All Blog Posts

Cybersecurity Articles

API authorization tests, Next.js security, and Burp lab notes. Technical posts with code and tests.

Search Articles

Android Pentest and Security Architecture: 2026 Field Manual and Source Code Analysis

A deep architectural analysis of Android application security: Binder IPC, Keystore/Keymint TEE integration, exported components, WebView exploits, JNI/NDK analysis, and Play Integrity mechanisms under 2026 standards.

A deep architectural analysis of Android application security: Binder IPC, Keystore/Keymint TEE integration, exported components, WebView exploits, JNI/NDK analysis, and Play Integrity mechanisms under 2026 standards.

14 min read
2,645 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Anti-Debugging for Noobs, Part 1: How a Program Notices the Debugger

First principles of anti-debugging on Linux: the one-tracer rule, ptrace self-trace, TracerPid in /proc, parent checks, timing gaps and 0xCC breakpoint scanning, plus how analysts answer each check.

First principles of anti-debugging on Linux: the one-tracer rule, ptrace self-trace, TracerPid in /proc, parent checks, timing gaps and 0xCC breakpoint scanning, plus how analysts answer each check.

15 min read
2,838 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Keylogging on Linux, Part 1: From Kernel Key Handling to the X Server

How a key press travels through the kernel keyboard driver, the input subsystem, evdev and /dev/input/event nodes, then through the X server input pipeline and XKB keymap, and where loggers hook in.

How a key press travels through the kernel keyboard driver, the input subsystem, evdev and /dev/input/event nodes, then through the X server input pipeline and XKB keymap, and where loggers hook in.

48 min read
9,418 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Security Architecture of Authorisation and Authentication UIs on the Linux Desktop

A deep architectural analysis of password prompts and permission dialogs on modern Linux: how Wayland, polkit, PAM, and xdg-desktop-portal isolate credentials and capabilities as of 2026.

A deep architectural analysis of password prompts and permission dialogs on modern Linux: how Wayland, polkit, PAM, and xdg-desktop-portal isolate credentials and capabilities as of 2026.

20 min read
3,830 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Prototype Pollution: Engine Internals, Node.js Gadget Chains, and Hardening Architecture

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

13 min read
2,587 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

regreSSHion Anatomy: Deep Dive into OpenSSH Pre-Auth RCE (CVE-2024-6387)

A deep architectural analysis of the OpenSSH pre-authentication remote code execution flaw (CVE-2024-6387): SIGALRM signal delivery, glibc ptmalloc reentrancy race conditions, heap grooming, and the 9.8p1 patch diff.

A deep architectural analysis of the OpenSSH pre-authentication remote code execution flaw (CVE-2024-6387): SIGALRM signal delivery, glibc ptmalloc reentrancy race conditions, heap grooming, and the 9.8p1 patch diff.

10 min read
1,806 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Wayland Compositor Security Architecture and Privileged Client Management

A deep architectural analysis of display server security: the input/output CIA triad, screencasting, input emulation (libei/EIS), session locking (ext-session-lock-v1), and sandbox isolation (security-context-v1) under 2026 standards.

A deep architectural analysis of display server security: the input/output CIA triad, screencasting, input emulation (libei/EIS), session locking (ext-session-lock-v1), and sandbox isolation (security-context-v1) under 2026 standards.

20 min read
3,868 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Modern Linux Binary Exploitation: Memory Layout, Compiler Mitigations, and Gadget Mechanics

An in-depth technical manual on x86_64 ELF memory corruption mechanics, compiler mitigations (Canaries, Full RELRO, PIE, Intel CET), sanitizer triage, and defensive binary engineering.

An in-depth technical manual on x86_64 ELF memory corruption mechanics, compiler mitigations (Canaries, Full RELRO, PIE, Intel CET), sanitizer triage, and defensive binary engineering.

16 min read
3,101 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Scanning the Access Matrix with Burp Intruder: A Repeatable Setup

Scanning the authorization matrix with two sessions and an ID list: recording a baseline, bulk requests with the attacker cookie, triage by length, single-request confirmation.

Scanning the authorization matrix with two sessions and an ID list: recording a baseline, bulk requests with the attacker cookie, triage by length, single-request confirmation.

16 min read
3,047 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Noindex Is Not Auth: Protecting Private Pages in Next.js

How to separate link-only pages from truly private content in Next.js App Router using robots metadata, middleware, server actions, and HttpOnly cookies.

How to separate link-only pages from truly private content in Next.js App Router using robots metadata, middleware, server actions, and HttpOnly cookies.

8 min read
1,589 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Bypassing WAFs with Unicode Compatibility

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

10 min read
1,951 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Follow new posts

No email newsletter; follow by RSS. Every new post lands here.