Learn
Network and security concepts, explained clearly.
Practical explanations of the concepts behind the tools. Each article is written to build genuine understanding, not just to define a term.
The article index ↓
The vendor-neutral library, grouped by subject. Vendor-specific writing lives on the hubs.
293 articles
Vendor hubs →
One door per vendor: the tools, the articles, and the certifications that belong to each platform.
8 vendors
The Practice →
How the work is actually done, rather than how the technology works. Triage, escalation, evidence, handover, and the parts no runbook covers.
64 published
The Roles →
The positions this industry is made of, grouped by the path a product takes. Who makes it, moves it, sells it, deploys it, runs it, supports it, defends it and teaches it.
39 positions
Certification study guides →
Exam blueprints mapped objective by objective to the articles that teach them.
105 exam guides
Glossary →
The field's terms, acronyms, expressions, jargon, and lore - defined, sourced, and linked to the tools that compute them.
1242 terms
Study guides →
Curated reading paths and blueprint-mapped certification guides - every objective tied to the articles that teach it and the tools that exercise it.
13 reading paths105 exam guides1632 objectives mapped
Ağ (105)
IPv4 adresleri nasıl çalışır
Her noktalı-dörtlü adresin arkasındaki 32 bit ve özel, loopback ve özel aralıkların ne anlama geldiği.
AğReadThe Syslog PRI: One Number, Two Meanings
Every syslog message starts with a PRI, a number in angle brackets that packs a facility and a severity into a single value. The formula is small and the arithmetic is easy once you have seen it: PRI equals facility times eight plus severity.
AğReadAlt ağ oluşturmanın temelleri
Bir ağı nasıl daha küçük alt ağlara böleceğiniz ve ana bilgisayar bitlerini ödünç almanın neden tüm hilenin kendisi olduğu.
AğReadSyslog Facilities and Severities, Explained
Syslog defines 24 facilities and 8 severities. The severities are a clean urgency scale from emergency down to debug; the facilities are a mix of genuinely useful categories and historical Unix leftovers, plus eight local slots that network devices lean on heavily.
AğReadCIDR notasyonu açıklandı
192.168.1.0/24'teki eğik çizginin aslında ne anlama geldiği ve bir önek uzunluğunun bir IP adresleri bloğunu nasıl tanımladığı.
AğReadSyslog on Network Devices: Which Facility Does What
Firewalls, load balancers, and switches almost all log to the local facilities, but each vendor picks a different default. Knowing that FortiGate defaults to local7, Cisco ASA to local4, and F5 BIG-IP to local0 turns a wall of PRI numbers into a map of which box said what.
AğReadSyslog Message Formats: RFC 3164 vs RFC 5424
The PRI is the same everywhere, but what follows it is not. Legacy BSD syslog (RFC 3164) has a loose, year-less format, while the modern format (RFC 5424) is precise and structured. Knowing which one you are looking at explains missing timestamps, ambiguous fields, and why parsers disagree.
AğReadVLSM: bir bloğu eşit olmayan alt ağlara bölme
Bir adres bloğunu yer israf etmeden farklı boyutlardaki alt ağlara nasıl keseceğiniz ve her şeyi düzenli tutan önce-en-büyük kuralı.
AğReadBaştan sona çözülmüş bir VLSM ataması
Gerçekçi bir ağ için değişken uzunluklu alt ağların eksiksiz bir ataması: her segmenti boyutlandırma, en büyükten en küçüğe sıralama, gerçek adresleri atama ve geriye kalan alanı hesaba katma.
AğReadHow Syslog Travels: UDP, TCP, and TLS
Syslog can ride over plain UDP, over TCP, or over TLS, and the choice decides whether messages can be silently lost, reordered, or read in transit. This covers the three transports, the ports involved, and why anything you rely on for audit should not be sent over UDP.
AğReadThe First Hour: Hypothesis-Driven Fault Isolation
The difference between a two-hour incident and a two-day one is usually decided in the first hour, and it is rarely decided by tools. It is decided by method: aligning onset with change, isolating by scope, reading layer signatures, and treating every explanation as a hypothesis that evidence must support or weaken before anyone acts on it.
AğOperations & FieldcraftReadÜst ağ oluşturma ve rota toplama
Bitişik öneklerin nasıl tek bir daha kısa önekte birleştiği, iki bloğun birleşip birleşemeyeceğini belirleyen hizalama kuralı ve tam toplama ile bunları kapsayan tek bir üst ağ arasındaki fark.
AğReadChange Windows That Do Not Become Incidents
Most self-inflicted outages are changes that went wrong with no clean way back. The difference between a change and an incident is rarely the change itself; it is the runbook around it - what you verified before, how you sequenced it, what would make you stop, and whether the way back was written down and tested before you needed it.
AğOperations & FieldcraftReadRota özetleme
Tek bir özet rotanın neden birçok belirli rotanın yerini alabileceği, bağlı olduğu bitişik ve hizalanmış atama ve tam sahip olmadığınız bir aralığı özetlerken kara delik riski.
AğReadAlt ağ çakışmaları ve boşlukları
İki önekin çakışmasının veya birinin diğerini içermesinin ne anlama geldiği, en uzun önek eşleşmesinin bazı çakışmaları neden kasıtlı kıldığı ve bir adres planının atanmamış boşluklarının nasıl bulunacağı.
AğReadRoot Cause Is a Verb, Not a Noun
The phrase root cause invites a single villain and a tidy ending. Real incidents rarely have one; they have contributing factors, and the honest work is structuring the candidates and the evidence that would confirm or rule out each - not naming a culprit before the evidence is in.
AğOperations & FieldcraftReadBlast-Radius Thinking Before You Change Anything
Before a change, the question is not only will this work but if it goes wrong, how far does the damage reach. Blast radius is the shape of that reach - target, neighbours, dependents, people - and thinking about it in tiers is how you decide what to contain before you touch anything.
AğOperations & FieldcraftReadÖzel IPv4 adres alanı ve RFC 1918
Üç özel aralık, neden internette yönlendirilemedikleri ve CIDR aracının işaretlediği diğer özel bloklar.
AğReadIPv6 adreslemesini anlamak
128 bitlik bir IPv6 adresinin nasıl yapılandırıldığı ve yazıldığı, onu kanonik biçimde sıkıştırma kuralları, adres türlerinin ve kapsamların ne anlama geldiği, ve arabirim tanımlayıcıları ile ters DNS'in nasıl çalıştığı.
AğReadTAC Cases That Get Triaged Fast
The slowest support cases are rarely the hardest problems; they are the ones that opened without the diagnostic the vendor needs. A case that arrives complete - clear problem, exact error, the diagnostic bundle, the impact - skips the round trips and starts with an engineer actually working it.
AğOperations & FieldcraftReadIPv6 ana bilgisayarları adresleri nasıl alır: SLAAC ve DHCPv6
Bir IPv6 ana bilgisayarının link-local'den yukarıya kendini nasıl yapılandırdığı, yönlendirici duyurularının neye karar verdiği, ve SLAAC, gizlilik adresleri ile DHCPv6 arasındaki fark.
AğReadCapture Points Before Packets
The instinct under pressure is to start tcpdump somewhere convenient and stare at the flood. The senior habit is the opposite: decide where to observe, in what order, and what each observation would mean - before a single packet is collected. Evidence is designed, not fished for.
AğOperations & FieldcraftReadIPv6 alt ağ oluşturma ve /64 sınırı
IPv6 alt ağ oluşturmanın neden kıtlık yerine yapı hakkında olduğu, tek bir alt ağın neden neredeyse her zaman bir /64 olduğu ve önek devrinin adres alanını nasıl dağıttığı.
AğReadPublic suffixes and the registered domain (eTLD+1)
What a public suffix (eTLD) and a registered domain (eTLD+1) are, why you cannot compute them by taking the last two labels, how the Public Suffix List algorithm resolves them, and where the boundary matters: certificate rate limits, cookies, and same-site.
AğSertifikalar ve PKIReadKomşu Keşfi: IPv6 ARP'yi nasıl değiştirir
IPv6'nın bir bağlantıda komşuları yayın ARP yerine ICMPv6 ve çok noktaya yayın kullanarak nasıl bulduğu, beş Komşu Keşfi mesajı, ve yayının neden gittiği.
AğReadMap the Path Before You Troubleshoot
The most expensive troubleshooting sessions share one flaw: nobody actually knew the path. The senior habit is refusing to reason about a failure until the chain is modeled - resolution included, return leg separate, every rewrite and TLS boundary named, and every unknown left visibly unknown.
AğOperations & FieldcraftReadBaselines Before You Need Them
Every comparison is only as honest as its weaker side. The discipline is captured baselines before changes, declared confidence instead of remembered health, observation windows that let convergence speak, churn literacy for the counters that always move - and never calling a change successful on green components alone.
AğOperations & FieldcraftReadIPv6 ve IPv4'ü birlikte çalıştırmak: dual-stack ve çeviri
İnternetin iki uyumsuz adres ailesi arasında nasıl köprü kurduğu: dual-stack, Happy Eyeballs, NAT64, ve bunu işler kılan IPv4-gömülü adresler.
AğReadWhat Is an OUI, and How MAC Addresses Are Assigned
How a MAC address is structured, what the OUI (the manufacturer prefix) is and who hands it out, the difference between universally and locally administered addresses, and why a randomized Wi-Fi MAC has no vendor at all.
AğReadFabric Connect and SPBM: Why VOSS Retires Spanning Tree
What Extreme's Fabric Connect actually is - Shortest Path Bridging MAC (SPBM, IEEE 802.1aq) with an IS-IS control plane and a MAC-in-MAC data plane - and why collapsing the core to a single link-state protocol replaces spanning tree and the usual overlay stack.
AğReadReading dig Output From Top to Bottom
A dig answer has a fixed shape: a version line, the header, the flags line, the OPT pseudo-section, the four sections, and the query stats. Once you know what each block is, you can read any response at a glance and spot the one line that explains a resolution problem.
AğReadThe DNS Header: Opcode, Status, and Flags
The header line and the flags line hold the message-level facts: what kind of query this is, whether it succeeded, and seven single-bit flags (qr, aa, tc, rd, ra, ad, cd) that tell you who answered and how. Reading them correctly is the difference between a two-minute diagnosis and an hour of guessing.
AğReadThe I-SID: How VOSS Replaces VLAN Stretching
Why Extreme's Fabric Connect provisions services at the edge instead of trunking VLANs hop by hop, what the 24-bit I-SID is, and how Layer 2 VSN, Layer 3 VSN, and IP Shortcuts all ride the same mechanism over an SPBM MAC-in-MAC core.
AğReadIS-IS, Nicknames, and B-MACs: The VOSS Control Plane
How SPBM uses IS-IS as its single link-state control plane on fabric links only, what a 20-bit node nickname is and why it must be unique, and how the system-id / backbone MAC drives MAC-in-MAC forwarding.
AğReadReading the Records in a dig Answer
Every record in a dig section is five columns: name, TTL, class, type, and rdata. This walks the columns and then the rdata of the record types you actually meet, from A and CNAME to MX, SOA, SRV, and CAA, so a wall of records reads as plain facts.
AğReadEDNS and the OPT Pseudo-Section
The OPT pseudo-section is not a record and not something you queried: it is EDNS(0) metadata that dig surfaces near the top of an answer. It carries the UDP payload size, the DO flag that requests DNSSEC, and options like COOKIE, and it quietly explains a whole class of resolution failures.
AğReadFabric Attach: Auto-Provisioning the Edge (Where VOSS Meets EXOS)
How Fabric Attach lets an edge device signal the service it needs so the fabric provisions the I-SID automatically, the FA Server / Proxy / Client roles, how it rides LLDP (Link Layer Discovery Protocol), and how an EXOS switch attaches to a VOSS fabric without running SPBM itself.
AğReadDNSSEC Records in dig Output
Add +dnssec and a dig answer grows a new family of records: RRSIG, DNSKEY, DS, and the NSEC or NSEC3 denial records. This explains what each one is, how they chain from the root down to a zone, and what the ad flag really certifies.
AğReadVOSS vs EXOS: Two Extreme Operating Systems
Extreme ships universal hardware that boots either EXOS or VOSS (Fabric Engine). This is what actually differs - a traditional-Ethernet OS with an intuitive CLI versus a fabric-native OS built on SPBM - and the three boundaries at which they interconnect.
AğReadReading nslookup Output
nslookup prints a Server / Address header for the resolver it used, an optional Non-authoritative answer marker, and then the answer in a per-type prose format. Knowing that shape lets you read any result quickly and see at a glance whether it succeeded, where it came from, and what it means.
AğReadSMLT and vIST: Dual-Homing a Fabric Edge
How Split MultiLink Trunking dual-homes an edge device to a pair of switches with active-active links and no spanning tree, how virtual IST runs the inter-switch trunk through the SPBM fabric itself, and the smlt-peer-system-id and smlt-virtual-bmac that make the cluster one logical node.
AğReadnslookup vs dig: Which to Use
nslookup and dig both query DNS, but nslookup is terser and hides the header flags and TTLs that dig shows in full. This maps one output onto the other and gives a simple rule for which to reach for.
