ozcanpng
was here
Penetration tester, CTF player and security researcher. Writing about what I find.
~/web-app-pentesting
Authenticated & unauthenticated web application assessments across modern stacks.
~/red-teaming
Adversary emulation, initial access, lateral movement and post-exploitation.
~/android-sec
Android app reversing, runtime instrumentation and API abuse.
~/cti
Cyber threat intelligence - tracking actors, IOCs and campaign infrastructure.
~/iot-hacking
Reversing router and embedded-device firmware, analyzing binaries and researching hardware-assisted attack surfaces.
~/disclaimer
you don't need to know all of them :)
CTF & Reference Letter
Competition results and professional recognition.
HackTheBox Cyber Apocalypse CTF 2026 - Team BuBayrak
Finished 48th worldwide and 1st in Türkiye, solving 136 flags in a competition with 6,744 teams and more than 10,000 participants.
RACONF'26 CTF
Individual CTF competition held at the RACONF'26 conference. Third place finish among 49 competitors.
BEING-WiSE CTF 2025 - Team DELiLER
International online CTF. First place in the team category against competitors from across the global cybersecurity community.
Türkiye Siber Vatan Bootcamp CTF 2025 - Solo
On-site CTF exam - the final selection stage for the bootcamp, following a multi-stage online elimination among 6,000+ candidates.
Reference Letter - Penetration Testing & Vulnerability Assessment
As part of a penetration test I conducted at Erzurum Technical University, I analyzed security vulnerabilities and reported them to the institution. In recognition of my contribution, I was awarded a letter of reference.
CVEs
Published vulnerability research and technical write-ups.
CVE-2026-76071 - Netis NC63 ipFilterList Stack Buffer Overflow
An unauthenticated pre-auth stack overflow caused by unbounded %[^,]
scansets in the skk_set.cgi ipFilterList handler.
CVE-2026-76070 - Netis NC63 login.cgi Stack Buffer Overflow
An unauthenticated pre-auth overflow where attacker-controlled Base64 output is decoded into a fixed-size stack buffer without decoded-length enforcement, leading to remote code execution.
CVE-2026-73673 - Netis NC63 Firmware Update Vulnerability
An unauthenticated firmware update path that accepts structurally valid images without cryptographic firmware authenticity verification.
CVE-2026-76071: Unauthenticated Pre-Auth Stack Buffer Overflow via sscanf %[^,] in skk_set.cgi ipFilterList Handler in Netis NC63
A pre-authentication Netis NC63 stack overflow caused by unbounded sscanf scansets in the skk_set.cgi ipFilterList destHost parser.
CVE-2026-76070: Unauthenticated Pre-Auth Stack Buffer Overflow via Base64-Decoded Password in Netis NC63 login.cgi Leading to RCE
A pre-authentication stack buffer overflow in the Netis NC63 login.cgi Base64 decode path, with saved return-address, PC, and guarded command-boundary control.
CVE-2026-73673: Netis NC63 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication
Netis NC63 V3.0.0.3327 unauthenticated firmware update with missing cryptographic firmware authentication.
CVE-2025-57819: FreePBX SQLi → RCE → Root
Unauthenticated SQL injection in FreePBX's endpoint module chains into root shell via cron job injection and incron privilege escalation.
Original Netis NC63 firmware research with a non-destructive PoC and evidence package.
Full-chain FreePBX PoC from unauthenticated SQL injection to RCE and root takeover.
Security training project built with Go and SQLite to demonstrate common web vulnerabilities.
Raspberry Pi Pico payloads and tooling inspired by USB Rubber Ducky workflows.
Proof of concept for an unauthenticated remote code execution vulnerability in MCPJam Inspector.
View all on GitHub →Özcan Ersan
Hello! I'm Özcan Ersan, a 4th-year Computer Engineering student actively training under the Siber Vatan program.
I enjoy studying how APT groups run their red team operations and reproducing those techniques in my own lab environment.