Mehmet Ince @mdisec – Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
a hacker at heart, a builder by practice, and a mentor by purpose. As co-founder of PRODAFT, I’ve spent the last two decades in vulnerability research and security product engineering.
Back in April, I was talking with our system and software engineering teams at PRODAFT about the possibilities of using a managed database service. Due to the nature of our business, we simply cannot start using managed services right away. I told my team, “Alright, I will have a look at a few companies and [ ] The post Part 1/6 | Systemic Risks in the Managed PostgreSQL Industry: Extension Risks…
It was May 2024, and our internal security team was evaluating the LogPoint SIEM/SOAR platform to replace our existing platform, potentially. As part of a habit I’ve built over the years —and honestly, part of our 3rd party due diligence— I gave myself 24 hours to do what I always do with any technology we’re [ ] The post The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until…
It was yet another day at the office. Our team was internally discussing moving to a different platform analytics solution. Our team was really leaning more towards Posthog. It s one of the brilliant -I personally believe it s the best- products on the market. And that s where the story has begun We have a somewhat unconventional—some [ ] The post Inside PostHog: How SSRF, a ClickHouse SQL…
I was playing a quick game of chess while waiting for my coffee this morning. I had the white pieces and, as always, was eager to make the most of my first-move advantage. Early in the game, I pushed a center pawn forward aggressively, hoping to gain more control of the board. But soon, I [ ] The post The Chessboard of Security: Insights on Product Development and Vulnerabilities from a Hacker…
Whenever I ponder the vastness of space and our limited ability to observe only the Milky Way, I am utterly fascinated. It took us thirty years to position the James Webb Telescope at the Lagrange point (L2), offering us a mere glimpse into events that unfolded millions of years ago. Trying to grasp the enormity [ ] The post Digital Cosmos: A Journey Through the Galaxy of Vulnerabilities appeared…
LiderAhenk is an open source software system that enables centralized management, monitoring and control of systems and users on the corporate network. In this blog post, you will see how bad it can get when you have a critical security vulnerability on your centralized client management system. Architecture and Our Target LiderAhenk software has 2 [ ] The post CVE-2021-3825 | LiderAhenk 0day All…
A couple of days ago, I came up with news that Pardus will organize a report-bug contest. I love to contribute to open-source projects. So that was a pretty good chance to revisit one of my old friends, Pardus, and uncover security and/or privacy issues. What is Pardus ? Pardus is a Linux distribution developed with support from [ ] The post CVE-2021-3806 | Pardus 21 Linux Distro Remote Code…
It has been a while since I haven t published a post on our beloved blog. Today I would like to share technical details and POC for a pretty funny vulnerability that I ve found at GravCMS. As I ve been saying since 2015, my pentest team and I love to chase after 0days during penetration test engagements. [ ] The post CVE-2021-21425 | Unexpected Journey #7 GravCMS Unauthenticated Arbitrary YAML…
I believe that doing a security research is all about trying to understand high-level of architecture of the products and finding a creative attack vectors. I hope this blog post will show some the readers how to start doing security research. Installation You can install that software Debian/Ubuntu or CentOS. I’ve installed it on Ubuntu [ ] The post Vesta Control Panel Second Order Remote Code…
I ve been doing security researches on softwares for a quite long time. During these researchs, I often find myself in a situation where in I think about the state of mind of developers, problems that occur during developments and core problems of nature of software crafting teams. Thinking about these questions always lead me to [ ] The post Why Secure Design Matters ? Secure Approach to Session…