<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
        xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
  
    <url>
      <loc>https://ibrahimsql.tr/posts/ai-cli-statusline-rehberi</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=AI%20CLI%20Ara%C3%A7lar%C4%B1nda%20Statusline%3A%20Tek%20Sat%C4%B1rda%20Model%2C%20Limit%20ve%20Context</image:loc>
        <image:title>AI CLI Araçlarında Statusline: Tek Satırda Model, Limit ve Context</image:title>
        <image:caption>Claude Code, agy, Codex ve Grok için statusline: hangi CLI hangi alanları verir, settings dosyaları, jq&apos;li payload çıkarma ve limit hesabı.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/android-pentesting-checklist-en</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Android%20Pentest%20and%20Security%20Architecture%3A%202026%20Field%20Manual%20and%20Source%20Code%20Analysis</image:loc>
        <image:title>Android Pentest and Security Architecture: 2026 Field Manual and Source Code Analysis</image:title>
        <image:caption>A deep architectural analysis of Android application security: Binder IPC, Keystore/Keymint TEE integration, exported components, WebView exploits, JNI/NDK analysis, and Play Integrity mechanisms under 2026 standards.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/android-pentesting-checklist-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Android%20Pentest%20ve%20G%C3%BCvenlik%20Mimarisi%3A%202026%20Saha%20Rehberi%20ve%20Kaynak%20Kod%20Analizi</image:loc>
        <image:title>Android Pentest ve Güvenlik Mimarisi: 2026 Saha Rehberi ve Kaynak Kod Analizi</image:title>
        <image:caption>Android güvenlik modeli, Binder IPC, Keystore/Keymint TEE entegrasyonu, exported bileşenler, WebView zafiyetleri, JNI/NDK analizi ve Play Integrity mekanizmalarının 2026 standartlarında derinlemesine teknik analizi.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/anti-debugging-noobs-en</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Anti-Debugging%20for%20Noobs%2C%20Part%201%3A%20How%20a%20Program%20Notices%20the%20Debugger</image:loc>
        <image:title>Anti-Debugging for Noobs, Part 1: How a Program Notices the Debugger</image:title>
        <image:caption>First principles of anti-debugging on Linux: the one-tracer rule, ptrace self-trace, TracerPid in /proc, parent checks, timing gaps and 0xCC breakpoint scanning, plus how analysts answer each check.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/anti-debugging-noobs-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Yeni%20Ba%C5%9Flayanlar%20i%C3%A7in%20Anti-Debugging%2C%20B%C3%B6l%C3%BCm%201%3A%20Program%20Debugger'%C4%B1%20Nas%C4%B1l%20Fark%20Eder</image:loc>
        <image:title>Yeni Başlayanlar için Anti-Debugging, Bölüm 1: Program Debugger&apos;ı Nasıl Fark Eder</image:title>
        <image:caption>Linux&apos;ta anti-debugging&apos;in temelleri: tek tracer kuralı, ptrace ile kendini izleme, /proc içinde TracerPid, ebeveyn kontrolü, zamanlama ölçümü ve 0xCC breakpoint taraması; artı analistlerin her kontrole verdiği yanıtlar.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/claude-code-co-authored-by-kaldirma</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Claude%20Code'da%20Co-Authored-By%20%C4%B0mzas%C4%B1n%C4%B1%20Kald%C4%B1rmak</image:loc>
        <image:title>Claude Code&apos;da Co-Authored-By İmzasını Kaldırmak</image:title>
        <image:caption>Claude Code&apos;un commit ve PR&apos;lara eklediği &apos;Co-Authored-By&apos; / &apos;Generated with&apos; satırlarını iki yolla kaldırmak: settings.json attribution ve commit-msg hook&apos;u.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/htb-cap-writeup</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=HackTheBox%20Cap%20Writeup</image:loc>
        <image:title>HackTheBox Cap Writeup</image:title>
        <image:caption>HTB Starting Point Cap makinesi: /data/0 IDOR ile başka kullanıcının PCAP&apos;i, FTP düz metin şifre, SSH şifre tekrarı ve cap_setuid ile root.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/htb-code-python-sandbox</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=HTB%20Code%3A%20Python%20Sandbox%20Escape%20ve%20Backy%20Sudo%20Bypass</image:loc>
        <image:title>HTB Code: Python Sandbox Escape ve Backy Sudo Bypass</image:title>