AğReadHow nslookup Prints Each Record Type
Instead of dig's fixed columns, nslookup labels each record in prose: mail exchanger =, canonical name =, nameserver =, and a multi-line block for SOA. A short guide to reading each type's line.
AğReadAuthoritative vs Non-Authoritative Answers
The Non-authoritative answer marker in nslookup means the result came from a resolver's cache, not from a server that actually holds the zone. This explains the difference, why it is usually fine, and how to get an authoritative answer when you need one.
AğReadnslookup Errors and What They Mean
When a lookup fails, nslookup prints a line like ** server can't find NAME: CODE. The code is the whole diagnosis. This covers NXDOMAIN, SERVFAIL, REFUSED, and timeouts, what each one tells you, and the first thing to check for each.
AğReadReverse DNS Lookups with nslookup
Reverse DNS maps an IP address back to a name through PTR records that live under in-addr.arpa for IPv4 and ip6.arpa for IPv6. nslookup does this automatically when you hand it an address. This covers how the special reverse name is built, why mail servers care, and why the forward and reverse can legitimately disagree.
AğReadnslookup Interactive Mode
Run nslookup with no arguments and it drops into an interactive prompt where you can switch resolvers, change the record type, turn on debug output, and look up many names in one session. This covers the handful of commands worth knowing and when interactive beats a one-shot query.
AğReaddig Query Options and Output Control
dig's real power is its options: choosing the server to ask, the record type, and exactly how much of the answer to print. This covers the handful you will actually use every day, from @server and -t to +short and the +noall +answer combination that trims dig down to just the records.
AğReadFollowing Delegation with dig +trace
dig +trace resolves a name the way the internet actually does it: starting at the root, following the delegation to the TLD, and then to the domain's own authoritative servers, printing each hop. It is the single best way to see where resolution breaks and to understand how DNS is stitched together.
AğReadReading a curl Command
A curl command is a shell command: the word curl, a set of options, and a URL. Reading it means seeing how the shell splits the line first (quotes, backslashes, line continuations) and then how curl reads short, long, and clustered flags.
AğWeb & HTTPReadcurl Data Flags and the Content-Type Trap
curl has several ways to attach a body, and they differ in encoding and default Content-Type. The big surprise is that -d defaults to form encoding, not JSON, so a JSON body can be mislabeled and rejected.
AğWeb & HTTPReadTranslating curl to fetch()
The browser fetch API and curl describe the same request differently. Method, headers, and body map across cleanly, but a couple of differences (implicit form Content-Type, cookies, and TLS verification) need care.
AğWeb & HTTPReadHeaders, Authentication, and Cookies in curl
Headers, auth, and cookies are how a request identifies and authorizes itself. -H adds headers, -u is HTTP Basic, a bearer token is just a header, and -b/-c handle cookies. All of them are sensitive.
AğWeb & HTTPReadHow curl Infers the HTTP Method
curl does not always need -X to choose a method. Body data implies POST, -I implies HEAD, -G forces GET, and an explicit -X always wins. Knowing the rules tells you at a glance what a request will do.
AğWeb & HTTPReadcurl Flags That Change Security Posture
A few curl flags change how safe a request is: -k disables TLS verification, http sends everything in clear text, and credentials in the URL can leak. None make a request malicious, but each is worth reading before you run or share a command.
AğWeb & HTTPReadThe TCP Proxy: What a Layer 4 Middlebox Does and Does Not See
A TCP proxy terminates the client's TCP connection and opens a separate one to the server, splicing two independent flows together at Layer 4. It rewrites addresses and ports, can pool and reuse connections, and sees nothing of the application payload above the transport header. This explains full-proxy versus packet-forwarding, why the source IP disappears, and how the Proxy Protocol puts it back.
AğWeb & HTTPReadHTTP Proxies: Forward vs Reverse, Explicit vs Transparent
An HTTP proxy parses requests at Layer 7, so it can route by URL, rewrite headers, and enforce policy on content a TCP proxy cannot see. Two axes describe every deployment: forward vs reverse (which side it works for) and explicit vs transparent (whether the client knows it is there). This covers the CONNECT method, X-Forwarded-For and Via, and where each combination is used.
AğWeb & HTTPReadThe 27 Protocols curl Speaks
curl is known as an HTTP tool, but the current tool speaks 27 URL schemes: file transfer over FTP, SFTP and SMB, mail over SMTP, POP3 and IMAP, MQTT publish-subscribe, LDAP lookups, and relics like Gopher, DICT and Telnet. Knowing the map, and which schemes start in cleartext, changes how you use it.
AğWeb & HTTPReadHTTP/0.9 vs 1.0 vs 1.1 vs 2 vs 3: Five Versions of the Web's Protocol
From a one-line GET that could only fetch HTML to a multiplexed protocol riding QUIC: what each HTTP version added, why it was needed, and which RFC defines it today - including the 2022 reorganization that split HTTP semantics (RFC 9110) from the per-version wire syntax.
AğWeb & HTTPReadAltaVista: built to break a processor, and lost by becoming a portal
AltaVista started as a benchmark. A researcher wanted a workload chaotic enough to stress DEC's new Alpha chips, so he pointed a crawler at the entire web. The result led search for years and then was dismantled by its own owners, which makes it the clearest case study in the industry of losing a market you already have.
AğReadGPON: How One Fiber Serves a Whole Neighborhood
A Gigabit Passive Optical Network runs one strand of glass from the exchange, splits it with unpowered prisms, and shares it among dozens of homes. How the light is divided, why upstream needs a schedule, and where the decibel budget goes.
AğReadJumbo frames: when 1500 bytes stops being enough
Why Ethernet settled on 1500 bytes, what 9000-byte jumbo frames actually buy, where they shine, and how an MTU mismatch turns into a silent black hole.
AğReadHTTP QUERY: the read that finally carries a body
RFC 10008 (June 2026) gave HTTP its first new method since 2010: QUERY is safe, idempotent, and cacheable like GET, but carries a request body like POST. What it fixes, how its caching and discovery work, why 'safe' is not 'harmless', and what every layer of infrastructure must check before QUERY traffic arrives.
AğWeb & HTTPReadThe OSI Model in Practice: Mapping Real Traffic to Seven Layers
The Open Systems Interconnection model earns its place not as trivia but as a shared address system for problems: a MAC address is Layer 2, an IP address Layer 3, a TCP or UDP port Layer 4, and the application on top. How to map real artifacts to layers, where the model bends against TCP/IP reality, and why troubleshooting conversations go faster when everyone points at the same floor.
AğReadSwitch, Router, Firewall: Who Does What on the Path
Three device roles carry most of every network diagram: switches forward frames inside a Layer 2 domain, routers move packets between networks, and firewalls decide what is allowed to pass. The function and purpose of each, how an application delivery controller relates to all three, and how to read a network diagram without getting lost.
AğReadARP and MAC Addresses: How IP Finds Ethernet
Every packet on a local network is delivered by MAC address, and ARP is the directory service that maps an IP to one. The one-to-one mapping, reading ARP output to prove resolution worked, gratuitous ARP, and MAC masquerading - the failover trick that makes an address move without the switches noticing.
AğReadRouting Tables and the Default Gateway: How a Packet Picks Its Next Hop
Why a route is needed at all, what a hop is, and the longest-prefix-match rule that decides which table entry wins - worked through the way the retired fundamentals exam asked: given a destination and a routing table, identify the route to be used. Plus the default route, the entry that answers when nothing else does.
AğReadNAT Explained: Source, Destination, and Why the Internet Still Works
Network Address Translation rewrites addresses in flight - source NAT lets a thousand private hosts share one public address, destination NAT publishes an inside service on an outside address, and the translation table is what makes the return traffic find its way home. The function and purpose, the flavors, and the troubleshooting consequences of each.
AğReadDHCP: the Lease Lifecycle Behind Automatic Addressing
The Dynamic Host Configuration Protocol hands out addresses, gateways, and resolvers so hosts arrive configured instead of blank. The discover-offer-request-acknowledge exchange, what a lease means and how renewal works, relays that carry requests across subnets, and the failure signatures - including the self-assigned address that says no server ever answered.
AğReadThe TCP Connection Lifecycle: Handshake, Teardown, and Why Connections Fail
Every TCP conversation has three acts: the SYN handshake that creates it, the data flow that justifies it, and the FIN or RST that ends it. The difference between polite close and abort, the possible reasons a connection terminates, and the short list of causes when one fails to establish at all - the literacy behind every capture you will ever read.
AğReadVPN Fundamentals: What Tunnels Protect, and What They Don't
A virtual private network wraps traffic in an encrypted tunnel so it crosses untrusted networks as if it never left home. The rationale - privacy, encryption, and the limits of anonymity - the valid uses from site-to-site links to remote access, and the honest boundaries: what a tunnel genuinely protects, and the claims it cannot keep.
AğReadThe Last Mile: From POTS to Always-On
The story of residential connectivity is the story of one stubborn stretch of infrastructure - the last mile - being reinvented four times: the plain old telephone service that carried voices, the ADSL trick that made the same copper pair carry data full-time, the cable plant's DOCSIS second life, and fiber to the home. Why 1999's 256 kbps mattered more than its speed, what always-on actually changed, and how one house can end up served by copper's ghost, coax, glass, and the sky at once.
AğReadPagers and Paging Networks: Reachable Before Real-Time
Before the phone in your pocket, there was the bip on your belt: a one-way radio receiver on a simulcast broadcast network, fed - in its classic form - by a human operator who took your caller's words and typed them into the air. How paging networks actually worked, from two-tone beeps to POCSAG and FLEX, why the operator-relay model meant strangers read your life aloud, and why hospitals kept pagers long after everyone else moved on.
AğReadLEO Constellations: Why the New Satellite Internet Is a Different Animal
Geostationary satellites solved coverage and lost latency: parked at 35,786 km, physics alone charges half a second round trip. Low Earth Orbit constellations invert the deal - satellites a few hundred kilometers up, latency in the tens of milliseconds, at the price of needing thousands of moving satellites, phased-array terminals that track them, and constant handoffs. The geometry, the engineering it forces, inter-satellite laser links, and the honest trade-offs.
AğReadLoRa and LPWAN: Kilometers of Range on a Coin Cell
There is a corner of networking where the requirements invert everything broadband optimizes for: send a few bytes, a few times an hour, kilometers through a city, from a battery that must last years. LPWAN is that corner; LoRa is its best-known citizen - Semtech's chirp spread spectrum radio trading bitrate for astonishing link budgets, and LoRaWAN, the LoRa Alliance's network layer, organizing gateways, device classes, and the duty-cycle etiquette of shared spectrum.
AğReadHTTP Methods: The Verbs of the Web
GET, HEAD, POST, PUT, DELETE, PATCH, OPTIONS, TRACE, CONNECT - and now QUERY. What each method promises, why 'safe' and 'idempotent' are the two properties that actually matter (to caches, retries, proxies, and crawlers), why HTML forms only ever learned two verbs, and how to read an API's soul from the methods it accepts.
AğWeb & HTTPReadHTTP Status Codes: The Five Families
Three digits, and the first one does most of the work: 1xx continues, 2xx succeeds, 3xx redirects, 4xx blames the client, 5xx confesses for the server. The family logic, the codes an operator actually meets (200, 204, 301 vs 302 vs 307, 304's cache dance, 401 vs 403, 404 vs 410, 429, 500 vs 502 vs 503 vs 504), the famous curiosities, and why an unknown code's first digit is always enough to act on.
AğWeb & HTTPReadHTTP Headers: The Anatomy of the Metadata
Everything HTTP knows about a message that isn't the message travels in headers: name-colon-value lines with case-insensitive names, folded into four working roles - request context, response context, representation metadata, and payload plumbing. The end-to-end vs hop-by-hop split that proxies live by, the Host header that made virtual hosting possible, content negotiation, conditionals, and why header order became a fingerprint.
AğWeb & HTTPSecurity & WAFReadHTTP Cookies: State Over a Stateless Protocol
HTTP forgets you after every request - by design. Cookies are the retrofit that lets it remember anyway: the server writes a note with Set-Cookie, the browser returns it with Cookie, and everything else - scope, lifetime, security - is rules about when that note travels. Domain and Path scoping, session vs persistent lifetimes, why the server never sees what the browser knows, and where the security flags article picks up.
AğWeb & HTTPSecurity & WAFReadAJAX, XHR, and fetch: When Pages Learned to Talk Back
For its first decade the web had one move: click, blank screen, new page. XMLHttpRequest gave pages a second one - request data in the background, update in place - and 'AJAX' named the revolution (which promptly dropped the X for JSON). How XHR worked, what fetch fixed (promises, streams, a sane API), what stayed the same underneath (it is all still HTTP), and the boundary every background request answers to: same-origin, with CORS as the negotiated exception.
AğWeb & HTTPReadHTML, CSS, and the DOM: The Page as a Living Tree
Three technologies, one division of labor: HTML declares structure, CSS declares presentation, and the DOM is what actually exists at runtime - the tree the browser built from your HTML, the only thing scripts can touch, and the reason 'view source' and 'inspect element' show different worlds. How markup becomes a tree, how selectors address it (the same selectors CSS styles with and scripts query with), and why the DOM is where XSS happens and where CSP stands guard.
