// security researcher
4th-year Computer Engineering student @ Erzurum Technical University

ozcanpng
was here

Penetration tester, CTF player and security researcher. Writing about what I find.

ozcan@pngwashere:~$
$catfocus_areas.md

~/web-app-pentesting

Authenticated & unauthenticated web application assessments across modern stacks.

~/red-teaming

Adversary emulation, initial access, lateral movement and post-exploitation.

~/android-sec

Android app reversing, runtime instrumentation and API abuse.

~/cti

Cyber threat intelligence - tracking actors, IOCs and campaign infrastructure.

~/iot-hacking

Reversing router and embedded-device firmware, analyzing binaries and researching hardware-assisted attack surfaces.

~/disclaimer

you don't need to know all of them :)

$ls~/honors

CTF & Reference Letter

Competition results and professional recognition.

HackTheBox Cyber Apocalypse CTF 2026 - Team BuBayrak

Finished 48th worldwide and 1st in Türkiye, solving 136 flags in a competition with 6,744 teams and more than 10,000 participants.

International · Team BuBayrak · 2026
#48

RACONF'26 CTF

Individual CTF competition held at the RACONF'26 conference. Third place finish among 49 competitors.

National · Apr 2026
#3

BEING-WiSE CTF 2025 - Team DELiLER

International online CTF. First place in the team category against competitors from across the global cybersecurity community.

International · Online · Nov 2025
#1

Türkiye Siber Vatan Bootcamp CTF 2025 - Solo

On-site CTF exam - the final selection stage for the bootcamp, following a multi-stage online elimination among 6,000+ candidates.

National · Alanya · Jul 2025
#5

Reference Letter - Penetration Testing & Vulnerability Assessment

As part of a penetration test I conducted at Erzurum Technical University, I analyzed security vulnerabilities and reported them to the institution. In recognition of my contribution, I was awarded a letter of reference.

National · Erzurum · Apr 2025
LoR

CVEs

Published vulnerability research and technical write-ups.

CVE-2026-76071 - Netis NC63 ipFilterList Stack Buffer Overflow

An unauthenticated pre-auth stack overflow caused by unbounded %[^,] scansets in the skk_set.cgi ipFilterList handler.

CWE-121·VulnCheck·Aug 2026
CVE

CVE-2026-76070 - Netis NC63 login.cgi Stack Buffer Overflow

An unauthenticated pre-auth overflow where attacker-controlled Base64 output is decoded into a fixed-size stack buffer without decoded-length enforcement, leading to remote code execution.

CWE-121·VulnCheck·Aug 2026
CVE

CVE-2026-73673 - Netis NC63 Firmware Update Vulnerability

An unauthenticated firmware update path that accepts structurally valid images without cryptographic firmware authenticity verification.

CWE-306 / CWE-494·VulnCheck·Aug 2026
CVE
$ls-la ~/blogs|head-n 4
$gitlog --oneline ~/projects
$whoami
Özcan Ersan

Özcan Ersan

Security Researcher · ozcanpng

Hello! I'm Özcan Ersan, a 4th-year Computer Engineering student actively training under the Siber Vatan program.

I enjoy studying how APT groups run their red team operations and reproducing those techniques in my own lab environment.

Web App Security IoT Security AD Security Firmware Reversing CVE Research
burp ghidra adaptix bloodhound frida python golang