        <image:caption>Code makinesi: string-based blocklist bypass, object graph ile subprocess.Popen, bcrypt SQLite şifreleri ve backy sudo JSON path traversal ile root.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/htb-facts-idor-traversal</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=HTB%20Facts%3A%20Camaleon%20CMS%20IDOR%2C%20Path%20Traversal%20ve%20Sudo%20Facter</image:loc>
        <image:title>HTB Facts: Camaleon CMS IDOR, Path Traversal ve Sudo Facter</image:title>
        <image:caption>Facts makinesi: mass-assignment ile admin yapımı, Camaleon download_private_file path traversal, MinIO bucket&apos;ten SSH anahtarı ve --custom-dir facter ile root.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/htb-kobold-mcpjam-docker</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=HTB%20Kobold%3A%20MCPJam%20CVE-2026-23744%20ve%20Docker%20Grubu%20Root'u</image:loc>
        <image:title>HTB Kobold: MCPJam CVE-2026-23744 ve Docker Grubu Root&apos;u</image:title>
        <image:caption>Kobold makinesi: MCPJam Inspector /api/mcp/connect ile kimlik doğrulamasız RCE, docker grubu newgrp ile active ve bind mount ile root.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/ios-pentesting-checklist-en</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=iOS%20Pentesting%20Checklist%3A%20A%20Practical%20Verification%20Pass</image:loc>
        <image:title>iOS Pentesting Checklist: A Practical Verification Pass</image:title>
        <image:caption>Step-by-step iOS pentest flow: data storage, keychain, ATS, jailbreak detection, SSL pinning, Frida hooks and traffic inspection.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/ios-pentesting-checklist-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=iOS%20Pentest%20Checklist%3A%20Pratik%20Bir%20Do%C4%9Frulama%20Listesi</image:loc>
        <image:title>iOS Pentest Checklist: Pratik Bir Doğrulama Listesi</image:title>
        <image:caption>iOS uygulamalarını test ederken izlenecek adımlar: veri saklama, keychain, ATS, jailbreak tespiti, Frida ve ağ trafiği analizi.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/keylogging-linux-rehberi-en</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Keylogging%20on%20Linux%2C%20Part%201%3A%20From%20Kernel%20Key%20Handling%20to%20the%20X%20Server</image:loc>
        <image:title>Keylogging on Linux, Part 1: From Kernel Key Handling to the X Server</image:title>
        <image:caption>How a key press travels through the kernel keyboard driver, the input subsystem, evdev and /dev/input/event nodes, then through the X server input pipeline and XKB keymap, and where loggers hook in.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/keylogging-linux-rehberi-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Linux'ta%20Keylogging%2C%20B%C3%B6l%C3%BCm%201%3A%20%C3%87ekirdek%20Tu%C5%9F%20%C4%B0%C5%9Flemeden%20X%20Sunucusuna</image:loc>
        <image:title>Linux&apos;ta Keylogging, Bölüm 1: Çekirdek Tuş İşlemeden X Sunucusuna</image:title>
        <image:caption>Bir tuş vuruşunun çekirdek klavye sürücüsü, input altyapısı, evdev ve /dev/input/event düğümleri üzerinden X sunucusu girdi hattına ve XKB keymap&apos;e nasıl aktığını ve logger&apos;ların nereye bağlandığını inceliyoruz.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/linux-auth-ui-en</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Security%20Architecture%20of%20Authorisation%20and%20Authentication%20UIs%20on%20the%20Linux%20Desktop</image:loc>
        <image:title>Security Architecture of Authorisation and Authentication UIs on the Linux Desktop</image:title>
        <image:caption>A deep architectural analysis of password prompts and permission dialogs on modern Linux: how Wayland, polkit, PAM, and xdg-desktop-portal isolate credentials and capabilities as of 2026.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/linux-auth-ui-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Linux%20Masa%C3%BCst%C3%BCnde%20Yetkilendirme%20ve%20Kimlik%20Do%C4%9Frulama%20Aray%C3%BCzlerinin%20G%C3%BCvenlik%20Mimarisi</image:loc>
        <image:title>Linux Masaüstünde Yetkilendirme ve Kimlik Doğrulama Arayüzlerinin Güvenlik Mimarisi</image:title>
        <image:caption>Parola ve onay pencerelerinin güvenlik sınırları, Wayland, polkit, PAM ve xdg-desktop-portal mimarisinin yetkilendirme ve kimlik doğrulama süreçlerini nasıl yalıttığının 2026 standartlarındaki derin teknik analizi.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/modern-linux-ikili-somuru-ve-savunma-2026-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Modern%20Linux%20%C4%B0kili%20Bellek%20G%C3%BCvenli%C4%9Fi%3A%20ELF%20Mimarisi%2C%20Derleyici%20Savunmalar%C4%B1%20ve%20ROP%20Mekanikleri</image:loc>
