Skip to content
Sedat Özdemir

Posts on red-team

54 posts on red-team. Notes from public sources and my own test lab.

WAF Won't Save You: The Illusion Behind Firewalls and the Harsh Truths

Think your 'premium' WAF makes your web application invincible? Think again. Let's talk about why defense starts in the code, not at the perimeter.

February 25, 2026·3 dk readapplication-securityred-teamsecure-coding

What Happens When You Change Just One Digit? The Silent Scream of IDOR

A deep dive into why authorization flaws like IDOR and business logic errors remain the 'invisible' threats that automated scanners often miss, told through real-world Red Team experience.

February 22, 2026·4 dk readcybersecurityidorred-team

Bending the Bars: The Art of Escaping the Container Cage

Forget the fancy slides. Let's talk about how simple misconfigurations like mounting docker.sock or abuse of capabilities turn your sandbox into paper.

February 14, 2026·5 dk readcloud-nativecontainer-securitydevsecops

Walking the Minefield: From Reverse Engineering to Runtime Manipulation

Mobile security is more than just decompiling APKs. Here is my journey from being a rookie to mastering the art of runtime manipulation with Frida.

February 11, 2026·5 dk readandroid-pentestfridamobile-security

SSH into the Human Terminal: Why the 'Trust' Protocol is Still Unpatched

Red teaming isn't just about zero-days. It's about debugging the 'Human OS' and bypassing danger perception through context and HTML Smuggling.

February 10, 2026·5 dk readcybersecurityhtml-smugglingpentesting

Your Screen Isn’t Just Black, Your Heart Just Stopped: The Reality of Ransomware

A raw look at how ransomware actually works, why speed is everything, and what attackers are really doing inside your network before the big "lockdown."

February 4, 2026·5 dk readcybersecurityincident-responsemalware-analysis