Ozgur Alp·Apr 8If OpenClaw is the New Computer, What Happens to Web Apps?Recently, Nvidia’s CEO dropped a statement that should be keeping software architects and security researchers awake at night: “OpenClaw…
Ozgur Alp·Jan 26Bug Bounties 201: Bug Hunting in the Age of AIFour years ago, when I wrote How to Start Bug Bounty 101, if you had asked me how AI would affect our industry, I would have dismissed it…A response icon5A response icon5
Ozgur Alp·Sep 30, 2025Turning Blind Error Based SQL Injection into Exploitable Boolean One Part 2: MySQLAfter my original blog post published in late 2020, I kept encountering the same vulnerability across different database management…A response icon1A response icon1
Ozgur Alp·Feb 28, 2023Depremzede Dolandırıcılarına Dikkat!Kendini depremzede olarak tanıtıp insanların duygularını sömürerek dolandırmaya çalışan sosyal medya dolandırıcılarına karşı en dikkatli…
Ozgur Alp·Feb 14, 2022BigQuery SQL Injection Cheat SheetLast year, we (My researcher partner on this topic, Anil and me) and found a SQL injection vulnerability on a target at Synack which was…
Ozgur Alp·Oct 27, 2021How to Start Bug Bounties 101 & How to Make a Million in 4 YearsI got lots of questions and requests especially from new beginners to the area, so wanted to prepare a blog post regarding how to start at…A response icon10A response icon10
Ozgur Alp·Nov 20, 2020Turning Blind Error Based SQL Injection Into An Exploitable Boolean OneWhile I was recently hunting on a promising host target, from my well configured (only checking SQLi) active scan results, I found out a…A response icon2A response icon2
Ozgur Alp·Apr 19, 2020Google Maps API (Not the key) Bugs That I Found Over the YearsAfter publishing my blog post Unauthorized Google Maps API Key Usage Cases, and Why You Need to Care and scanner script for it, I got…A response icon4A response icon4
Ozgur Alp·Mar 15, 2020Using Vulnerability Analytics Feature Like a BossFor the %90 of my working time, I am hunting bugs on the Synack for 2 reasons:A response icon1A response icon1
Ozgur Alp·Feb 26, 2020Write-up: AWS Document Signing Security Control BypassWhile I prefer more to write/talk about far-going topics instead of just one vulnerability write-up, I decided to make an exception for…A response icon1A response icon1