        <image:title>Modern Linux İkili Bellek Güvenliği: ELF Mimarisi, Derleyici Savunmaları ve ROP Mekanikleri</image:title>
        <image:caption>x86_64 ELF bellek bozulma mekaniklerinin derin teknik analizi: Derleyici korumaları (Canaries, Full RELRO, PIE, Intel CET), AddressSanitizer ile hata triyajı, ROP teorisi ve ikili savunma mühendisliği.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/prototype-pollution-2025</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Prototype%20Pollution%3A%20Engine%20Internals%2C%20Node.js%20Gadget%20Chains%2C%20and%20Hardening%20Architecture</image:loc>
        <image:title>Prototype Pollution: Engine Internals, Node.js Gadget Chains, and Hardening Architecture</image:title>
        <image:caption>A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/prototype-pollution-2026-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Prototype%20Pollution%3A%20V8%20Motor%20%C4%B0%C3%A7%20Mekanikleri%2C%20Node.js%20Gadget%20Zincirleri%20ve%20Savunma%20Mimarisi</image:loc>
        <image:title>Prototype Pollution: V8 Motor İç Mekanikleri, Node.js Gadget Zincirleri ve Savunma Mimarisi</image:title>
        <image:caption>JavaScript prototip kirlenmesinin derin teknik analizi: V8 nesne modelleri, child_process ve şablon motorları üzerinden sunucu taraflı RCE zincirleri, istemci taraflı DOM vektörleri ve çalışma zamanı sertleştirme mimarileri.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/regresshion-cve-2024-6387-anatomisi</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=regreSSHion%20Anatomisi%3A%20CVE-2024-6387%20OpenSSH%20Pre-Auth%20RCE%20Derinlemesine%20Analizi</image:loc>
        <image:title>regreSSHion Anatomisi: CVE-2024-6387 OpenSSH Pre-Auth RCE Derinlemesine Analizi</image:title>
        <image:caption>OpenSSH sunucusunda kimlik doğrulama öncesi uzaktan kod yürütme zafiyeti (CVE-2024-6387): SIGALRM sinyali, glibc ptmalloc reentrancy yarışı, heap manipülasyonu ve 9.8p1 yama analizinin tam kaynak kod incelemesi.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/regresshion-cve-2024-6387-anatomy-en</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=regreSSHion%20Anatomy%3A%20Deep%20Dive%20into%20OpenSSH%20Pre-Auth%20RCE%20(CVE-2024-6387)</image:loc>
        <image:title>regreSSHion Anatomy: Deep Dive into OpenSSH Pre-Auth RCE (CVE-2024-6387)</image:title>
        <image:caption>A deep architectural analysis of the OpenSSH pre-authentication remote code execution flaw (CVE-2024-6387): SIGALRM signal delivery, glibc ptmalloc reentrancy race conditions, heap grooming, and the 9.8p1 patch diff.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/rust-ve-go-ikilisi</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Rust%20ve%20Go%3A%20%C4%B0kisi%20Birlikte%20Ne%20%C4%B0%C5%9Fe%20Yar%C4%B1yor</image:loc>
        <image:title>Rust ve Go: İkisi Birlikte Ne İşe Yarıyor</image:title>
        <image:caption>Rust ve Go&apos;yu neden birlikte kullanıyorum: performans-ve-güvenlik ekseni, concurrency, dağıtım farkı ve pratik iş yükü paylaşımı.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-burp-suite-lab-rehberi</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Burp%20Suite%20ile%20G%C3%BCvenli%20Lab%20%C3%87al%C4%B1%C5%9Fmas%C4%B1%3A%20Ba%C5%9Flang%C4%B1%C3%A7%20Rehberi</image:loc>
        <image:title>Burp Suite ile Güvenli Lab Çalışması: Başlangıç Rehberi</image:title>
        <image:caption>Burp Suite öğrenirken yasal, kontrollü ve tekrar edilebilir bir laboratuvar düzeni kurmak için temel yaklaşım.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-guvenli-nextjs-uygulama-yapisi</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=G%C3%BCvenli%20Next.js%20Uygulama%20Yap%C4%B1s%C4%B1%3A%20K%C3%BC%C3%A7%C3%BCk%20Ekipler%20%C4%B0%C3%A7in%20Pratik%20Kontrol%20Listesi</image:loc>
        <image:title>Güvenli Next.js Uygulama Yapısı: Küçük Ekipler İçin Pratik Kontrol Listesi</image:title>
        <image:caption>Next.js projelerinde rota, environment değişkenleri, form güvenliği ve SEO temellerini aynı anda sağlamlaştırmak için uygulanabilir bir rehber.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-siber-guvenlik-risk-modeli</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Siber%20G%C3%BCvenlikte%20Risk%20Modeli%3A%20%C3%96nce%20Neyi%20Korumal%C4%B1%3F</image:loc>