AğSecurity & WAFReadWhat Is an Algorithm? A Working Primer
An algorithm is a finite, unambiguous recipe that turns input into output - and the engineering questions are always the same three: is it correct, how does its cost grow, and what does it trade away. Big-O as the grammar of growth, why constants and asymptotes both matter, the core families you already operate (search, sort, hash, graph, state machines), and where each one is already running inside this site's own tools.
AğWeb & HTTPHash ve kriptoReadThe IEEE 802 family, group by group
802 is not one standard but a committee of working groups, each owning a slice of the lower two layers. Here is the map: who owns Ethernet, who owns Wi-Fi, what the numbers after the dot mean, and which groups are alive, hibernating, or long dead.
AğReadStructured cabling: the system behind the wall jack
TIA-568 turns a building's wiring from improvisation into a system: horizontal runs, telecom rooms, the 100-meter channel, categories, pinouts, and the fire ratings inspectors actually check. The map from wall plate to backbone.
AğReadBGP: how the internet decides where traffic goes
The Border Gateway Protocol is the internet's routing brain - and it works nothing like the routing inside your network. A practical primer: autonomous systems, the path-vector idea, the attributes that encode business policy, why convergence is slow on purpose, and what RPKI fixes.
AğReadOSPF: the map, the math, and area 0
Open Shortest Path First is the standard interior routing protocol: every router gets the whole map and runs Dijkstra on it. A practical primer: link-state flooding, areas and the backbone rule, cost and the reference-bandwidth trap, DR elections, and the design habits that keep OSPF boring.
AğReadIS-IS: the routing protocol hiding under the internet
OSPF's link-state twin from the OSI world runs the carrier backbones your packets cross daily - and most engineers have never typed its name. A practical primer: the layer-2 trick, NET addresses, levels instead of areas, TLV extensibility, and why the big networks never left.
AğReadMPLS: labels, stacks, and the BGP-free core
Push a label at the edge, swap it hop by hop, pop it before the exit - and suddenly the core needs no routing table, VPNs isolate thousands of customers, and traffic goes where engineering says. A practical primer on label switching, L3VPNs, and the Segment Routing present.
AğReadPeer-to-peer, from Napster to the swarm: the architectures that outlived the piracy
Napster, Gnutella, Kazaa, eMule, BitTorrent - four years of file-sharing produced five distinct network architectures, each solving the weakness the last one died from. The centralized index, unstructured flooding, the supernode, the distributed hash table, and the swarm - what each actually was, how the courtroom shaped the topology, and why these ideas quietly power Skype, streaming CDNs, and blockchains today.
AğReadThe Brazilian market reserve, in theory and in practice
For eight years Brazil legally reserved its computer market for domestically-owned companies. The theory was an infant industry that would grow up and compete. The practice was clones, smuggling, a trade war with Washington, and a generation of engineers who learned on machines the policy created. Both halves are true.
AğReadDigital transformation: what actually changed, and how to read what comes next
Transformation is not the technology arriving. It is the moment a capability stops being remarkable and becomes assumed. A look at what genuinely changed across money, work, health, and the state, and then an honest method for reading predictions, including a deadline that is real and moving at the same time.
AğOperations & FieldcraftReadHow the internet gets shut down, and who can actually do it
There is no off switch, but there are chokepoints: cables, routing, exchanges, and the small number of companies most traffic passes through. A tour of the mechanisms, what each state can genuinely do with them, and the uncomfortable conclusion that watching everything is easier than switching anything off.
AğReadWho actually governs the internet in Brazil
Brazil built one of the world's most distinctive internet governance models: multistakeholder before that was a word, with a research foundation running the country's first connection and a committee that is not a ministry. The organs, the laws, the state computing backbone underneath it all, and the 2025 ruling that rewrote platform liability.
AğReadAmateur radio: callsigns, modes, and why it still matters
A callsign is an identity issued by treaty, readable anywhere on earth. What the letters and the digit mean, how PY2 says São Paulo, the difference between voice and CW and digital, what a repeater actually does, and why a hobby older than broadcasting is still the fallback when everything else fails.
AğReadThe data communications window, 1968 to 1972
A regulator opened a market. The Carterfone decision let equipment AT&T had not built attach to the telephone network, and within four years an industry of modem and multiplexer companies existed that could not have existed before. The trigger, the window, the products that defined it, and why it closed.
AğReadThe networking window, 1979 to 1982
Corporations had bought computers for a decade and now needed them to talk to each other inside a building. The window that opened around 1979 produced local area networks and the data PBX, settled a contest between two answers to the same problem, and closed once the answer was obvious.
AğReadThe radio spectrum: which frequencies go how far, and why
Why a shortwave signal crosses an ocean on 100 watts while your Wi-Fi struggles through a wall. The bands from VLF to EHF, the three propagation modes that explain nearly everything, and the trade that governs all radio: reach or capacity, never both.
AğReadThe internetworking window, 1984 to 1988
The previous window's success created this one's problem: buildings full of local area networks that could not reach each other. Bridges and routers answered it, a standards war ran alongside, and two trade shows in 1988 made the outcome visible before the argument was formally over.
AğReadThe two shows of 1988
One trade show put competing vendors' equipment on a single live network in public, where failure would be seen. The other showed an ecosystem that was largely described rather than shipped. The standards argument was formally undecided and a buyer walking both floors did not need it settled.
AğReadThe founders who kept founding
Reading this industry as a sequence of companies misses that it is substantially the same population of people, recombining. Ungermann left Intel for Zilog and Zilog for Ungermann-Bass; Metcalfe left Xerox for 3Com. What that pattern explains, and what it does not.
AğReadBFD: when a link is up and dead at the same time
Routing protocols detect failure with their own timers, measured in tens of seconds. BFD detects it in milliseconds, and exists because the most dangerous link failure is the one where the interface stays up. What it does, what it does not do, and where it goes wrong.
AğReadFirst-hop redundancy: VRRP, HSRP, and the gateway that is a fiction
A host knows one default gateway and cannot fail over. VRRP and HSRP solve that by making the gateway address belong to a role rather than to a router. How they work, why the protocol choice matters less than people think, and the failure modes that make a redundant pair worse than a single router.
AğReadMulticast: what it costs to not flood
Multicast sends one copy where unicast would send thousands, and the saving is real. What it buys in bandwidth it pays for in state, and the failure modes are not the ones people expect: a network that floods multicast everywhere is usually working exactly as configured.
AğReadPublic DNS resolvers: what you are actually choosing
Cloudflare, Google, Quad9, OpenDNS and the rest differ far less in speed than in policy. What each one does with your queries, which ones block by default, why anycast makes 'nearest' complicated, and the trade nobody states: the resolver that protects you also sees everything you ask for.
AğReadFortiGate as a DNS server: four modes, and where the filter applies
A FortiGate can relay DNS, answer from its own database, or resolve from the root itself. The four modes behave differently under failure, and the DNS filter profile does not apply to all of them - which is the configuration that looks protected and is not.
AğRead
| Article | Topic | Summary |
|---|---|---|
| IPv4 adresleri nasıl çalışır | Ağ | Her noktalı-dörtlü adresin arkasındaki 32 bit ve özel, loopback ve özel aralıkların ne anlama geldiği. |
| The Syslog PRI: One Number, Two Meanings | Ağ | Every syslog message starts with a PRI, a number in angle brackets that packs a facility and a severity into a single value. The formula is small and the arithmetic is easy once you have seen it: PRI equals facility times eight plus severity. |
| Alt ağ oluşturmanın temelleri | Ağ | Bir ağı nasıl daha küçük alt ağlara böleceğiniz ve ana bilgisayar bitlerini ödünç almanın neden tüm hilenin kendisi olduğu. |
| Syslog Facilities and Severities, Explained | Ağ | Syslog defines 24 facilities and 8 severities. The severities are a clean urgency scale from emergency down to debug; the facilities are a mix of genuinely useful categories and historical Unix leftovers, plus eight local slots that network devices lean on heavily. |
| CIDR notasyonu açıklandı | Ağ | 192.168.1.0/24'teki eğik çizginin aslında ne anlama geldiği ve bir önek uzunluğunun bir IP adresleri bloğunu nasıl tanımladığı. |
| Syslog on Network Devices: Which Facility Does What | Ağ | Firewalls, load balancers, and switches almost all log to the local facilities, but each vendor picks a different default. Knowing that FortiGate defaults to local7, Cisco ASA to local4, and F5 BIG-IP to local0 turns a wall of PRI numbers into a map of which box said what. |
| Syslog Message Formats: RFC 3164 vs RFC 5424 | Ağ | The PRI is the same everywhere, but what follows it is not. Legacy BSD syslog (RFC 3164) has a loose, year-less format, while the modern format (RFC 5424) is precise and structured. Knowing which one you are looking at explains missing timestamps, ambiguous fields, and why parsers disagree. |
| VLSM: bir bloğu eşit olmayan alt ağlara bölme | Ağ | Bir adres bloğunu yer israf etmeden farklı boyutlardaki alt ağlara nasıl keseceğiniz ve her şeyi düzenli tutan önce-en-büyük kuralı. |
| Baştan sona çözülmüş bir VLSM ataması | Ağ | Gerçekçi bir ağ için değişken uzunluklu alt ağların eksiksiz bir ataması: her segmenti boyutlandırma, en büyükten en küçüğe sıralama, gerçek adresleri atama ve geriye kalan alanı hesaba katma. |
| How Syslog Travels: UDP, TCP, and TLS | Ağ | Syslog can ride over plain UDP, over TCP, or over TLS, and the choice decides whether messages can be silently lost, reordered, or read in transit. This covers the three transports, the ports involved, and why anything you rely on for audit should not be sent over UDP. |
| The First Hour: Hypothesis-Driven Fault Isolation | AğOperations & Fieldcraft | The difference between a two-hour incident and a two-day one is usually decided in the first hour, and it is rarely decided by tools. It is decided by method: aligning onset with change, isolating by scope, reading layer signatures, and treating every explanation as a hypothesis that evidence must support or weaken before anyone acts on it. |
| Üst ağ oluşturma ve rota toplama | Ağ | Bitişik öneklerin nasıl tek bir daha kısa önekte birleştiği, iki bloğun birleşip birleşemeyeceğini belirleyen hizalama kuralı ve tam toplama ile bunları kapsayan tek bir üst ağ arasındaki fark. |
| Change Windows That Do Not Become Incidents | AğOperations & Fieldcraft | Most self-inflicted outages are changes that went wrong with no clean way back. The difference between a change and an incident is rarely the change itself; it is the runbook around it - what you verified before, how you sequenced it, what would make you stop, and whether the way back was written down and tested before you needed it. |
| Rota özetleme | Ağ | Tek bir özet rotanın neden birçok belirli rotanın yerini alabileceği, bağlı olduğu bitişik ve hizalanmış atama ve tam sahip olmadığınız bir aralığı özetlerken kara delik riski. |
| Alt ağ çakışmaları ve boşlukları | Ağ | İki önekin çakışmasının veya birinin diğerini içermesinin ne anlama geldiği, en uzun önek eşleşmesinin bazı çakışmaları neden kasıtlı kıldığı ve bir adres planının atanmamış boşluklarının nasıl bulunacağı. |
| Root Cause Is a Verb, Not a Noun | AğOperations & Fieldcraft | The phrase root cause invites a single villain and a tidy ending. Real incidents rarely have one; they have contributing factors, and the honest work is structuring the candidates and the evidence that would confirm or rule out each - not naming a culprit before the evidence is in. |
| Blast-Radius Thinking Before You Change Anything | AğOperations & Fieldcraft | Before a change, the question is not only will this work but if it goes wrong, how far does the damage reach. Blast radius is the shape of that reach - target, neighbours, dependents, people - and thinking about it in tiers is how you decide what to contain before you touch anything. |
| Özel IPv4 adres alanı ve RFC 1918 | Ağ | Üç özel aralık, neden internette yönlendirilemedikleri ve CIDR aracının işaretlediği diğer özel bloklar. |
| IPv6 adreslemesini anlamak | Ağ | 128 bitlik bir IPv6 adresinin nasıl yapılandırıldığı ve yazıldığı, onu kanonik biçimde sıkıştırma kuralları, adres türlerinin ve kapsamların ne anlama geldiği, ve arabirim tanımlayıcıları ile ters DNS'in nasıl çalıştığı. |
| TAC Cases That Get Triaged Fast | AğOperations & Fieldcraft | The slowest support cases are rarely the hardest problems; they are the ones that opened without the diagnostic the vendor needs. A case that arrives complete - clear problem, exact error, the diagnostic bundle, the impact - skips the round trips and starts with an engineer actually working it. |
| IPv6 ana bilgisayarları adresleri nasıl alır: SLAAC ve DHCPv6 | Ağ | Bir IPv6 ana bilgisayarının link-local'den yukarıya kendini nasıl yapılandırdığı, yönlendirici duyurularının neye karar verdiği, ve SLAAC, gizlilik adresleri ile DHCPv6 arasındaki fark. |
| Capture Points Before Packets | AğOperations & Fieldcraft | The instinct under pressure is to start tcpdump somewhere convenient and stare at the flood. The senior habit is the opposite: decide where to observe, in what order, and what each observation would mean - before a single packet is collected. Evidence is designed, not fished for. |
| IPv6 alt ağ oluşturma ve /64 sınırı | Ağ | IPv6 alt ağ oluşturmanın neden kıtlık yerine yapı hakkında olduğu, tek bir alt ağın neden neredeyse her zaman bir /64 olduğu ve önek devrinin adres alanını nasıl dağıttığı. |
