skip to content
hackwith.me — sessionlink: stable
$ whoami

Adil Burak Şen

a.k.a. 0racLe
Senior Application Security Engineer
$ cat ./signal.txt

Application security engineer with 10+ years in offensive and application security across banking, telecom, aviation, insurance and e-commerce. Web, API and mobile security testing, threat modeling and CI/CD security. Bugcrowd Top 100 (2018), 150+ validated vulnerabilities, credited for CVE-2026-31974 (OpenProject). OSCP+, eWPTx, eMAPT, CASP.

$ ▍
// Selected Disclosure
CVE-2026-31974 (external)
SSRF in OpenProject — OpenProject
LowReporter2026

Blind SSRF through webhooks and the SMTP test endpoint. Reported independently through the YesWeHack OpenProject program and credited in the advisory. Fixed in v17.2.0.

// Featured Project
2025 / active
CVE-2025-25257 Exploit Tool (external)

Public exploit tool for pre-authentication SQL injection in Fortinet FortiWeb Fabric Connector (CVSS 9.8). Detects vulnerable instances and demonstrates impact.

// Recent Writingview all →
$ status --availability
Open to Europe / UK / Remote
Istanbul, Turkey