Blog · corpus.blog/blogs/mehmetince.net/posts
mehmetince.net
mehmetince.net
2026
Part 2/6 | Breaking the Postgres Superuser Guardrails: Attacking Security-Hardening Extensions |Systemic Risks in the Managed PostgreSQL Industryoriginal ↗
23 Sept 2026
Part 1/6 | Systemic Risks in the Managed PostgreSQL Industry: Extension Risks Are Real! Exploiting PostGis Memory Corruption Bug at NeonDB, SupaBase and Many Moreoriginal ↗
14 Aug 2026
The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Applianceoriginal ↗
1 Jan 2026
2025
Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096)original ↗
15 Dec 2025
The Chessboard of Security: Insights on Product Development and Vulnerabilities from a Hacker Perspectiveoriginal ↗
7 Nov 2025
2021
CVE-2021-21425 | Unexpected Journey #7 – GravCMS Unauthenticated Arbitrary YAML Write/Update leads to Code Executionoriginal ↗
21 Mar 2021
2020
18 Mar 2020
2019
Why Secure Design Matters ? Secure Approach to Session Validation on Modern Frameworks (Django Solution)original ↗
8 Sept 2019
2018
Unexpected Journey #6 – All ways lead to Rome ! Remote Code Execution on MicroFocus Secure Messaging Gatewayoriginal ↗
22 Jun 2018
2017
Advisory | DenyAll Web Application Firewall Unauthenticated Remote Code Execution (CVE-2017-14706)original ↗
19 Sept 2017
Unexpected Journey #5 – From weak password to RCE on Symantec Messaging Gateway (CVE-2017-6326)original ↗
10 Jun 2017
Unexpected Journey #4 – Escaping from Restricted Shell and Gaining Root Access to SolarWinds Log & Event Manager (SIEM) Productoriginal ↗
17 Mar 2017
Unexpected Journey #3 – Visiting Another SIEM and Uncovering Pre-auth Privileged Remote Code Executionoriginal ↗
7 Mar 2017
16 Feb 2017