| Public suffixes and the registered domain (eTLD+1) | AğSertifikalar ve PKI | What a public suffix (eTLD) and a registered domain (eTLD+1) are, why you cannot compute them by taking the last two labels, how the Public Suffix List algorithm resolves them, and where the boundary matters: certificate rate limits, cookies, and same-site. |
| Komşu Keşfi: IPv6 ARP'yi nasıl değiştirir | Ağ | IPv6'nın bir bağlantıda komşuları yayın ARP yerine ICMPv6 ve çok noktaya yayın kullanarak nasıl bulduğu, beş Komşu Keşfi mesajı, ve yayının neden gittiği. |
| Map the Path Before You Troubleshoot | AğOperations & Fieldcraft | The most expensive troubleshooting sessions share one flaw: nobody actually knew the path. The senior habit is refusing to reason about a failure until the chain is modeled - resolution included, return leg separate, every rewrite and TLS boundary named, and every unknown left visibly unknown. |
| Baselines Before You Need Them | AğOperations & Fieldcraft | Every comparison is only as honest as its weaker side. The discipline is captured baselines before changes, declared confidence instead of remembered health, observation windows that let convergence speak, churn literacy for the counters that always move - and never calling a change successful on green components alone. |
| IPv6 ve IPv4'ü birlikte çalıştırmak: dual-stack ve çeviri | Ağ | İnternetin iki uyumsuz adres ailesi arasında nasıl köprü kurduğu: dual-stack, Happy Eyeballs, NAT64, ve bunu işler kılan IPv4-gömülü adresler. |
| What Is an OUI, and How MAC Addresses Are Assigned | Ağ | How a MAC address is structured, what the OUI (the manufacturer prefix) is and who hands it out, the difference between universally and locally administered addresses, and why a randomized Wi-Fi MAC has no vendor at all. |
| Fabric Connect and SPBM: Why VOSS Retires Spanning Tree | Ağ | What Extreme's Fabric Connect actually is - Shortest Path Bridging MAC (SPBM, IEEE 802.1aq) with an IS-IS control plane and a MAC-in-MAC data plane - and why collapsing the core to a single link-state protocol replaces spanning tree and the usual overlay stack. |
| Reading dig Output From Top to Bottom | Ağ | A dig answer has a fixed shape: a version line, the header, the flags line, the OPT pseudo-section, the four sections, and the query stats. Once you know what each block is, you can read any response at a glance and spot the one line that explains a resolution problem. |
| The DNS Header: Opcode, Status, and Flags | Ağ | The header line and the flags line hold the message-level facts: what kind of query this is, whether it succeeded, and seven single-bit flags (qr, aa, tc, rd, ra, ad, cd) that tell you who answered and how. Reading them correctly is the difference between a two-minute diagnosis and an hour of guessing. |
| The I-SID: How VOSS Replaces VLAN Stretching | Ağ | Why Extreme's Fabric Connect provisions services at the edge instead of trunking VLANs hop by hop, what the 24-bit I-SID is, and how Layer 2 VSN, Layer 3 VSN, and IP Shortcuts all ride the same mechanism over an SPBM MAC-in-MAC core. |
| IS-IS, Nicknames, and B-MACs: The VOSS Control Plane | Ağ | How SPBM uses IS-IS as its single link-state control plane on fabric links only, what a 20-bit node nickname is and why it must be unique, and how the system-id / backbone MAC drives MAC-in-MAC forwarding. |
| Reading the Records in a dig Answer | Ağ | Every record in a dig section is five columns: name, TTL, class, type, and rdata. This walks the columns and then the rdata of the record types you actually meet, from A and CNAME to MX, SOA, SRV, and CAA, so a wall of records reads as plain facts. |
| EDNS and the OPT Pseudo-Section | Ağ | The OPT pseudo-section is not a record and not something you queried: it is EDNS(0) metadata that dig surfaces near the top of an answer. It carries the UDP payload size, the DO flag that requests DNSSEC, and options like COOKIE, and it quietly explains a whole class of resolution failures. |
| Fabric Attach: Auto-Provisioning the Edge (Where VOSS Meets EXOS) | Ağ | How Fabric Attach lets an edge device signal the service it needs so the fabric provisions the I-SID automatically, the FA Server / Proxy / Client roles, how it rides LLDP (Link Layer Discovery Protocol), and how an EXOS switch attaches to a VOSS fabric without running SPBM itself. |
| DNSSEC Records in dig Output | Ağ | Add +dnssec and a dig answer grows a new family of records: RRSIG, DNSKEY, DS, and the NSEC or NSEC3 denial records. This explains what each one is, how they chain from the root down to a zone, and what the ad flag really certifies. |
| VOSS vs EXOS: Two Extreme Operating Systems | Ağ | Extreme ships universal hardware that boots either EXOS or VOSS (Fabric Engine). This is what actually differs - a traditional-Ethernet OS with an intuitive CLI versus a fabric-native OS built on SPBM - and the three boundaries at which they interconnect. |
| Reading nslookup Output | Ağ | nslookup prints a Server / Address header for the resolver it used, an optional Non-authoritative answer marker, and then the answer in a per-type prose format. Knowing that shape lets you read any result quickly and see at a glance whether it succeeded, where it came from, and what it means. |
| SMLT and vIST: Dual-Homing a Fabric Edge | Ağ | How Split MultiLink Trunking dual-homes an edge device to a pair of switches with active-active links and no spanning tree, how virtual IST runs the inter-switch trunk through the SPBM fabric itself, and the smlt-peer-system-id and smlt-virtual-bmac that make the cluster one logical node. |
| nslookup vs dig: Which to Use | Ağ | nslookup and dig both query DNS, but nslookup is terser and hides the header flags and TTLs that dig shows in full. This maps one output onto the other and gives a simple rule for which to reach for. |
| How nslookup Prints Each Record Type | Ağ | Instead of dig's fixed columns, nslookup labels each record in prose: mail exchanger =, canonical name =, nameserver =, and a multi-line block for SOA. A short guide to reading each type's line. |
| Authoritative vs Non-Authoritative Answers | Ağ | The Non-authoritative answer marker in nslookup means the result came from a resolver's cache, not from a server that actually holds the zone. This explains the difference, why it is usually fine, and how to get an authoritative answer when you need one. |
| nslookup Errors and What They Mean | Ağ | When a lookup fails, nslookup prints a line like ** server can't find NAME: CODE. The code is the whole diagnosis. This covers NXDOMAIN, SERVFAIL, REFUSED, and timeouts, what each one tells you, and the first thing to check for each. |
| Reverse DNS Lookups with nslookup | Ağ | Reverse DNS maps an IP address back to a name through PTR records that live under in-addr.arpa for IPv4 and ip6.arpa for IPv6. nslookup does this automatically when you hand it an address. This covers how the special reverse name is built, why mail servers care, and why the forward and reverse can legitimately disagree. |
| nslookup Interactive Mode | Ağ | Run nslookup with no arguments and it drops into an interactive prompt where you can switch resolvers, change the record type, turn on debug output, and look up many names in one session. This covers the handful of commands worth knowing and when interactive beats a one-shot query. |
| dig Query Options and Output Control | Ağ | dig's real power is its options: choosing the server to ask, the record type, and exactly how much of the answer to print. This covers the handful you will actually use every day, from @server and -t to +short and the +noall +answer combination that trims dig down to just the records. |
| Following Delegation with dig +trace | Ağ | dig +trace resolves a name the way the internet actually does it: starting at the root, following the delegation to the TLD, and then to the domain's own authoritative servers, printing each hop. It is the single best way to see where resolution breaks and to understand how DNS is stitched together. |
| Reading a curl Command | AğWeb & HTTP | A curl command is a shell command: the word curl, a set of options, and a URL. Reading it means seeing how the shell splits the line first (quotes, backslashes, line continuations) and then how curl reads short, long, and clustered flags. |
| curl Data Flags and the Content-Type Trap | AğWeb & HTTP | curl has several ways to attach a body, and they differ in encoding and default Content-Type. The big surprise is that -d defaults to form encoding, not JSON, so a JSON body can be mislabeled and rejected. |
| Translating curl to fetch() | AğWeb & HTTP | The browser fetch API and curl describe the same request differently. Method, headers, and body map across cleanly, but a couple of differences (implicit form Content-Type, cookies, and TLS verification) need care. |
| Headers, Authentication, and Cookies in curl | AğWeb & HTTP | Headers, auth, and cookies are how a request identifies and authorizes itself. -H adds headers, -u is HTTP Basic, a bearer token is just a header, and -b/-c handle cookies. All of them are sensitive. |
| How curl Infers the HTTP Method | AğWeb & HTTP | curl does not always need -X to choose a method. Body data implies POST, -I implies HEAD, -G forces GET, and an explicit -X always wins. Knowing the rules tells you at a glance what a request will do. |
| curl Flags That Change Security Posture | AğWeb & HTTP | A few curl flags change how safe a request is: -k disables TLS verification, http sends everything in clear text, and credentials in the URL can leak. None make a request malicious, but each is worth reading before you run or share a command. |
| The TCP Proxy: What a Layer 4 Middlebox Does and Does Not See | AğWeb & HTTP | A TCP proxy terminates the client's TCP connection and opens a separate one to the server, splicing two independent flows together at Layer 4. It rewrites addresses and ports, can pool and reuse connections, and sees nothing of the application payload above the transport header. This explains full-proxy versus packet-forwarding, why the source IP disappears, and how the Proxy Protocol puts it back. |
| HTTP Proxies: Forward vs Reverse, Explicit vs Transparent | AğWeb & HTTP | An HTTP proxy parses requests at Layer 7, so it can route by URL, rewrite headers, and enforce policy on content a TCP proxy cannot see. Two axes describe every deployment: forward vs reverse (which side it works for) and explicit vs transparent (whether the client knows it is there). This covers the CONNECT method, X-Forwarded-For and Via, and where each combination is used. |
| The 27 Protocols curl Speaks | AğWeb & HTTP | curl is known as an HTTP tool, but the current tool speaks 27 URL schemes: file transfer over FTP, SFTP and SMB, mail over SMTP, POP3 and IMAP, MQTT publish-subscribe, LDAP lookups, and relics like Gopher, DICT and Telnet. Knowing the map, and which schemes start in cleartext, changes how you use it. |
| HTTP/0.9 vs 1.0 vs 1.1 vs 2 vs 3: Five Versions of the Web's Protocol | AğWeb & HTTP | From a one-line GET that could only fetch HTML to a multiplexed protocol riding QUIC: what each HTTP version added, why it was needed, and which RFC defines it today - including the 2022 reorganization that split HTTP semantics (RFC 9110) from the per-version wire syntax. |
| AltaVista: built to break a processor, and lost by becoming a portal | Ağ | AltaVista started as a benchmark. A researcher wanted a workload chaotic enough to stress DEC's new Alpha chips, so he pointed a crawler at the entire web. The result led search for years and then was dismantled by its own owners, which makes it the clearest case study in the industry of losing a market you already have. |
| GPON: How One Fiber Serves a Whole Neighborhood | Ağ | A Gigabit Passive Optical Network runs one strand of glass from the exchange, splits it with unpowered prisms, and shares it among dozens of homes. How the light is divided, why upstream needs a schedule, and where the decibel budget goes. |
| Jumbo frames: when 1500 bytes stops being enough | Ağ | Why Ethernet settled on 1500 bytes, what 9000-byte jumbo frames actually buy, where they shine, and how an MTU mismatch turns into a silent black hole. |
| HTTP QUERY: the read that finally carries a body | AğWeb & HTTP | RFC 10008 (June 2026) gave HTTP its first new method since 2010: QUERY is safe, idempotent, and cacheable like GET, but carries a request body like POST. What it fixes, how its caching and discovery work, why 'safe' is not 'harmless', and what every layer of infrastructure must check before QUERY traffic arrives. |
| The OSI Model in Practice: Mapping Real Traffic to Seven Layers | Ağ | The Open Systems Interconnection model earns its place not as trivia but as a shared address system for problems: a MAC address is Layer 2, an IP address Layer 3, a TCP or UDP port Layer 4, and the application on top. How to map real artifacts to layers, where the model bends against TCP/IP reality, and why troubleshooting conversations go faster when everyone points at the same floor. |
| Switch, Router, Firewall: Who Does What on the Path | Ağ | Three device roles carry most of every network diagram: switches forward frames inside a Layer 2 domain, routers move packets between networks, and firewalls decide what is allowed to pass. The function and purpose of each, how an application delivery controller relates to all three, and how to read a network diagram without getting lost. |
| ARP and MAC Addresses: How IP Finds Ethernet | Ağ | Every packet on a local network is delivered by MAC address, and ARP is the directory service that maps an IP to one. The one-to-one mapping, reading ARP output to prove resolution worked, gratuitous ARP, and MAC masquerading - the failover trick that makes an address move without the switches noticing. |
| Routing Tables and the Default Gateway: How a Packet Picks Its Next Hop | Ağ | Why a route is needed at all, what a hop is, and the longest-prefix-match rule that decides which table entry wins - worked through the way the retired fundamentals exam asked: given a destination and a routing table, identify the route to be used. Plus the default route, the entry that answers when nothing else does. |
| NAT Explained: Source, Destination, and Why the Internet Still Works | Ağ | Network Address Translation rewrites addresses in flight - source NAT lets a thousand private hosts share one public address, destination NAT publishes an inside service on an outside address, and the translation table is what makes the return traffic find its way home. The function and purpose, the flavors, and the troubleshooting consequences of each. |
| DHCP: the Lease Lifecycle Behind Automatic Addressing | Ağ | The Dynamic Host Configuration Protocol hands out addresses, gateways, and resolvers so hosts arrive configured instead of blank. The discover-offer-request-acknowledge exchange, what a lease means and how renewal works, relays that carry requests across subnets, and the failure signatures - including the self-assigned address that says no server ever answered. |
