ozcanpng
was here
Penetration tester, CTF player and security researcher. Writing about what I find.
~/web-app-pentesting
Authenticated & unauthenticated web application assessments across modern stacks.
~/red-teaming
Adversary emulation, initial access, lateral movement and post-exploitation.
~/android-sec
Android app reversing, runtime instrumentation and API abuse.
~/cti
Cyber threat intelligence — tracking actors, IOCs and campaign infrastructure.
~/malware-dev
Offensive tooling, evasion research and custom implants for red team ops.
~/disclaimer
you don't need to know all of them :)
RACONF'26 CTF
Individual CTF competition held at the RACONF'26 conference. Third place finish among 49 competitors.
BEING-WiSE CTF 2025 — Team DELiLER
International online CTF. First place in the team category against competitors from across the global cybersecurity community.
Türkiye Siber Vatan Bootcamp CTF 2025 — Solo
On-site CTF exam — the final selection stage for the bootcamp, following a multi-stage online elimination among 6,000+ candidates.
Reference Letter — Penetration Testing & Vulnerability Assessment
As part of a penetration test I conducted at Erzurum Technical University, I analyzed security vulnerabilities and reported them to the institution. In recognition of my contribution, I was awarded a letter of reference.
CVE-2025-57819: FreePBX SQLi → RCE → Root
Unauthenticated SQL injection in FreePBX's endpoint module chains into root shell via cron job injection and incron privilege escalation.
RACONF'26 — CTF WRITE-UP
Write-ups for the 6 challenges I solved at RACONF'26: Aurora Industries (web), Nova Media Network (OSINT), kepler10b.apk (mobile), Orbital Communications (forensics), Helix Biocore (crypto), and Quante Systems (reverse).
CVE-2021-42013: Apache Path Traversal to RCE
Apache HTTP Server 2.4.49/2.4.50 path traversal and RCE via mod_cgi and URL-encoded path sequences.
Chrome Cookie Theft via Remote Debugging Port
How to extract session cookies from Chrome's remote debugging port to hijack authenticated sessions.
Security training project with Go and SQLite showcasing common web vulnerabilities.
Track Zara, Pull&Bear, Bershka products — get notified instantly when stock arrives.
Cargo tracking web application using Flask and MySQL.
Rubber Ducky-like device using Raspberry Pi Pico. Turkish translated source.
Payloads for Raspberry Pi Pico — everything the USB Rubber Ducky can do.
View all on GitHub →Özcan Ersan
Hello! I'm Özcan Ersan, a 4th-year Computer Engineering student actively training under the Siber Vatan program.
I enjoy studying how APT groups run their red team operations and reproducing those techniques in my own lab environment.