtime instrumentation and API abuse.
~/cti
Cyber threat intelligence — tracking actors, IOCs and campaign infrastructure.
~/malware-dev
Offensive tooling, evasion research and custom implants for red team ops.
~/disclaimer
you don't need to know all of them :)
RACONF'26 CTF
Individual CTF competition held at the RACONF'26 conference. Third place finish among 49 competitors.
BEING-WiSE CTF 2025 — Team DELiLER
International online CTF. First place in the team category against competitors from across the global cybersecurity community.
Türkiye Siber Vatan Bootcamp CTF 2025 — Solo
On-site CTF exam — the final selection stage for the bootcamp, following a multi-stage online elimination among 6,000+ candidates.
Reference Letter — Penetration Testing & Vulnerability Assessment
As part of a penetration test I conducted at Erzurum Technical University, I analyzed security vulnerabilities and reported them to the institution. In recognition of my contribution, I was awarded a letter of reference.
RACONF'26 — CTF WRITE-UP
Write-ups for the 6 challenges I solved at RACONF'26: Aurora Industries (web), Nova Media Network (OSINT), kepler10b.apk (mobile), Orbital Communications (forensics), Helix Biocore (crypto), and Quante Systems (reverse).
CVE-2021-42013: Apache Path Traversal to RCE
Apache HTTP Server 2.4.49/2.4.50 path traversal and RCE via mod_cgi and URL-encoded path sequences.
Chrome Cookie Theft via Remote Debugging Port
How to extract session cookies from Chrome's remote debugging port to hijack authenticated sessions.
CVE-2025-32463: Sudo Local Privilege Escalation
Local privilege escalation via sudo's --chroot (-R) flag, abusing libnss loading to obtain a root shell.
Security training project with Go and SQLite showcasing common web vulnerabilities.
Track Zara, Pull&Bear, Bershka products — get notified instantly when stock arrives.
Cargo tracking web application using Flask and MySQL.
Rubber Ducky-like device using Raspberry Pi Pico. Turkish translated source.
Payloads for Raspberry Pi Pico — everything the USB Rubber Ducky can do.
View all on GitHub →Özcan Ersan
Hello! I'm Özcan Ersan, a 4th-year Computer Engineering student actively training under the Siber Vatan program.
I enjoy studying how APT groups run their red team operations and reproducing those techniques in my own lab environment.