| The TCP Connection Lifecycle: Handshake, Teardown, and Why Connections Fail | Ağ | Every TCP conversation has three acts: the SYN handshake that creates it, the data flow that justifies it, and the FIN or RST that ends it. The difference between polite close and abort, the possible reasons a connection terminates, and the short list of causes when one fails to establish at all - the literacy behind every capture you will ever read. |
| VPN Fundamentals: What Tunnels Protect, and What They Don't | Ağ | A virtual private network wraps traffic in an encrypted tunnel so it crosses untrusted networks as if it never left home. The rationale - privacy, encryption, and the limits of anonymity - the valid uses from site-to-site links to remote access, and the honest boundaries: what a tunnel genuinely protects, and the claims it cannot keep. |
| The Last Mile: From POTS to Always-On | Ağ | The story of residential connectivity is the story of one stubborn stretch of infrastructure - the last mile - being reinvented four times: the plain old telephone service that carried voices, the ADSL trick that made the same copper pair carry data full-time, the cable plant's DOCSIS second life, and fiber to the home. Why 1999's 256 kbps mattered more than its speed, what always-on actually changed, and how one house can end up served by copper's ghost, coax, glass, and the sky at once. |
| Pagers and Paging Networks: Reachable Before Real-Time | Ağ | Before the phone in your pocket, there was the bip on your belt: a one-way radio receiver on a simulcast broadcast network, fed - in its classic form - by a human operator who took your caller's words and typed them into the air. How paging networks actually worked, from two-tone beeps to POCSAG and FLEX, why the operator-relay model meant strangers read your life aloud, and why hospitals kept pagers long after everyone else moved on. |
| LEO Constellations: Why the New Satellite Internet Is a Different Animal | Ağ | Geostationary satellites solved coverage and lost latency: parked at 35,786 km, physics alone charges half a second round trip. Low Earth Orbit constellations invert the deal - satellites a few hundred kilometers up, latency in the tens of milliseconds, at the price of needing thousands of moving satellites, phased-array terminals that track them, and constant handoffs. The geometry, the engineering it forces, inter-satellite laser links, and the honest trade-offs. |
| LoRa and LPWAN: Kilometers of Range on a Coin Cell | Ağ | There is a corner of networking where the requirements invert everything broadband optimizes for: send a few bytes, a few times an hour, kilometers through a city, from a battery that must last years. LPWAN is that corner; LoRa is its best-known citizen - Semtech's chirp spread spectrum radio trading bitrate for astonishing link budgets, and LoRaWAN, the LoRa Alliance's network layer, organizing gateways, device classes, and the duty-cycle etiquette of shared spectrum. |
| HTTP Methods: The Verbs of the Web | AğWeb & HTTP | GET, HEAD, POST, PUT, DELETE, PATCH, OPTIONS, TRACE, CONNECT - and now QUERY. What each method promises, why 'safe' and 'idempotent' are the two properties that actually matter (to caches, retries, proxies, and crawlers), why HTML forms only ever learned two verbs, and how to read an API's soul from the methods it accepts. |
| HTTP Status Codes: The Five Families | AğWeb & HTTP | Three digits, and the first one does most of the work: 1xx continues, 2xx succeeds, 3xx redirects, 4xx blames the client, 5xx confesses for the server. The family logic, the codes an operator actually meets (200, 204, 301 vs 302 vs 307, 304's cache dance, 401 vs 403, 404 vs 410, 429, 500 vs 502 vs 503 vs 504), the famous curiosities, and why an unknown code's first digit is always enough to act on. |
| HTTP Headers: The Anatomy of the Metadata | AğWeb & HTTPSecurity & WAF | Everything HTTP knows about a message that isn't the message travels in headers: name-colon-value lines with case-insensitive names, folded into four working roles - request context, response context, representation metadata, and payload plumbing. The end-to-end vs hop-by-hop split that proxies live by, the Host header that made virtual hosting possible, content negotiation, conditionals, and why header order became a fingerprint. |
| HTTP Cookies: State Over a Stateless Protocol | AğWeb & HTTPSecurity & WAF | HTTP forgets you after every request - by design. Cookies are the retrofit that lets it remember anyway: the server writes a note with Set-Cookie, the browser returns it with Cookie, and everything else - scope, lifetime, security - is rules about when that note travels. Domain and Path scoping, session vs persistent lifetimes, why the server never sees what the browser knows, and where the security flags article picks up. |
| AJAX, XHR, and fetch: When Pages Learned to Talk Back | AğWeb & HTTP | For its first decade the web had one move: click, blank screen, new page. XMLHttpRequest gave pages a second one - request data in the background, update in place - and 'AJAX' named the revolution (which promptly dropped the X for JSON). How XHR worked, what fetch fixed (promises, streams, a sane API), what stayed the same underneath (it is all still HTTP), and the boundary every background request answers to: same-origin, with CORS as the negotiated exception. |
| HTML, CSS, and the DOM: The Page as a Living Tree | AğSecurity & WAF | Three technologies, one division of labor: HTML declares structure, CSS declares presentation, and the DOM is what actually exists at runtime - the tree the browser built from your HTML, the only thing scripts can touch, and the reason 'view source' and 'inspect element' show different worlds. How markup becomes a tree, how selectors address it (the same selectors CSS styles with and scripts query with), and why the DOM is where XSS happens and where CSP stands guard. |
| What Is an Algorithm? A Working Primer | AğWeb & HTTPHash ve kripto | An algorithm is a finite, unambiguous recipe that turns input into output - and the engineering questions are always the same three: is it correct, how does its cost grow, and what does it trade away. Big-O as the grammar of growth, why constants and asymptotes both matter, the core families you already operate (search, sort, hash, graph, state machines), and where each one is already running inside this site's own tools. |
| The IEEE 802 family, group by group | Ağ | 802 is not one standard but a committee of working groups, each owning a slice of the lower two layers. Here is the map: who owns Ethernet, who owns Wi-Fi, what the numbers after the dot mean, and which groups are alive, hibernating, or long dead. |
| Structured cabling: the system behind the wall jack | Ağ | TIA-568 turns a building's wiring from improvisation into a system: horizontal runs, telecom rooms, the 100-meter channel, categories, pinouts, and the fire ratings inspectors actually check. The map from wall plate to backbone. |
| BGP: how the internet decides where traffic goes | Ağ | The Border Gateway Protocol is the internet's routing brain - and it works nothing like the routing inside your network. A practical primer: autonomous systems, the path-vector idea, the attributes that encode business policy, why convergence is slow on purpose, and what RPKI fixes. |
| OSPF: the map, the math, and area 0 | Ağ | Open Shortest Path First is the standard interior routing protocol: every router gets the whole map and runs Dijkstra on it. A practical primer: link-state flooding, areas and the backbone rule, cost and the reference-bandwidth trap, DR elections, and the design habits that keep OSPF boring. |
| IS-IS: the routing protocol hiding under the internet | Ağ | OSPF's link-state twin from the OSI world runs the carrier backbones your packets cross daily - and most engineers have never typed its name. A practical primer: the layer-2 trick, NET addresses, levels instead of areas, TLV extensibility, and why the big networks never left. |
| MPLS: labels, stacks, and the BGP-free core | Ağ | Push a label at the edge, swap it hop by hop, pop it before the exit - and suddenly the core needs no routing table, VPNs isolate thousands of customers, and traffic goes where engineering says. A practical primer on label switching, L3VPNs, and the Segment Routing present. |
| Peer-to-peer, from Napster to the swarm: the architectures that outlived the piracy | Ağ | Napster, Gnutella, Kazaa, eMule, BitTorrent - four years of file-sharing produced five distinct network architectures, each solving the weakness the last one died from. The centralized index, unstructured flooding, the supernode, the distributed hash table, and the swarm - what each actually was, how the courtroom shaped the topology, and why these ideas quietly power Skype, streaming CDNs, and blockchains today. |
| The Brazilian market reserve, in theory and in practice | Ağ | For eight years Brazil legally reserved its computer market for domestically-owned companies. The theory was an infant industry that would grow up and compete. The practice was clones, smuggling, a trade war with Washington, and a generation of engineers who learned on machines the policy created. Both halves are true. |
| Digital transformation: what actually changed, and how to read what comes next | AğOperations & Fieldcraft | Transformation is not the technology arriving. It is the moment a capability stops being remarkable and becomes assumed. A look at what genuinely changed across money, work, health, and the state, and then an honest method for reading predictions, including a deadline that is real and moving at the same time. |
| How the internet gets shut down, and who can actually do it | Ağ | There is no off switch, but there are chokepoints: cables, routing, exchanges, and the small number of companies most traffic passes through. A tour of the mechanisms, what each state can genuinely do with them, and the uncomfortable conclusion that watching everything is easier than switching anything off. |
| Who actually governs the internet in Brazil | Ağ | Brazil built one of the world's most distinctive internet governance models: multistakeholder before that was a word, with a research foundation running the country's first connection and a committee that is not a ministry. The organs, the laws, the state computing backbone underneath it all, and the 2025 ruling that rewrote platform liability. |
| Amateur radio: callsigns, modes, and why it still matters | Ağ | A callsign is an identity issued by treaty, readable anywhere on earth. What the letters and the digit mean, how PY2 says São Paulo, the difference between voice and CW and digital, what a repeater actually does, and why a hobby older than broadcasting is still the fallback when everything else fails. |
| The data communications window, 1968 to 1972 | Ağ | A regulator opened a market. The Carterfone decision let equipment AT&T had not built attach to the telephone network, and within four years an industry of modem and multiplexer companies existed that could not have existed before. The trigger, the window, the products that defined it, and why it closed. |
| The networking window, 1979 to 1982 | Ağ | Corporations had bought computers for a decade and now needed them to talk to each other inside a building. The window that opened around 1979 produced local area networks and the data PBX, settled a contest between two answers to the same problem, and closed once the answer was obvious. |
| The radio spectrum: which frequencies go how far, and why | Ağ | Why a shortwave signal crosses an ocean on 100 watts while your Wi-Fi struggles through a wall. The bands from VLF to EHF, the three propagation modes that explain nearly everything, and the trade that governs all radio: reach or capacity, never both. |
| The internetworking window, 1984 to 1988 | Ağ | The previous window's success created this one's problem: buildings full of local area networks that could not reach each other. Bridges and routers answered it, a standards war ran alongside, and two trade shows in 1988 made the outcome visible before the argument was formally over. |
| The two shows of 1988 | Ağ | One trade show put competing vendors' equipment on a single live network in public, where failure would be seen. The other showed an ecosystem that was largely described rather than shipped. The standards argument was formally undecided and a buyer walking both floors did not need it settled. |
| The founders who kept founding | Ağ | Reading this industry as a sequence of companies misses that it is substantially the same population of people, recombining. Ungermann left Intel for Zilog and Zilog for Ungermann-Bass; Metcalfe left Xerox for 3Com. What that pattern explains, and what it does not. |
| BFD: when a link is up and dead at the same time | Ağ | Routing protocols detect failure with their own timers, measured in tens of seconds. BFD detects it in milliseconds, and exists because the most dangerous link failure is the one where the interface stays up. What it does, what it does not do, and where it goes wrong. |
| First-hop redundancy: VRRP, HSRP, and the gateway that is a fiction | Ağ | A host knows one default gateway and cannot fail over. VRRP and HSRP solve that by making the gateway address belong to a role rather than to a router. How they work, why the protocol choice matters less than people think, and the failure modes that make a redundant pair worse than a single router. |
| Multicast: what it costs to not flood | Ağ | Multicast sends one copy where unicast would send thousands, and the saving is real. What it buys in bandwidth it pays for in state, and the failure modes are not the ones people expect: a network that floods multicast everywhere is usually working exactly as configured. |
| Public DNS resolvers: what you are actually choosing | Ağ | Cloudflare, Google, Quad9, OpenDNS and the rest differ far less in speed than in policy. What each one does with your queries, which ones block by default, why anycast makes 'nearest' complicated, and the trade nobody states: the resolver that protects you also sees everything you ask for. |
| FortiGate as a DNS server: four modes, and where the filter applies | Ağ | A FortiGate can relay DNS, answer from its own database, or resolve from the root itself. The four modes behave differently under failure, and the DNS filter profile does not apply to all of them - which is the configuration that looks protected and is not. |
Hash ve kripto (15)
Karma, şifreleme ve kodlama: üç farklı şey
Sürekli karıştırılan üç işlem, iki soruyla temiz biçimde ayrılır: geri döndürülebilir mi ve bir anahtar gerektirir mi?
