Hello,

I write blog posts which are mostly related to computer security. Currently, I’m living in Berlin, Germany.

You can find more information about me on my LinkedIn profile.

Do not hesitate to get in touch with me.

Interested in

  1. Finding or analyzing security problems of computer software.
  2. Robustness Testing for Software Development such as fuzz testing and related sub-topics https://github.com/cemonatk/onefuzzyway.
  3. Coding.

Some of my amateur/college projects

  1. Padding Oracle Demo 1
  2. Estimator Tool Development for Number of People in a Particular Area
  3. Designing Downgrader from LTE GRC Block for UHDs
  4. EMP Generator Circuit on PCB 1, 2
  5. KOU OBS iOS Mobile Application 1, 2
  6. Temperature Measurement on MSP430 MCU (Microcontroller Unit) Server via Bluetooth Comm.
  7. Simple Link Shortener 1

Security researcher acknowledgments

  1. 35𝒕𝒉 and 92𝒕𝒉 (Nickname: Arif Isik) on Microsoft Security Response Center’s Top 100 Security Researchers of 2018. Attended BlueHat18 invite-only conference in Microsoft’s Headquarters, Seattle
  2. OpenAI Hall of Fame (CTRL+F: cemonatk, 2023)
  3. CVE-2017-8758: Microsoft Exchange Server Elevation of Privilege Vulnerability - Allowed to obtain victim’s data on Outlook Web Access by sending crafted emails even it is not opened by the victim. PoC Video. More detailed PoC Video is available upon request.
  4. Null Pointer Dereference Bug on Oracle VM VirtualBox, Ticket, PoC.cpp
  5. Google Chromium Remote Heap Memory Corruption, Exploit-DB
  6. Oracle - (6 bugs in same Critical Patch Update)
  7. Google
  8. Apple
  9. Several bugs of Microsoft’s products and online services. (Since 2016) 1, 2
  10. Mail.Ru and Pentagon
  11. Geeks for Geeks
  12. CERT-EU
  13. IT Department of Kocaeli University 1, 2
  14. Some private programs from several platforms and direct-invites from some of big companies

Other Bugs:

  1. Memory Corruption (Access Violation) on Zoom for Windows (2021). Fixed and rewarded by the vendor.

  2. Multiple bugs in Vim Editor (Written in C).
  3. Multiple bugs in tsMuxer which is used by Universal Media Server (https://www.universalmediaserver.com/about/) internally - Most starred transport stream muxer project on Github (Written in C++).
  4. Multiple bugs in ffjpeg project.

Other

  1. Ex-Core Member at CanYouPwn.Me
  2. Ex-Member of WeedSquad
  3. Python for Hackers Instructor at PwnlyDays
  4. OSCP and OSCE certifications