        <image:title>Siber Güvenlikte Risk Modeli: Önce Neyi Korumalı?</image:title>
        <image:caption>Siber güvenlik çalışmalarını rastgele araç denemelerinden çıkarıp ölçülebilir bir risk modeline bağlamak için pratik bir yaklaşım.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-terminal-ag-araclari-cheatsheet</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Terminal%20ve%20A%C4%9F%20Ara%C3%A7lar%C4%B1%20Cheatsheet%3A%20G%C3%BCnl%C3%BCk%20G%C3%BCvenlik%20%C4%B0%C5%9F%20Ak%C4%B1%C5%9F%C4%B1</image:loc>
        <image:title>Terminal ve Ağ Araçları Cheatsheet: Günlük Güvenlik İş Akışı</image:title>
        <image:caption>Günlük güvenlik çalışmalarında terminal, ağ gözlemi ve dokümantasyon için kullanılan temel araç kategorileri.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/wayland-compositor-en</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Wayland%20Compositor%20Security%20Architecture%20and%20Privileged%20Client%20Management</image:loc>
        <image:title>Wayland Compositor Security Architecture and Privileged Client Management</image:title>
        <image:caption>A deep architectural analysis of display server security: the input/output CIA triad, screencasting, input emulation (libei/EIS), session locking (ext-session-lock-v1), and sandbox isolation (security-context-v1) under 2026 standards.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/wayland-compositor-tr</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Wayland%20Kompozit%C3%B6r%20G%C3%BCvenlik%20Mimarisi%20ve%20Ayr%C4%B1cal%C4%B1kl%C4%B1%20%C4%B0stemci%20Y%C3%B6netimi</image:loc>
        <image:title>Wayland Kompozitör Güvenlik Mimarisi ve Ayrıcalıklı İstemci Yönetimi</image:title>
        <image:caption>Görüntü sunucusu güvenlik modeli, X11 ve Wayland mimarilerinin girdi-çıktı CIA üçgeni, screencast, girdi emülasyonu (libei/EIS), oturum kilitleme (ext-session-lock-v1) ve sandbox (security-context-v1) ayrıcalıklarının 2026 standartlarında teknik analizi.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/zero-day-exploit-development-tutorial</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Modern%20Linux%20Binary%20Exploitation%3A%20Memory%20Layout%2C%20Compiler%20Mitigations%2C%20and%20Gadget%20Mechanics</image:loc>
        <image:title>Modern Linux Binary Exploitation: Memory Layout, Compiler Mitigations, and Gadget Mechanics</image:title>
        <image:caption>An in-depth technical manual on x86_64 ELF memory corruption mechanics, compiler mitigations (Canaries, Full RELRO, PIE, Intel CET), sanitizer triage, and defensive binary engineering.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-bola-test-matrix-automation</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Turning%20the%20BOLA%20Test%20Matrix%20into%20Automation%3A%20Keeping%20Authorization%20as%20Endpoints%20Grow</image:loc>
        <image:title>Turning the BOLA Test Matrix into Automation: Keeping Authorization as Endpoints Grow</image:title>
        <image:caption>Encoding the IDOR test matrix as code: a fixed set of role and tenant combinations that every new endpoint must pass before merging.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-burp-intruder-access-matrix</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Scanning%20the%20Access%20Matrix%20with%20Burp%20Intruder%3A%20A%20Repeatable%20Setup</image:loc>
        <image:title>Scanning the Access Matrix with Burp Intruder: A Repeatable Setup</image:title>
        <image:caption>Scanning the authorization matrix with two sessions and an ID list: recording a baseline, bulk requests with the attacker cookie, triage by length, single-request confirmation.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-denied-request-alert-triage</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Turning%20Denied%20Requests%20into%20Alerts%3A%20From%20Log%20to%20Triage</image:loc>
        <image:title>Turning Denied Requests into Alerts: From Log to Triage</image:title>
        <image:caption>Deny logs become attack signal: alert record format, scanning patterns, threshold tuning, and a response card confirmed with a single request.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-nextjs-server-actions-authorization</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Authorization%20in%20Server%20Actions%3A%20Hiding%20the%20Button%20Is%20Not%20Protection</image:loc>
        <image:title>Authorization in Server Actions: Hiding the Button Is Not Protection</image:title>