Hash ve kriptoKodlama ve veriReadKriptografik karma: SHA-256 ve SHA-2 ailesi
Bir karma fonksiyonunun neyi garanti ettiği, onu kriptografik yapan özellikler ve bir özetin neden şifreleme olmadığı.
Hash ve kriptoReadBir karma seçmek: MD5, SHA-1, SHA-2, SHA-3 ve BLAKE
Hangi karma fonksiyonlarının hâlâ güvenli, hangilerinin kırık olduğu, çıktı boyutları ve doğrusunu nasıl seçeceğiniz.
Hash ve kriptoReadÇakışmalar, ön görüntü direnci ve doğum günü sınırı
Kriptografik bir karmanın sahip olması gereken üç güvenlik özelliği, çakışmaların neden önemli olduğu ve gerçek gücü belirleyen doğum günü matematiği.
Hash ve kriptoReadParola saklama: bcrypt, scrypt ve Argon2
SHA-256 gibi hızlı bir karmanın neden parolalar için yanlış araç olduğu ve tuzlama ile iş faktörlerinin gerçekte ne yaptığı.
Hash ve kriptoReadHMAC: mesaj kimlik doğrulaması için anahtarlı karma
Düz bir karmanın neden bütünlüğü kanıtladığı ama gerçekliği kanıtlamadığı, gizli bir anahtarın bunu nasıl düzelttiği ve HMAC'in yapısının neden önemli olduğu.
Hash ve kriptoReadNeden HMAC, hash(anahtar + mesaj) değil
Naif anahtarlı karmalamayı kıran uzunluk uzatma saldırısı ve HMAC'in onu yenmek için kullandığı iç içe yapı.
Hash ve kriptoReadAPI isteklerini HMAC ile kimlik doğrulama
Paylaşılan bir sırrın ve bir karmanın, bir sunucunun yapıldığını görmediği bir isteğe güvenmesini nasıl sağladığı ve yeniden oynatma korumasının nasıl uyduğu.
Hash ve kriptoReadBir HMAC'i güvenle doğrulama: sabit zaman ve yeniden oynatma
İmzaları == ile karşılaştırmanın neden bir zaman yan kanalı sızdırdığı ve geçerli bir imzanın tek başına neden tekrarlanan bir isteği durdurmadığı.
Hash ve kriptoReadWhy Cryptographic Hashes Are One-Way
A cryptographic hash maps any input to a fixed-size digest and is designed so that recovering the input from the digest is infeasible. That property, preimage resistance, is why you cannot decrypt a hash. The only ways to reverse one are to look it up or to guess-and-check, both of which are search, not inversion.
Hash ve kriptoReadBrute Force vs Lookup Tables: Two Ways to Reverse a Hash
Since a hash cannot be inverted, reversing one means searching, and there are two families. Precompute a giant table of input-to-hash pairs and look the hash up (what CrackStation does), or generate candidates on the fly and hash each until one matches (brute force). They trade storage for compute in opposite directions.
Hash ve kriptoReadWhy Salting Defeats Precomputed Tables
A salt is a unique random value stored with each password hash and mixed in before hashing. It makes identical passwords hash differently, which destroys the economics of precomputed tables: an attacker would need a separate table for every salt. Salting is the specific defense that neutralizes lookup services and rainbow tables.
Hash ve kriptoReadSlow KDFs: bcrypt, scrypt, and Argon2
Salting defeats precomputation but not a targeted guess-and-check attack; a fast hash still lets an attacker try billions of candidates per second. Slow key derivation functions fix that by making each guess deliberately expensive and tunable, cutting an attacker's rate by many orders of magnitude. These are what you should store passwords with.
Hash ve kriptoReadKeyspace, Entropy, and Crack Time
Whether brute force can reverse a hash comes down to keyspace size versus the attacker's hashing rate. Keyspace grows exponentially with length and alphabet, so a few extra characters move a secret from cracked in seconds to infeasible for millennia. This is the arithmetic behind why length and randomness matter most.
Hash ve kriptoReadChoosing a Password Hash
Storing passwords safely is a solved problem: use a purpose-built, salted, slow password hash, not a raw digest. This is a short decision guide, from the algorithm to pick to the parameters to set and the mistakes to avoid, aligned with OWASP and NIST guidance.
Hash ve kriptoRead
| Article | Topic | Summary |
|---|---|---|
| Karma, şifreleme ve kodlama: üç farklı şey | Hash ve kriptoKodlama ve veri | Sürekli karıştırılan üç işlem, iki soruyla temiz biçimde ayrılır: geri döndürülebilir mi ve bir anahtar gerektirir mi? |
| Kriptografik karma: SHA-256 ve SHA-2 ailesi | Hash ve kripto | Bir karma fonksiyonunun neyi garanti ettiği, onu kriptografik yapan özellikler ve bir özetin neden şifreleme olmadığı. |
| Bir karma seçmek: MD5, SHA-1, SHA-2, SHA-3 ve BLAKE | Hash ve kripto | Hangi karma fonksiyonlarının hâlâ güvenli, hangilerinin kırık olduğu, çıktı boyutları ve doğrusunu nasıl seçeceğiniz. |
| Çakışmalar, ön görüntü direnci ve doğum günü sınırı | Hash ve kripto | Kriptografik bir karmanın sahip olması gereken üç güvenlik özelliği, çakışmaların neden önemli olduğu ve gerçek gücü belirleyen doğum günü matematiği. |
| Parola saklama: bcrypt, scrypt ve Argon2 | Hash ve kripto | SHA-256 gibi hızlı bir karmanın neden parolalar için yanlış araç olduğu ve tuzlama ile iş faktörlerinin gerçekte ne yaptığı. |
| HMAC: mesaj kimlik doğrulaması için anahtarlı karma | Hash ve kripto | Düz bir karmanın neden bütünlüğü kanıtladığı ama gerçekliği kanıtlamadığı, gizli bir anahtarın bunu nasıl düzelttiği ve HMAC'in yapısının neden önemli olduğu. |
| Neden HMAC, hash(anahtar + mesaj) değil | Hash ve kripto | Naif anahtarlı karmalamayı kıran uzunluk uzatma saldırısı ve HMAC'in onu yenmek için kullandığı iç içe yapı. |
| API isteklerini HMAC ile kimlik doğrulama | Hash ve kripto | Paylaşılan bir sırrın ve bir karmanın, bir sunucunun yapıldığını görmediği bir isteğe güvenmesini nasıl sağladığı ve yeniden oynatma korumasının nasıl uyduğu. |
| Bir HMAC'i güvenle doğrulama: sabit zaman ve yeniden oynatma | Hash ve kripto | İmzaları == ile karşılaştırmanın neden bir zaman yan kanalı sızdırdığı ve geçerli bir imzanın tek başına neden tekrarlanan bir isteği durdurmadığı. |
| Why Cryptographic Hashes Are One-Way | Hash ve kripto | A cryptographic hash maps any input to a fixed-size digest and is designed so that recovering the input from the digest is infeasible. That property, preimage resistance, is why you cannot decrypt a hash. The only ways to reverse one are to look it up or to guess-and-check, both of which are search, not inversion. |
| Brute Force vs Lookup Tables: Two Ways to Reverse a Hash | Hash ve kripto | Since a hash cannot be inverted, reversing one means searching, and there are two families. Precompute a giant table of input-to-hash pairs and look the hash up (what CrackStation does), or generate candidates on the fly and hash each until one matches (brute force). They trade storage for compute in opposite directions. |
| Why Salting Defeats Precomputed Tables | Hash ve kripto | A salt is a unique random value stored with each password hash and mixed in before hashing. It makes identical passwords hash differently, which destroys the economics of precomputed tables: an attacker would need a separate table for every salt. Salting is the specific defense that neutralizes lookup services and rainbow tables. |
| Slow KDFs: bcrypt, scrypt, and Argon2 | Hash ve kripto | Salting defeats precomputation but not a targeted guess-and-check attack; a fast hash still lets an attacker try billions of candidates per second. Slow key derivation functions fix that by making each guess deliberately expensive and tunable, cutting an attacker's rate by many orders of magnitude. These are what you should store passwords with. |
| Keyspace, Entropy, and Crack Time | Hash ve kripto | Whether brute force can reverse a hash comes down to keyspace size versus the attacker's hashing rate. Keyspace grows exponentially with length and alphabet, so a few extra characters move a secret from cracked in seconds to infeasible for millennia. This is the arithmetic behind why length and randomness matter most. |
| Choosing a Password Hash | Hash ve kripto | Storing passwords safely is a solved problem: use a purpose-built, salted, slow password hash, not a raw digest. This is a short decision guide, from the algorithm to pick to the parameters to set and the mistakes to avoid, aligned with OWASP and NIST guidance. |
Kimlik ve token'lar (39)
Bir JSON Web Token'ın anatomisi
Bir JWT'nin üç bölümü, imzanın onu nasıl güvenilir kıldığı ve bir token'ı kod çözmenin onu doğrulamakla aynı şey olmadığı.
Kimlik ve token'larReadJWKS and Key Rotation: How Providers Publish Their Keys
A JWKS is the public phone book of signing keys that an identity provider publishes so anyone can verify its tokens. Understanding the keys array, the kid that names each key, and why a provider keeps more than one key at a time is the foundation of token verification.
Kimlik ve token'larReadOpenID Connect: An Identity Layer on OAuth 2.0
What OpenID Connect adds to OAuth 2.0, the ID token at the center of it, the relying party and provider roles, how the authorization code flow delivers an ID token, and why an ID token is just a JWT you can decode and read.
Kimlik ve token'larReadJWK Key Types: RSA, EC, OKP, and oct
Every JSON Web Key declares a kty, and that one field decides which parameters the key carries. Four types cover almost everything you will meet: RSA, elliptic curve, the Edwards and Montgomery curves, and the symmetric octet sequence. The crucial split in all of them is public versus private.
Kimlik ve token'larReadJWT imzalama algoritmaları: HMAC, RSA ve ECDSA
Bir JWT'nin alg başlığının neden önemli olduğu, simetrik ve asimetrik imzalama arasındaki fark ve nasıl seçileceği.
Kimlik ve token'larReadThe ID Token Claims, and What a Relying Party Checks
The claims inside an OIDC ID token: the required iss, sub, aud, exp, and iat; the nonce that stops replay; azp when there are multiple audiences; acr and amr for authentication strength; auth_time; and the at_hash and c_hash binding claims, with the validation a relying party performs on each.
Kimlik ve token'larReadJWT güvenlik tuzakları: alg:none, anahtar karışıklığı ve eksik kontroller
Bir JWT doğrulayıcısını bir sahtecilik makinesine dönüştüren bir avuç hata ve doğru bir doğrulayıcının yapması gereken doğrulama.
Kimlik ve token'larReadOIDC vs OAuth 2.0: Authentication vs Authorization
Why OAuth 2.0 is about authorization and OpenID Connect is about authentication, the difference between an access token and an ID token, why using plain OAuth as a login mechanism is a known antipattern, and how to tell which token is which.
Kimlik ve token'larReadVerifying a JWT with a JWKS: From kid to Signature
Verifying a signed token is a short, strict sequence: read the header, find the key whose kid matches in the provider's JWKS, confirm the algorithm, and check the signature. Each step has a classic pitfall, and skipping the strictness is how verification bypasses happen.
Kimlik ve token'larReadErişim token'ları, yenileme token'ları ve kimlik token'ları
Sürekli karıştırılan üç OAuth ve OpenID Connect token'ı, her birinin aslında ne işe yaradığı ve yanlış olanı yanlış yere göndermenin neden gerçek bir hata olduğu.
Kimlik ve token'larReadJWK Parameters and Thumbprints
A JWK is a JSON object describing one key, and its parameters say what the key is for and how to identify it. Beyond the key material, kid names it and an RFC 7638 thumbprint gives it a stable, computed identifier. This covers the common parameters and how a thumbprint is derived and used.
Kimlik ve token'larReadOIDC Discovery: The openid-configuration Document
How the .well-known/openid-configuration document lets a relying party learn a provider's endpoints and capabilities automatically, what the issuer, jwks_uri, and signing-algorithm fields mean, why advertising the none algorithm is dangerous, and why PKCE S256 support matters.
Kimlik ve token'larReadAçık ile gizli istemciler ve PKCE'nin yeri
Bir OAuth istemcisinin bir sır tutup tutamaması tüm güvenlik modeline karar verir. Neden SPA'lar ve mobil uygulamalar açık istemcilerdir ve neden PKCE artık hepsi için önerilir.
