Security

Cybersecurity research, penetration testing, and vulnerability analysis

30
Posts

Android Pentest and Security Architecture: 2026 Field Manual and Source Code Analysis

A deep architectural analysis of Android application security: Binder IPC, Keystore/Keymint TEE integration, exported components, WebView exploits, JNI/NDK analysis, and Play Integrity mechanisms under 2026 standards.

A deep architectural analysis of Android application security: Binder IPC, Keystore/Keymint TEE integration, exported components, WebView exploits, JNI/NDK analysis, and Play Integrity mechanisms under 2026 standards.

14 min read
2,645 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Anti-Debugging for Noobs, Part 1: How a Program Notices the Debugger

First principles of anti-debugging on Linux: the one-tracer rule, ptrace self-trace, TracerPid in /proc, parent checks, timing gaps and 0xCC breakpoint scanning, plus how analysts answer each check.

First principles of anti-debugging on Linux: the one-tracer rule, ptrace self-trace, TracerPid in /proc, parent checks, timing gaps and 0xCC breakpoint scanning, plus how analysts answer each check.

15 min read
2,838 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Keylogging on Linux, Part 1: From Kernel Key Handling to the X Server

How a key press travels through the kernel keyboard driver, the input subsystem, evdev and /dev/input/event nodes, then through the X server input pipeline and XKB keymap, and where loggers hook in.

How a key press travels through the kernel keyboard driver, the input subsystem, evdev and /dev/input/event nodes, then through the X server input pipeline and XKB keymap, and where loggers hook in.

48 min read
9,418 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Security Architecture of Authorisation and Authentication UIs on the Linux Desktop

A deep architectural analysis of password prompts and permission dialogs on modern Linux: how Wayland, polkit, PAM, and xdg-desktop-portal isolate credentials and capabilities as of 2026.

A deep architectural analysis of password prompts and permission dialogs on modern Linux: how Wayland, polkit, PAM, and xdg-desktop-portal isolate credentials and capabilities as of 2026.

20 min read
3,830 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Prototype Pollution: Engine Internals, Node.js Gadget Chains, and Hardening Architecture

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

13 min read
2,587 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

regreSSHion Anatomy: Deep Dive into OpenSSH Pre-Auth RCE (CVE-2024-6387)

A deep architectural analysis of the OpenSSH pre-authentication remote code execution flaw (CVE-2024-6387): SIGALRM signal delivery, glibc ptmalloc reentrancy race conditions, heap grooming, and the 9.8p1 patch diff.

A deep architectural analysis of the OpenSSH pre-authentication remote code execution flaw (CVE-2024-6387): SIGALRM signal delivery, glibc ptmalloc reentrancy race conditions, heap grooming, and the 9.8p1 patch diff.

10 min read
1,806 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Wayland Compositor Security Architecture and Privileged Client Management

A deep architectural analysis of display server security: the input/output CIA triad, screencasting, input emulation (libei/EIS), session locking (ext-session-lock-v1), and sandbox isolation (security-context-v1) under 2026 standards.

A deep architectural analysis of display server security: the input/output CIA triad, screencasting, input emulation (libei/EIS), session locking (ext-session-lock-v1), and sandbox isolation (security-context-v1) under 2026 standards.

20 min read
3,868 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Modern Linux Binary Exploitation: Memory Layout, Compiler Mitigations, and Gadget Mechanics

An in-depth technical manual on x86_64 ELF memory corruption mechanics, compiler mitigations (Canaries, Full RELRO, PIE, Intel CET), sanitizer triage, and defensive binary engineering.

An in-depth technical manual on x86_64 ELF memory corruption mechanics, compiler mitigations (Canaries, Full RELRO, PIE, Intel CET), sanitizer triage, and defensive binary engineering.

16 min read
3,101 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Bypassing WAFs with Unicode Compatibility

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

10 min read
1,951 words
İS

ibrahimsql

Cybersecurity Engineer

Read More