        <image:caption>Next.js Server Actions are directly callable endpoints. A small policy pattern that moves the authorization check inside the action, plus how to test it.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-security-finding-scoring</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Scoring%20Security%20Findings%3A%20An%20Impact-by-Reachability%20Table</image:loc>
        <image:title>Scoring Security Findings: An Impact-by-Reachability Table</image:title>
        <image:caption>CVSS alone lacks context: a practical prioritization table crossing data class and tenant breach with ease of access.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-security-logging-design</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Security%20Logging%3A%20Who%20Accessed%20What%2C%20Decided%20How</image:loc>
        <image:title>Security Logging: Who Accessed What, Decided How</image:title>
        <image:caption>Authorization decisions must be observable: an event schema recording actor, tenant, object, action, and policy decision, plus how to test it.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-shadow-api-asset-inventory</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Shadow%20APIs%20and%20Asset%20Inventory%3A%20Mapping%20the%20Attack%20Surface</image:loc>
        <image:title>Shadow APIs and Asset Inventory: Mapping the Attack Surface</image:title>
        <image:caption>You cannot protect an endpoint you do not know: an inventory record format and coverage metric built from code, traffic, and DNS sources.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-bola-test-matrisi-otomasyon</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=BOLA%20Test%20Matrisini%20Otomasyona%20Ba%C4%9Flamak%3A%20Endpoint%20B%C3%BCy%C3%BCrken%20Yetki%20Nas%C4%B1l%20Korunur</image:loc>
        <image:title>BOLA Test Matrisini Otomasyona Bağlamak: Endpoint Büyürken Yetki Nasıl Korunur</image:title>
        <image:caption>IDOR test matrisini kod haline getirmek: rol ve tenant kombinasyonlarını otomatik test eden, yeni endpoint eklenirken çalışması zorunlu bir düzen.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-burp-intruder-yetki-taramasi</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Burp%20Intruder%20ile%20Yetki%20Matrisi%20Taramas%C4%B1%3A%20Tekrar%20Edilebilir%20Bir%20D%C3%BCzen</image:loc>
        <image:title>Burp Intruder ile Yetki Matrisi Taraması: Tekrar Edilebilir Bir Düzen</image:title>
        <image:caption>İki oturum ve bir ID listesiyle yetki matrisini taramak: baseline kaydı, saldırgan çereziyle toplu istek, uzunluk farkıyla ayıklama ve tek istekle doğrulama.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-golge-api-varlik-envanteri</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=G%C3%B6lge%20API%20ve%20Varl%C4%B1k%20Envanteri%3A%20Sald%C4%B1r%C4%B1%20Y%C3%BCzeyini%20Haritalamak</image:loc>
        <image:title>Gölge API ve Varlık Envanteri: Saldırı Yüzeyini Haritalamak</image:title>
        <image:caption>Bilmediğin endpoint&apos;i koruyamazsın: kod, trafik ve DNS kaynaklarından saldırı yüzeyini çıkaran envanter kayıt formatı ve kapsama metriği.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-guvenlik-bulgusu-skorlama</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=G%C3%BCvenlik%20Bulgular%C4%B1n%C4%B1%20Skorlamak%3A%20Etki%20ve%20Eri%C5%9Filebilirlik%20Tablosu</image:loc>
        <image:title>Güvenlik Bulgularını Skorlamak: Etki ve Erişilebilirlik Tablosu</image:title>
        <image:caption>CVSS tek başına bağlam vermez: veri sınıfı ve tenant aşımı ile erişim kolaylığını çaprazlayan pratik bir önceliklendirme tablosu.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-guvenlik-loglama-tasarimi</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=G%C3%BCvenlik%20Loglamas%C4%B1%3A%20Kim%2C%20Neye%2C%20Hangi%20Kararla%20Eri%C5%9Fti</image:loc>
        <image:title>Güvenlik Loglaması: Kim, Neye, Hangi Kararla Erişti</image:title>
        <image:caption>Yetki kararları gözlemlenebilir olmalı: aktör, tenant, obje, aksiyon ve policy kararını kaydeden olay şeması ve test yaklaşımı.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-nextjs-server-actions-yetkilendirme</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Server%20Actions'ta%20Yetkilendirme%3A%20Butonu%20Gizlemek%20Koruma%20De%C4%9Fildir</image:loc>
        <image:title>Server Actions&apos;ta Yetkilendirme: Butonu Gizlemek Koruma Değildir</image:title>