Kimlik ve token'larReadJWT Algorithm Confusion Attacks
Two classic JWT verification failures come from trusting the token's own algorithm header: accepting alg none, and being tricked into verifying an RS256 token as HS256 using the public key as the secret. Both are defeated by pinning the expected algorithm on the server instead of reading it from the token.
Kimlik ve token'larReadThe OIDC Authorization Code Flow
The authorization code flow is the recommended way an app gets an ID token: the user is redirected to the identity provider to log in, the app receives a short-lived code, and it exchanges that code at a back-channel token endpoint for the tokens. Keeping the token out of the browser is the whole point.
Kimlik ve token'larReadOAuth 2.0 yetkilendirme kodu akışı
Dört rol, yönlendir-ve-takas dansı ve kodun neden arka kanalda bir token'la takas edildiği.
Kimlik ve token'larReadPKCE: OAuth yetkilendirme kodu akışını güvenceye almak
PKCE'nin yendiği ele geçirme saldırısı, verifier ile challenge'ın nasıl bir araya geldiği ve S256'nın neden zorunlu olduğu.
Kimlik ve token'larReadOpenID Connect: OAuth 2.0 üzerinde kimlik
OIDC'nin OAuth'un yetkilendirmesine kimlik doğrulamayı nasıl eklediği, kimlik belirtecinin ne olduğu ve PKCE ile kod akışının neden önerilen yol olduğu.
Kimlik ve token'larReadHow TOTP and HOTP one-time passwords work
Both turn a shared secret into a short code that proves possession without sending the secret. HOTP counts events; TOTP counts time. The engine underneath is the same HMAC plus a truncation step.
Kimlik ve token'larReadValidating one-time passwords: drift, windows, and replay
Generating a code is the easy half. Accepting one means tolerating clock drift, bounding the window, rejecting reuse, and throttling guesses, each a tradeoff between usability and security.
Kimlik ve token'larReadProvisioning Authenticators: otpauth URIs and QR Codes
Before an authenticator app can generate codes, it needs the shared secret and the parameters that go with it. That is carried in an otpauth URI, usually shown as a QR code to scan. Knowing the URI's fields explains what the QR code actually contains and why the secret is in base32.
Kimlik ve token'larReadInstalling PingFederate: Requirements, First Run, and the Setup Wizard
What a PingFederate deployment needs before the ZIP is even extracted - a supported Java runtime, the 9999/9031 port plan, a dedicated service account - then the install itself on Windows or Linux, and exactly what the initial configuration wizard asks of you on first login: license, first administrator, and the base URL partners will trust.
Kimlik ve token'larReadUpgrading PingFederate: The Utility, the Merge, and the Cluster Order
How PingFederate upgrades actually work: the Upgrade Utility that copies configuration from the old install into the new one, the release notes you read for every version crossed, the custom-logging merge everyone forgets, and the console-first order that keeps a cluster consistent.
Kimlik ve token'larReadThe PingFederate Startup Files: Who Controls What
A tour of the files that decide how a PingFederate server runs: the run.sh/run.bat launchers, run.properties for ports and the clustered role, jvm-memory.options for the heap, and log4j2.xml for what gets written where - plus the habit of knowing which file owns which behavior before you need it at 3 a.m.
Kimlik ve token'larReadWho Administers PingFederate: Native Accounts, Roles, and Console Login via LDAP
The administrative access model: native accounts and the role set that divides power - User Admin, Admin, Expression Admin, Auditor, and the cryptographic role - plus how console authentication moves from native accounts to an LDAP directory through run.properties and ldap.properties, with directory groups mapped onto the same roles.
Kimlik ve token'larReadPingFederate Operational Hygiene: License, Notifications, and the Configuration Archive
Three habits that keep a PingFederate deployment boring in the best way: managing the license file and its expiry, wiring notification publishers so certificate and licensing events announce themselves, and treating the data.zip configuration archive - manual exports and the automatic snapshots - as the backup, migration, and undo mechanism it is.
Kimlik ve token'larSertifikalar ve PKIReadThe PingFederate Endpoints Map: Admin Port, Runtime Port, and What Lives Where
Every PingFederate endpoint belongs to one of two families: administrative endpoints on the console port (the console app and the /pf-admin-api) or runtime endpoints on the engine port (/idp and /sp application endpoints, the /as OAuth authorization server, OIDC's userinfo and discovery, and the /pf/heartbeat.ping that load balancers watch). Knowing which port answers which path is half the troubleshooting.
Kimlik ve token'larReadPingFederate Data Stores: LDAP and JDBC, Defined Once, Used Everywhere
Data stores are PingFederate's reusable connection definitions: an LDAP store with directory type, failover hosts, bind credentials, and LDAPS; a JDBC store with its connection URL, validation query, and the driver JAR that must be deployed before anything connects. Credential validators, attribute lookups, and provisioning all consume the same definitions - which is the whole point.
Kimlik ve token'larReadHow Users Prove Who They Are: PCVs and the Five Adapters
The PingFederate authentication toolkit the exam names: Password Credential Validators as the reusable password-checking layer, then the five adapters and the integration pattern each one embodies - HTML Form for interactive login, HTTP Basic for the 401 challenge, Kerberos for silent desktop SSO, OpenToken for integration-kit handoff, and Reference ID for the agentless back-channel.
Kimlik ve token'larReadThe PingFederate Log Files: Which One Answers Which Question
The cast of <pf_install>/pingfederate/log and what each member is for: server.log for the application, admin.log and admin-api.log for who changed what, transaction.log for runtime protocol summaries, audit.log for authentication and security events - plus the log4j2.xml levels that control verbosity and the habit of matching the question to the file.
Kimlik ve token'larReadPingFederate Authentication Policies: Trees, Selectors, and the Contract at the End
How PingFederate decides who authenticates how: policy trees whose nodes are authentication sources and selectors, Fail and Success branches flowing top-down, reusable fragments for common sequences, and the Authentication Policy Contract at the end of every successful path - the normalization layer that makes everything downstream source-independent.
Kimlik ve token'larReadLDAP Fundamentals: The Directory Model Behind Identity Systems
The Lightweight Directory Access Protocol from first principles: the tree of entries and their distinguished names, the bind operation that authenticates, searches with base, scope, and filter, the group memberships access decisions ride on, and the LDAPS transport - the working vocabulary every identity product assumes before its own documentation makes sense.
Kimlik ve token'larReadKerberos and SPNEGO: How Silent Desktop SSO Actually Works
The ticket machinery behind login-without-a-prompt: the KDC's two services, the TGT and the service ticket, why SPNs and keytabs exist, how SPNEGO carries a Kerberos ticket inside an HTTP Negotiate header, and the small list of things - clock skew, missing SPNs, browser trust - that break it in practice.
Kimlik ve token'larReadSCIM: The Standard That Provisions the Accounts SSO Signs In
The System for Cross-domain Identity Management in one sitting: why provisioning needed a standard, the RFC 7643 schemas for Users and Groups, the RFC 7644 REST protocol - create, filter, PATCH, deactivate - and where SCIM sits next to SAML and OIDC in an identity architecture: they authenticate the account, SCIM is how the account got there.
Kimlik ve token'larReadThe PingAccess Policy Model: Gateway, Agent, and the Rule Stack
How PingAccess decides who reaches what: the two deployment shapes (gateway routing to sites, agents speaking PAAP to a policy server), the application-and-resource partition, rules composed into rule sets and rule set groups, the fixed evaluation order, and the token mediation that keeps legacy backends in the game.
Kimlik ve token'larReadThe PingDirectory Platform: Store, Aggregate, Sync, Delegate
The four-piece identity data platform: the PingDirectory server as a high-performance LDAP and native SCIM 2.0 REST store, PingDirectoryProxy as the LDAPv3 gateway and virtual directory, PingDataSync as the real-time bidirectional synchronization engine across heterogeneous stores, and Delegated Admin as the controlled self-service surface - plus the operational grammar of cn=config, server groups, and zero-downtime moves.
Kimlik ve token'larReadPingOne: The Platform Behind the Product Names
What PingOne actually is - a multi-tenant identity-as-a-service platform organized around environments inside an organization - and how its named services (SSO, MFA, Protect, Verify, Authorize, DaVinci) divide the work, how it relates to the self-managed PingFederate/PingAccess/PingDirectory stack and to Advanced Identity Cloud, and why the same word appears in so many product names.
Kimlik ve token'larReadPingOne DaVinci: Identity Orchestration as a Canvas
What identity orchestration is and why it became its own product category: DaVinci's drag-and-drop flows, the connector catalog that turns vendors into nodes, server-driven orchestration that lets journeys change without app releases, the Singular Key origin story, and how DaVinci coexists with the ForgeRock-heritage journeys and trees under one SDK family.
Kimlik ve token'larReadFrom Sun to Ping: The ForgeRock Lineage Decoded
Why the Ping catalog has two of everything: the family tree from Sun's OpenSSO, OpenDS, and OpenIDM through ForgeRock's OpenAM, OpenDJ, OpenIDM, and OpenIG to today's PingAM, PingDS, PingIDM, PingGateway, and PingOne Advanced Identity Cloud - the 2023 merger that created the parallel stacks, which product answers to which name, and how to read any Ping architecture diagram without ambiguity.
