<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="//blog.onurcangenc.com.tr/sitemap.xsl"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"><url><loc>https://blog.onurcangenc.com.tr/htb-valentine/</loc><lastmod>2026-04-03T20:22:32.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/04/Gemini_Generated_Image_9on0o9on0o9on0o9-1.png</image:loc><image:caption>Gemini_Generated_Image_9on0o9on0o9on0o9-1.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-cicada-from-password-spraying-to-token-abuse/</loc><lastmod>2026-04-03T16:17:02.110Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_xkz25rxkz25rxkz2.png</image:loc><image:caption>Gemini_Generated_Image_xkz25rxkz25rxkz2.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-irked-writeup-unrealircd-backdoor-to-root-via-suid-abuse/</loc><lastmod>2026-04-03T16:11:41.145Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_g3j66eg3j66eg3j6.png</image:loc><image:caption>Gemini_Generated_Image_g3j66eg3j66eg3j6.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-beep/</loc><lastmod>2026-04-03T14:47:37.362Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_l4dqb8l4dqb8l4dq.png</image:loc><image:caption>Gemini_Generated_Image_l4dqb8l4dqb8l4dq.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-curling-joomla-rce-to-curl-config-file-abuse/</loc><lastmod>2026-04-03T01:30:42.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/04/d7ea8cb4-2412-4e19-b16a-036b0e9c0cf0.jpg</image:loc><image:caption>d7ea8cb4-2412-4e19-b16a-036b0e9c0cf0.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/cve-2025-10878/</loc><lastmod>2026-03-30T23:12:46.385Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_wv9q7qwv9q7qwv9q.png</image:loc><image:caption>Gemini_Generated_Image_wv9q7qwv9q7qwv9q.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/cve-2026-34156-vm-sandbox-escape-to-rce-in-nocobase/</loc><lastmod>2026-03-28T13:43:49.278Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_dp2l7vdp2l7vdp2l.png</image:loc><image:caption>Gemini_Generated_Image_dp2l7vdp2l7vdp2l.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/applying-ethical-theories-in-responsible-disclosure-program/</loc><lastmod>2026-03-25T04:52:52.465Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/nf6E6BMh-1.jpg</image:loc><image:caption>nf6E6BMh-1.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-bank/</loc><lastmod>2026-03-21T00:31:12.570Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_ofo3r3ofo3r3ofo3.png</image:loc><image:caption>Gemini_Generated_Image_ofo3r3ofo3r3ofo3.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/idor-in-moodle-openai-chat-block-block_openai_chat-proof-of-concept-poc-cve-2025-60511/</loc><lastmod>2026-03-17T23:40:34.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_60wic060wic060wi.png</image:loc><image:caption>Gemini_Generated_Image_60wic060wic060wi.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/cve-2025-10228/</loc><lastmod>2026-03-16T20:30:22.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_2oire2oire2oire2.png</image:loc><image:caption>Gemini_Generated_Image_2oire2oire2oire2.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/cve-2025-60507-moodle-geniai-plugin-v2-3-6-xss-via-pdf-upload-prompt-injection/</loc><lastmod>2026-03-16T20:13:16.542Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_7uv7x87uv7x87uv7.png</image:loc><image:caption>Gemini_Generated_Image_7uv7x87uv7x87uv7.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/cve-2025-60506-stored-cross-site-scripting-xss-in-moodle-pdf-annotator-plugin-v1-5-release-9/</loc><lastmod>2026-03-16T20:12:47.222Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_gjebu4gjebu4gjeb.png</image:loc><image:caption>Gemini_Generated_Image_gjebu4gjebu4gjeb.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/cve-2025-57520-stored-xss-in-decap-cms-3-8-3/</loc><lastmod>2026-03-16T20:12:38.233Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_czdjeqczdjeqczdj.png</image:loc><image:caption>Gemini_Generated_Image_czdjeqczdjeqczdj.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-nibbles-file-upload-to-root/</loc><lastmod>2026-03-16T18:35:17.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_cve63tcve63tcve6.png</image:loc><image:caption>Gemini_Generated_Image_cve63tcve63tcve6.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-devvortex-from-joomla-info-disclosure-to-root/</loc><lastmod>2026-03-16T11:21:28.152Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/Gemini_Generated_Image_68n5wv68n5wv68n5.png</image:loc><image:caption>Gemini_Generated_Image_68n5wv68n5wv68n5.