        <image:caption>Next.js Server Action&apos;lar doğrudan çağrılabilen endpoint&apos;lerdir. Yetki kontrolünü action&apos;ın içine taşıyan küçük bir policy deseni ve test yaklaşımı.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-reddedilen-istek-alarm-triyaj</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Reddedilen%20%C4%B0steklerden%20Alarm%20%C3%9Cretmek%3A%20Logdan%20Triyaja</image:loc>
        <image:title>Reddedilen İsteklerden Alarm Üretmek: Logdan Triyaja</image:title>
        <image:caption>Deny logları saldırı sinyaline dönüşür: alarm kaydı formatı, tarama desenleri, eşik ayarı ve tek istekle doğrulanan yanıt kartı.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/htb-support-writeup</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Support%3A%20.NET%20Binary'den%20DC'ye</image:loc>
        <image:title>Support: .NET Binary&apos;den DC&apos;ye</image:title>
        <image:caption>HackTheBox Support makinesinin çözüm zinciri: SMB&apos;de gizli binary, monodis ile XOR kimlik bilgisi, LDAP info alanı şifresi ve RBCD ile DC&apos;ye Administrator.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/htb-twomillion-writeup</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=TwoMillion%3A%20Davet%20Kodundan%20Root'a</image:loc>
        <image:title>TwoMillion: Davet Kodundan Root&apos;a</image:title>
        <image:caption>HackTheBox TwoMillion makinesinin nmap&apos;ten root&apos;a giden tam çözüm zinciri: obfuscated JS&apos;ten davet kodu, BOLA ile admin, command injection, .env şifre tekrarı ve CVE-2023-0386.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-api-access-control-test-plan</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Your%20API%20Has%20Roles.%20That%20Does%20Not%20Mean%20Access%20Control%20Works</image:loc>
        <image:title>Your API Has Roles. That Does Not Mean Access Control Works</image:title>
        <image:caption>A practical test plan for object-level authorization, tenant isolation, and API access control bugs that survive happy-path role checks.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/en-nextjs-private-pages-noindex-is-not-auth</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Noindex%20Is%20Not%20Auth%3A%20Protecting%20Private%20Pages%20in%20Next.js</image:loc>
        <image:title>Noindex Is Not Auth: Protecting Private Pages in Next.js</image:title>
        <image:caption>How to separate link-only pages from truly private content in Next.js App Router using robots metadata, middleware, server actions, and HttpOnly cookies.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-api-yetkilendirme-hatalari</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=API%20Yetkilendirme%20Hatalar%C4%B1%3A%20IDOR'u%20UUID%20ile%20%C3%87%C3%B6zd%C3%BC%C4%9F%C3%BCn%C3%BC%20Sanma</image:loc>
        <image:title>API Yetkilendirme Hataları: IDOR&apos;u UUID ile Çözdüğünü Sanma</image:title>
        <image:caption>API güvenliğinde en pahalı hata genelde authentication değil authorization tarafında çıkar. IDOR, tenant izolasyonu ve obje bazlı kontrol için pratik bir test planı.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/tr-nextjs-middleware-ile-ozel-sayfa-koruma</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Next.js'te%20%C3%96zel%20Sayfa%20Koruma%3A%20Noindex%20Yetmez%2C%20Server%20Taraf%C4%B1nda%20Kilitle</image:loc>
        <image:title>Next.js&apos;te Özel Sayfa Koruma: Noindex Yetmez, Server Tarafında Kilitle</image:title>
        <image:caption>Linki bilenlerin görebileceği sayfalar ile gerçekten şifreli alanlar farklı şeylerdir. Next.js App Router&apos;da noindex, middleware ve HttpOnly cookie ile pratik bir koruma modeli.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/htb-silentium-writeup</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=HackTheBox%20Silentium%20Writeup</image:loc>
        <image:title>HackTheBox Silentium Writeup</image:title>
        <image:caption>HTB Medium Silentium: staging subdomain, Flowise forgot-password + Mailhog, CVE-2025-59528 RCE, şifre tekrarı SSH, GOGS symlink arbitrary file write (CVE-2025-8110) ile root.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/metasploit-framework-guide</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Metasploit%20Framework%3A%20Modules%2C%20Sessions%2C%20and%20Basic%20Workflows</image:loc>
        <image:title>Metasploit Framework: Modules, Sessions, and Basic Workflows</image:title>
