<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://burakdirlik.dev/</id><title>Burak Dirlik</title><subtitle>A minimal, responsive and feature-rich Jekyll theme for technical writing.</subtitle> <updated>2026-06-06T19:01:12+03:00</updated> <author> <name>Burak Dirlik</name> <uri>https://burakdirlik.dev/</uri> </author><link rel="self" type="application/atom+xml" href="https://burakdirlik.dev/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://burakdirlik.dev/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Burak Dirlik </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>GraphQL Vulnerabilities from an Attacker's Perspective</title><link href="https://burakdirlik.dev/posts/graphql-vulnerabilities/" rel="alternate" type="text/html" title="GraphQL Vulnerabilities from an Attacker&amp;apos;s Perspective" /><published>2026-06-06T16:20:00+03:00</published> <updated>2026-06-06T19:00:52+03:00</updated> <id>https://burakdirlik.dev/posts/graphql-vulnerabilities/</id> <content type="text/html" src="https://burakdirlik.dev/posts/graphql-vulnerabilities/" /> <author> <name>Burak Dirlik</name> </author> <category term="Web Security" /> <category term="GraphQL" /> <summary>What GraphQL vulnerabilities are and how to find them in bug bounty — introspection, IDOR/BOLA, injection, and rate-limit bypass via batching, explained from scratch with examples.</summary> </entry> <entry><title>SSRF Deep Dive: From Internal Services to Cloud Metadata</title><link href="https://burakdirlik.dev/posts/ssrf-attacks/" rel="alternate" type="text/html" title="SSRF Deep Dive: From Internal Services to Cloud Metadata" /><published>2026-04-25T00:00:00+03:00</published> <updated>2026-04-25T01:39:45+03:00</updated> <id>https://burakdirlik.dev/posts/ssrf-attacks/</id> <content type="text/html" src="https://burakdirlik.dev/posts/ssrf-attacks/" /> <author> <name>Burak Dirlik</name> </author> <category term="Web Security" /> <category term="Pentest" /> <summary>From basic internal port scanning to AWS/GCP metadata exploitation — SSRF walked through real pentest scenarios, filter bypasses, and cloud attack paths.</summary> </entry> <entry><title>JWT Attacks: A Pentester's Playbook Through Real Scenarios</title><link href="https://burakdirlik.dev/posts/jwt-attacks/" rel="alternate" type="text/html" title="JWT Attacks: A Pentester&amp;apos;s Playbook Through Real Scenarios" /><published>2026-04-24T10:00:00+03:00</published> <updated>2026-04-25T01:38:42+03:00</updated> <id>https://burakdirlik.dev/posts/jwt-attacks/</id> <content type="text/html" src="https://burakdirlik.dev/posts/jwt-attacks/" /> <author> <name>Burak Dirlik</name> </author> <category term="Web Security" /> <category term="Pentest" /> <summary>From alg:none to kid injection, from algorithm confusion to jku manipulation — the JWT attack surface walked through real pentest scenarios.</summary> </entry> <entry><title>Mass Assignment: A Silent but Devastating API Vulnerability</title><link href="https://burakdirlik.dev/posts/mass-assignment-vulnerability/" rel="alternate" type="text/html" title="Mass Assignment: A Silent but Devastating API Vulnerability" /><published>2026-04-20T10:00:00+03:00</published> <updated>2026-04-25T01:39:00+03:00</updated> <id>https://burakdirlik.dev/posts/mass-assignment-vulnerability/</id> <content type="text/html" src="https://burakdirlik.dev/posts/mass-assignment-vulnerability/" /> <author> <name>Burak Dirlik</name> </author> <category term="Web Security" /> <category term="API Security" /> <summary>The technical origin of the Mass Assignment vulnerability, scenario-based exploitation examples, real-world cases, and framework-specific defense methods.</summary> </entry> <entry><title>Privilege Escalation in Active Directory: RBCD Attack</title><link href="https://burakdirlik.dev/posts/Active-Directory-RBCD-Attack/" rel="alternate" type="text/html" title="Privilege Escalation in Active Directory: RBCD Attack" /><published>2026-04-15T21:49:00+03:00</published> <updated>2026-04-25T01:38:24+03:00</updated> <id>https://burakdirlik.dev/posts/Active-Directory-RBCD-Attack/</id> <content type="text/html" src="https://burakdirlik.dev/posts/Active-Directory-RBCD-Attack/" /> <author> <name>Burak Dirlik</name> </author> <category term="Active Directory" /> <category term="Privilege Escalation" /> <summary>What is Resource-Based Constrained Delegation, how is it exploited, and a full end-to-end attack chain walk-through using RBCD-Pwn.</summary> </entry> </feed>
