Guler Tech_
Offensive security research and field notes — web, mobile, API, network and cloud penetration testing. Written from real engagements and lab work, published when they're worth sharing.
Web Application
XSS, SQLi, SSRF, XXE, SSTI, IDOR, auth & session, request smuggling, business logic.
0 NOTES →Mobile Application
iOS & Android — static/dynamic analysis, Frida/Objection, SSL pinning & root/jailbreak bypass.
5 NOTES →API & GraphQL
Introspection, authz gaps, mass assignment, JWT attacks, rate-limit bypass.
0 NOTES →Network & AD
Active Directory, lateral movement, impacket, Kerberos, relay & coercion.
0 NOTES →Cloud
AWS / Azure / GCP misconfigurations, IAM escalation, metadata & storage.
0 NOTES →Privilege Escalation
Linux & Windows local privesc — sudo, LD_PRELOAD, library hijacking, service abuse.
0 NOTES →CVE & Writeups
CVE analysis, full attack-chain walkthroughs and lab/box writeups.
0 NOTES →-
2026-09-02
Memory Corruption in Android Apps: Where It Still Applies (MASTG-KNOW-0005)
ART protects managed code, not JNI/NDK. What to test in native libraries, why MASTG dropped its black-box tests, and how to scope this in a report.
-
2026-09-02
Third-Party Libraries in Android Apps (MASTG-KNOW-0004)
Identifying bundled dependencies in an APK, mapping them to known CVEs, and the licence exposure most reports leave out.
-
2026-09-02
Android App Signing: v1/v2/v3 Schemes and How to Verify Them (MASTG-KNOW-0003)
Signature schemes, debug-key detection, certificate validity requirements, and why a v1-only APK is a repackaging finding.
-
2026-09-02
FingerprintManager: Testing Legacy Android Fingerprint Auth (MASTG-KNOW-0002)
The deprecated pre-API 28 fingerprint API — what a correct implementation looks like, the five prerequisite checks, and how to spot the null-CryptoObject pattern.
-
2026-09-02
Android Biometric Authentication (MASTG-KNOW-0001)
How Android biometric auth actually works, why event-bound implementations are trivially bypassed, and how to test for Keystore-backed flows.