        <image:caption>Metasploit organized by task: choosing modules, handling sessions, and keeping notes during a test.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/burp-suite-beginners</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Burp%20Suite%20Proxy%2C%20Repeater%2C%20and%20Intruder%3A%20Intercepting%20and%20Replaying%20Web%20Requests</image:loc>
        <image:title>Burp Suite Proxy, Repeater, and Intruder: Intercepting and Replaying Web Requests</image:title>
        <image:caption>How Burp Suite Proxy, Repeater, and Intruder handle traffic interception and request replay, and where each fits in a manual web test.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/wireshark-guide</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Wireshark%3A%20Capture%20Filters%20and%20Malicious%20Traffic%20Patterns</image:loc>
        <image:title>Wireshark: Capture Filters and Malicious Traffic Patterns</image:title>
        <image:caption>How to capture and analyze network traffic with Wireshark. Essential filters and techniques for spotting malicious activity.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/owasp-top-10-guide</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=OWASP%20Top%2010%3A%20What%20Each%20Risk%20Category%20Covers</image:loc>
        <image:title>OWASP Top 10: What Each Risk Category Covers</image:title>
        <image:caption>The ten OWASP risk categories summarized: from Broken Access Control to Injection, with prevention pointers.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/top-10-bug-bounty-tools</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=A%20Small%20Bug%20Bounty%20Toolkit%3A%20What%20Each%20Tool%20Actually%20Does</image:loc>
        <image:title>A Small Bug Bounty Toolkit: What Each Tool Actually Does</image:title>
        <image:caption>Burp Suite, SQLmap, Shodan, and similar tools grouped by task: interception, enumeration, and verification in a manual test.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/ios-android-hacking-guide</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Mobile%20App%20Testing%20Notes%3A%20APK%20Analysis%2C%20Jailbreak%20Detection%2C%20and%20Traffic%20Interception</image:loc>
        <image:title>Mobile App Testing Notes: APK Analysis, Jailbreak Detection, and Traffic Interception</image:title>
        <image:caption>Manual mobile test tasks: decompiling APKs, dealing with jailbreak and root detection, and intercepting TLS traffic.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/wordpress-exploitation-guide-2025</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=WordPress%20Attack%20Surface%3A%20Plugins%2C%20Themes%2C%20and%20Core%20Misconfigurations</image:loc>
        <image:title>WordPress Attack Surface: Plugins, Themes, and Core Misconfigurations</image:title>
        <image:caption>Where WordPress findings usually come from: plugin and theme flaws plus core misconfigurations, and how testers narrow that surface.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/aws-cloud-penetration-testing-secrets</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=AWS%20Penetration%20Testing%20Notes%3A%20S3%2C%20IAM%2C%20and%20Lambda%20Misconfigurations</image:loc>
        <image:title>AWS Penetration Testing Notes: S3, IAM, and Lambda Misconfigurations</image:title>
        <image:caption>Common AWS findings: exposed S3 buckets, IAM misconfigurations, and Lambda weaknesses, grouped by service.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/social-engineering-masterclass</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Social%20Engineering%3A%20Phishing%2C%20Vishing%2C%20and%20Physical%20Breach%20Patterns</image:loc>
        <image:title>Social Engineering: Phishing, Vishing, and Physical Breach Patterns</image:title>
        <image:caption>Recurring social-engineering patterns across phishing, vishing, and physical intrusion attempts.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/penetration-testing-roadmap-2025</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Penetration%20Testing%20Reading%20Order%3A%20Skills%2C%20Certifications%2C%20and%20Tools</image:loc>
        <image:title>Penetration Testing Reading Order: Skills, Certifications, and Tools</image:title>