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-bounty-file-upload-to-system-via-chimichurri/</loc><lastmod>2026-03-14T22:11:09.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_v219c-v-BJkMKvx3bAWpcg.webp</image:loc><image:caption>1_v219c-v-BJkMKvx3bAWpcg.webp</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/my-c-ai-mlpen-exam-journey-2/</loc><lastmod>2026-03-13T22:31:30.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_9rBzA9nvHnOCkFPuIPP9EQ.jpg</image:loc><image:caption>1_9rBzA9nvHnOCkFPuIPP9EQ.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/i-asked-an-ai-about-its-security-policies-it-gave-me-the-api-key/</loc><lastmod>2026-03-13T22:20:27.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_GICozJ36YK4jbxuyv0So2g.jpg</image:loc><image:caption>1_GICozJ36YK4jbxuyv0So2g.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/breaking-an-ai-powered-shell/</loc><lastmod>2026-03-13T22:18:44.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/0_IrbdPSGe91dvmFBm.jpg</image:loc><image:caption>0_IrbdPSGe91dvmFBm.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-blocky/</loc><lastmod>2026-03-13T22:16:58.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_5kxnjP_IfGY6sxlW6GsiIg.jpg</image:loc><image:caption>1_5kxnjP_IfGY6sxlW6GsiIg.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-keeper-writeup-how-a-danish-dessert-unlocked-root-access/</loc><lastmod>2026-03-13T16:40:16.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_JmHvP5cIYvdxps-looXZZQ.jpg</image:loc><image:caption>1_JmHvP5cIYvdxps-looXZZQ.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-knife-php-8-1-0-dev-supply-chain-backdoor-rce-to-root/</loc><lastmod>2026-03-13T16:38:16.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_dfWBAa2DHYELxtRrxRcieQ.jpg</image:loc><image:caption>1_dfWBAa2DHYELxtRrxRcieQ.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-broker-writeup/</loc><lastmod>2026-03-13T15:00:53.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_99fAv1G0A9iuTkEYtQDaZw.webp</image:loc><image:caption>1_99fAv1G0A9iuTkEYtQDaZw.webp</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/my-c-ai-mlpen-exam-journey/</loc><lastmod>2026-03-12T15:34:01.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_9rBzA9nvHnOCkFPuIPP9EQ.webp</image:loc><image:caption>1_9rBzA9nvHnOCkFPuIPP9EQ.webp</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-bashed-writeup-from-phpbash-webshell-to-root-via-cron-job-abuse/</loc><lastmod>2026-03-12T15:31:03.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_HxzGOit6W8w8fH0arH3-2w.jpg</image:loc><image:caption>1_HxzGOit6W8w8fH0arH3-2w.jpg</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-mirai-default-creds-pi-hole-usb-forensics/</loc><lastmod>2026-03-12T15:30:20.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_iyk1_KaqFIKU-8bRqO4UmA.png</image:loc><image:caption>1_iyk1_KaqFIKU-8bRqO4UmA.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-shocker-rce-via-cgi-bin-perl-privesc/</loc><lastmod>2026-03-12T15:29:33.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_AxotoJPbRFlnHkubQWLXlA.png</image:loc><image:caption>1_AxotoJPbRFlnHkubQWLXlA.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/cross-detector-inconsistency-in-ai-text-detection-a-benchmark-study-with-hybrid-evasion-techniques/</loc><lastmod>2026-03-12T15:02:58.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_2INie45JG5h_V_e18KYUEw.webp</image:loc><image:caption>1_2INie45JG5h_V_e18KYUEw.webp</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-sense-hacking-the-firewall/</loc><lastmod>2026-03-12T10:16:25.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_P-bWOcA-hSdR-AQofUUDiQ-1.png</image:loc><image:caption>1_P-bWOcA-hSdR-AQofUUDiQ-1.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-arctic-remote-command-execution-to-juicypotato-privesc/</loc><lastmod>2026-03-12T10:15:31.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_P-bWOcA-hSdR-AQofUUDiQ.png</image:loc><image:caption>1_P-bWOcA-hSdR-AQofUUDiQ.png</image:caption></image:image></url><url><loc>https://blog.onurcangenc.com.tr/htb-return-ldap-credential-theft-to-service-hijacking/</loc><lastmod>2026-03-12T10:09:04.000Z</lastmod><image:image><image:loc>https://blog.onurcangenc.com.tr/content/images/2026/03/1_pviiN4Kuv-m5P3U3g6eYfA.jpg</image:loc><image:caption>1_pviiN4Kuv-m5P3U3g6eYfA.jpg</image:caption></image:image></url></urlset>