        <image:caption>A suggested study order for starting penetration testing: networking basics, security fundamentals, then practical labs.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/xss-comprehensive-guide</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=XSS%20Types%20Compared%3A%20Reflected%2C%20Stored%2C%20and%20DOM-Based%20Behavior</image:loc>
        <image:title>XSS Types Compared: Reflected, Stored, and DOM-Based Behavior</image:title>
        <image:caption>How reflected, stored, and DOM-based XSS differ in delivery and execution, with prevention notes tied to each type.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/sql-injection-mastery</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=SQL%20Injection%3A%20Types%2C%20Manual%20Detection%2C%20and%20Parameterized%20Queries</image:loc>
        <image:title>SQL Injection: Types, Manual Detection, and Parameterized Queries</image:title>
        <image:caption>In-band, blind, and out-of-band SQL injection compared, with manual detection notes and parameterized-query prevention.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/web-hacking-101-2025</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Web%20Hacking%3A%20Client-Side%20and%20Server-Side%20Vulnerability%20Classes</image:loc>
        <image:title>Web Hacking: Client-Side and Server-Side Vulnerability Classes</image:title>
        <image:caption>A map of web vulnerability classes, split by client-side and server-side, for planning what to study next.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/attacking-secondary-contexts</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Attacking%20Secondary%20Contexts%20in%20Web%20Applications</image:loc>
        <image:title>Attacking Secondary Contexts in Web Applications</image:title>
        <image:caption>Secondary contexts testers check after the main flow: log files, admin panels, and background jobs.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/waf-bypass-unicode</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Bypassing%20WAFs%20with%20Unicode%20Compatibility</image:loc>
        <image:title>Bypassing WAFs with Unicode Compatibility</image:title>
        <image:caption>When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/ai-security-testing</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=LLM-Assisted%20Security%20Testing%3A%20Payloads%2C%20Code%20Review%2C%20and%20Detection%20Notes</image:loc>
        <image:title>LLM-Assisted Security Testing: Payloads, Code Review, and Detection Notes</image:title>
        <image:caption>Where LLMs fit in a manual test: payload drafting, code review assistance, and detection support, with limits.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/smart-contract-auditing</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Smart%20Contract%20Auditing%3A%20Reentrancy%20and%20Common%20Solidity%20Flaws</image:loc>
        <image:title>Smart Contract Auditing: Reentrancy and Common Solidity Flaws</image:title>
        <image:caption>Solidity audit starting points: reentrancy and other frequent flaws, plus Slither and Mythril usage notes.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/zap-2-16-review</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=OWASP%20ZAP%202.16%3A%20New%20Features%20and%20Scan%20Comparison%20Notes</image:loc>
        <image:title>OWASP ZAP 2.16: New Features and Scan Comparison Notes</image:title>
        <image:caption>Notes on OWASP ZAP 2.16: new features, performance observations, and differences from paid scanners.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/automating-dead-link-detection</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Dead%20Link%20Detection%3A%20Subdomain%20Takeover%20and%20Phishing%20Risk</image:loc>
        <image:title>Dead Link Detection: Subdomain Takeover and Phishing Risk</image:title>
        <image:caption>Broken links as attack surface: subdomain takeovers and phishing via dangling references, with automation notes.</image:caption>
      </image:image>
    </url>

    <url>
      <loc>https://ibrahimsql.tr/posts/hidden-xss-no-interaction</loc>
      <image:image>
        <image:loc>https://ibrahimsql.tr/api/og?title=Zero-Interaction%20XSS%3A%20Payloads%20in%20Metadata%2C%20Filenames%2C%20and%20API%20Responses</image:loc>
        <image:title>Zero-Interaction XSS: Payloads in Metadata, Filenames, and API Responses</image:title>
        <image:caption>XSS vectors that trigger without a click: metadata, filenames, and API responses rendering unsanitized content.</image:caption>
      </image:image>
    </url>
</urlset>