Kimlik ve token'larRead
| Article | Topic | Summary |
|---|---|---|
| Bir JSON Web Token'ın anatomisi | Kimlik ve token'lar | Bir JWT'nin üç bölümü, imzanın onu nasıl güvenilir kıldığı ve bir token'ı kod çözmenin onu doğrulamakla aynı şey olmadığı. |
| JWKS and Key Rotation: How Providers Publish Their Keys | Kimlik ve token'lar | A JWKS is the public phone book of signing keys that an identity provider publishes so anyone can verify its tokens. Understanding the keys array, the kid that names each key, and why a provider keeps more than one key at a time is the foundation of token verification. |
| OpenID Connect: An Identity Layer on OAuth 2.0 | Kimlik ve token'lar | What OpenID Connect adds to OAuth 2.0, the ID token at the center of it, the relying party and provider roles, how the authorization code flow delivers an ID token, and why an ID token is just a JWT you can decode and read. |
| JWK Key Types: RSA, EC, OKP, and oct | Kimlik ve token'lar | Every JSON Web Key declares a kty, and that one field decides which parameters the key carries. Four types cover almost everything you will meet: RSA, elliptic curve, the Edwards and Montgomery curves, and the symmetric octet sequence. The crucial split in all of them is public versus private. |
| JWT imzalama algoritmaları: HMAC, RSA ve ECDSA | Kimlik ve token'lar | Bir JWT'nin alg başlığının neden önemli olduğu, simetrik ve asimetrik imzalama arasındaki fark ve nasıl seçileceği. |
| The ID Token Claims, and What a Relying Party Checks | Kimlik ve token'lar | The claims inside an OIDC ID token: the required iss, sub, aud, exp, and iat; the nonce that stops replay; azp when there are multiple audiences; acr and amr for authentication strength; auth_time; and the at_hash and c_hash binding claims, with the validation a relying party performs on each. |
| JWT güvenlik tuzakları: alg:none, anahtar karışıklığı ve eksik kontroller | Kimlik ve token'lar | Bir JWT doğrulayıcısını bir sahtecilik makinesine dönüştüren bir avuç hata ve doğru bir doğrulayıcının yapması gereken doğrulama. |
| OIDC vs OAuth 2.0: Authentication vs Authorization | Kimlik ve token'lar | Why OAuth 2.0 is about authorization and OpenID Connect is about authentication, the difference between an access token and an ID token, why using plain OAuth as a login mechanism is a known antipattern, and how to tell which token is which. |
| Verifying a JWT with a JWKS: From kid to Signature | Kimlik ve token'lar | Verifying a signed token is a short, strict sequence: read the header, find the key whose kid matches in the provider's JWKS, confirm the algorithm, and check the signature. Each step has a classic pitfall, and skipping the strictness is how verification bypasses happen. |
| Erişim token'ları, yenileme token'ları ve kimlik token'ları | Kimlik ve token'lar | Sürekli karıştırılan üç OAuth ve OpenID Connect token'ı, her birinin aslında ne işe yaradığı ve yanlış olanı yanlış yere göndermenin neden gerçek bir hata olduğu. |
| JWK Parameters and Thumbprints | Kimlik ve token'lar | A JWK is a JSON object describing one key, and its parameters say what the key is for and how to identify it. Beyond the key material, kid names it and an RFC 7638 thumbprint gives it a stable, computed identifier. This covers the common parameters and how a thumbprint is derived and used. |
| OIDC Discovery: The openid-configuration Document | Kimlik ve token'lar | How the .well-known/openid-configuration document lets a relying party learn a provider's endpoints and capabilities automatically, what the issuer, jwks_uri, and signing-algorithm fields mean, why advertising the none algorithm is dangerous, and why PKCE S256 support matters. |
| Açık ile gizli istemciler ve PKCE'nin yeri | Kimlik ve token'lar | Bir OAuth istemcisinin bir sır tutup tutamaması tüm güvenlik modeline karar verir. Neden SPA'lar ve mobil uygulamalar açık istemcilerdir ve neden PKCE artık hepsi için önerilir. |
| JWT Algorithm Confusion Attacks | Kimlik ve token'lar | Two classic JWT verification failures come from trusting the token's own algorithm header: accepting alg none, and being tricked into verifying an RS256 token as HS256 using the public key as the secret. Both are defeated by pinning the expected algorithm on the server instead of reading it from the token. |
| The OIDC Authorization Code Flow | Kimlik ve token'lar | The authorization code flow is the recommended way an app gets an ID token: the user is redirected to the identity provider to log in, the app receives a short-lived code, and it exchanges that code at a back-channel token endpoint for the tokens. Keeping the token out of the browser is the whole point. |
| OAuth 2.0 yetkilendirme kodu akışı | Kimlik ve token'lar | Dört rol, yönlendir-ve-takas dansı ve kodun neden arka kanalda bir token'la takas edildiği. |
| PKCE: OAuth yetkilendirme kodu akışını güvenceye almak | Kimlik ve token'lar | PKCE'nin yendiği ele geçirme saldırısı, verifier ile challenge'ın nasıl bir araya geldiği ve S256'nın neden zorunlu olduğu. |
| OpenID Connect: OAuth 2.0 üzerinde kimlik | Kimlik ve token'lar | OIDC'nin OAuth'un yetkilendirmesine kimlik doğrulamayı nasıl eklediği, kimlik belirtecinin ne olduğu ve PKCE ile kod akışının neden önerilen yol olduğu. |
| How TOTP and HOTP one-time passwords work | Kimlik ve token'lar | Both turn a shared secret into a short code that proves possession without sending the secret. HOTP counts events; TOTP counts time. The engine underneath is the same HMAC plus a truncation step. |
| Validating one-time passwords: drift, windows, and replay | Kimlik ve token'lar | Generating a code is the easy half. Accepting one means tolerating clock drift, bounding the window, rejecting reuse, and throttling guesses, each a tradeoff between usability and security. |
| Provisioning Authenticators: otpauth URIs and QR Codes | Kimlik ve token'lar | Before an authenticator app can generate codes, it needs the shared secret and the parameters that go with it. That is carried in an otpauth URI, usually shown as a QR code to scan. Knowing the URI's fields explains what the QR code actually contains and why the secret is in base32. |
| Installing PingFederate: Requirements, First Run, and the Setup Wizard | Kimlik ve token'lar | What a PingFederate deployment needs before the ZIP is even extracted - a supported Java runtime, the 9999/9031 port plan, a dedicated service account - then the install itself on Windows or Linux, and exactly what the initial configuration wizard asks of you on first login: license, first administrator, and the base URL partners will trust. |
| Upgrading PingFederate: The Utility, the Merge, and the Cluster Order | Kimlik ve token'lar | How PingFederate upgrades actually work: the Upgrade Utility that copies configuration from the old install into the new one, the release notes you read for every version crossed, the custom-logging merge everyone forgets, and the console-first order that keeps a cluster consistent. |
| The PingFederate Startup Files: Who Controls What | Kimlik ve token'lar | A tour of the files that decide how a PingFederate server runs: the run.sh/run.bat launchers, run.properties for ports and the clustered role, jvm-memory.options for the heap, and log4j2.xml for what gets written where - plus the habit of knowing which file owns which behavior before you need it at 3 a.m. |
| Who Administers PingFederate: Native Accounts, Roles, and Console Login via LDAP | Kimlik ve token'lar | The administrative access model: native accounts and the role set that divides power - User Admin, Admin, Expression Admin, Auditor, and the cryptographic role - plus how console authentication moves from native accounts to an LDAP directory through run.properties and ldap.properties, with directory groups mapped onto the same roles. |
| PingFederate Operational Hygiene: License, Notifications, and the Configuration Archive | Kimlik ve token'larSertifikalar ve PKI | Three habits that keep a PingFederate deployment boring in the best way: managing the license file and its expiry, wiring notification publishers so certificate and licensing events announce themselves, and treating the data.zip configuration archive - manual exports and the automatic snapshots - as the backup, migration, and undo mechanism it is. |
| The PingFederate Endpoints Map: Admin Port, Runtime Port, and What Lives Where | Kimlik ve token'lar | Every PingFederate endpoint belongs to one of two families: administrative endpoints on the console port (the console app and the /pf-admin-api) or runtime endpoints on the engine port (/idp and /sp application endpoints, the /as OAuth authorization server, OIDC's userinfo and discovery, and the /pf/heartbeat.ping that load balancers watch). Knowing which port answers which path is half the troubleshooting. |
| PingFederate Data Stores: LDAP and JDBC, Defined Once, Used Everywhere | Kimlik ve token'lar | Data stores are PingFederate's reusable connection definitions: an LDAP store with directory type, failover hosts, bind credentials, and LDAPS; a JDBC store with its connection URL, validation query, and the driver JAR that must be deployed before anything connects. Credential validators, attribute lookups, and provisioning all consume the same definitions - which is the whole point. |
| How Users Prove Who They Are: PCVs and the Five Adapters | Kimlik ve token'lar | The PingFederate authentication toolkit the exam names: Password Credential Validators as the reusable password-checking layer, then the five adapters and the integration pattern each one embodies - HTML Form for interactive login, HTTP Basic for the 401 challenge, Kerberos for silent desktop SSO, OpenToken for integration-kit handoff, and Reference ID for the agentless back-channel. |
| The PingFederate Log Files: Which One Answers Which Question | Kimlik ve token'lar | The cast of <pf_install>/pingfederate/log and what each member is for: server.log for the application, admin.log and admin-api.log for who changed what, transaction.log for runtime protocol summaries, audit.log for authentication and security events - plus the log4j2.xml levels that control verbosity and the habit of matching the question to the file. |
| PingFederate Authentication Policies: Trees, Selectors, and the Contract at the End | Kimlik ve token'lar | How PingFederate decides who authenticates how: policy trees whose nodes are authentication sources and selectors, Fail and Success branches flowing top-down, reusable fragments for common sequences, and the Authentication Policy Contract at the end of every successful path - the normalization layer that makes everything downstream source-independent. |
| LDAP Fundamentals: The Directory Model Behind Identity Systems | Kimlik ve token'lar | The Lightweight Directory Access Protocol from first principles: the tree of entries and their distinguished names, the bind operation that authenticates, searches with base, scope, and filter, the group memberships access decisions ride on, and the LDAPS transport - the working vocabulary every identity product assumes before its own documentation makes sense. |
| Kerberos and SPNEGO: How Silent Desktop SSO Actually Works | Kimlik ve token'lar | The ticket machinery behind login-without-a-prompt: the KDC's two services, the TGT and the service ticket, why SPNs and keytabs exist, how SPNEGO carries a Kerberos ticket inside an HTTP Negotiate header, and the small list of things - clock skew, missing SPNs, browser trust - that break it in practice. |
| SCIM: The Standard That Provisions the Accounts SSO Signs In | Kimlik ve token'lar | The System for Cross-domain Identity Management in one sitting: why provisioning needed a standard, the RFC 7643 schemas for Users and Groups, the RFC 7644 REST protocol - create, filter, PATCH, deactivate - and where SCIM sits next to SAML and OIDC in an identity architecture: they authenticate the account, SCIM is how the account got there. |
| The PingAccess Policy Model: Gateway, Agent, and the Rule Stack | Kimlik ve token'lar | How PingAccess decides who reaches what: the two deployment shapes (gateway routing to sites, agents speaking PAAP to a policy server), the application-and-resource partition, rules composed into rule sets and rule set groups, the fixed evaluation order, and the token mediation that keeps legacy backends in the game. |
| The PingDirectory Platform: Store, Aggregate, Sync, Delegate | Kimlik ve token'lar | The four-piece identity data platform: the PingDirectory server as a high-performance LDAP and native SCIM 2.0 REST store, PingDirectoryProxy as the LDAPv3 gateway and virtual directory, PingDataSync as the real-time bidirectional synchronization engine across heterogeneous stores, and Delegated Admin as the controlled self-service surface - plus the operational grammar of cn=config, server groups, and zero-downtime moves. |
| PingOne: The Platform Behind the Product Names | Kimlik ve token'lar | What PingOne actually is - a multi-tenant identity-as-a-service platform organized around environments inside an organization - and how its named services (SSO, MFA, Protect, Verify, Authorize, DaVinci) divide the work, how it relates to the self-managed PingFederate/PingAccess/PingDirectory stack and to Advanced Identity Cloud, and why the same word appears in so many product names. |
| PingOne DaVinci: Identity Orchestration as a Canvas | Kimlik ve token'lar | What identity orchestration is and why it became its own product category: DaVinci's drag-and-drop flows, the connector catalog that turns vendors into nodes, server-driven orchestration that lets journeys change without app releases, the Singular Key origin story, and how DaVinci coexists with the ForgeRock-heritage journeys and trees under one SDK family. |
| From Sun to Ping: The ForgeRock Lineage Decoded | Kimlik ve token'lar | Why the Ping catalog has two of everything: the family tree from Sun's OpenSSO, OpenDS, and OpenIDM through ForgeRock's OpenAM, OpenDJ, OpenIDM, and OpenIG to today's PingAM, PingDS, PingIDM, PingGateway, and PingOne Advanced Identity Cloud - the 2023 merger that created the parallel stacks, which product answers to which name, and how to read any Ping architecture diagram without ambiguity. |
Kodlama ve veri (42)
Baytlar, kod noktaları ve UTF-8
Bir karakter ile bir bayt arasındaki fark, Unicode ve UTF-8'in neden var olduğu ve bunun Base64 ile ne ilgisi olduğu.
Kodlama ve veriReadJSON vs YAML: What Converts Cleanly and What Does Not
YAML was designed so that every JSON document is also valid YAML, which is why conversion between them usually just works. The interesting part is the edges: comments, anchors, multiple documents, and YAML-only types that have no JSON equivalent.
Kodlama ve veriReadThe Anatomy of a URL
Every URL is built from the same handful of parts defined by RFC 3986: scheme, authority (userinfo, host, port), path, query, and fragment. What each part means, how a parser tells them apart, and where the boundaries actually fall.
Kodlama ve veriWeb & HTTPReadThe JSON Grammar: Six Types and a Few Strict Rules
JSON is smaller than it looks. The whole format is six value types and a handful of structural characters, governed by rules that are stricter than most people remember: no comments, no trailing commas, and keys that must be quoted strings.
Kodlama ve veriReadWhat Unix Time Actually Is
Unix time is a single integer: the number of seconds since 1970-01-01T00:00:00Z, the epoch. It is time-zone independent, compact, and sortable, which is why it underpins almost every system clock, log line, and API timestamp. Converting it to a calendar date is pure arithmetic.
Kodlama ve veriReadBase64 ve Base64URL, açıklandı
İkili verinin nasıl iletime güvenli metne dönüştüğü, dolgunun neden var olduğu ve URL'ye güvenli varyantta neyin değiştiği.
Kodlama ve veriReadJSON Numbers and the Precision Trap
JSON puts no limit on the size or precision of a number, but most parsers quietly convert every number to a 64-bit float. That mismatch silently corrupts large integers and exact decimals, which is why a formatter should preserve the original digits.
Kodlama ve veriReadQuery Strings: Parameters, Plus Signs, and Repeated Keys
The part of a URL after the question mark looks simple but hides real ambiguity: how parameters are separated, why a plus sign sometimes means a space, how repeated keys behave, and why there is no single governing standard.
Kodlama ve veriWeb & HTTPReadSeconds, Milliseconds, Microseconds, Nanoseconds: Telling Epoch Units Apart
The same instant can be written as 1700000000, 1700000000000, or larger, depending on whether the timestamp counts seconds, milliseconds, microseconds, or nanoseconds. Mixing them up is a classic bug. You can almost always tell which is which from the number's magnitude.
Kodlama ve veriReadYAML Type Coercion and the Norway Problem
YAML guesses the type of every unquoted scalar, and its guesses are surprising: the country code NO becomes false, a version like 1.0 becomes a number, and a zero-padded code loses its zeros. Knowing the rule is the key to safe conversion.
Kodlama ve veriReadBase64URL ve URL'ye uygun alfabe
JWT'lerin ve PKCE'nin neden farklı bir Base64 alfabesi kullandığı, değişen iki karakter ve dolguya ne olduğu.
Kodlama ve veriReadDuplicate Keys in JSON: Legal, Dangerous, and Worth Catching
JSON syntax allows the same key to appear more than once in an object, but the specification does not say what that means. Different parsers resolve it differently, which makes duplicate keys a quiet source of bugs and even security issues.
Kodlama ve veriReadJSON and YAML in Practice: APIs, Declarations, and Orchestration
The split is not random: APIs and machine-to-machine declarations tend to be JSON, while human-authored orchestration and pipeline files tend to be YAML. Understanding why each domain chose what it did explains when converting between them is useful.
Kodlama ve veriReadThe Year 2038 Problem
A signed 32-bit integer can count seconds only up to 2147483647, which falls on 2038-01-19T03:14:07Z. One second later it overflows and wraps to a negative number, throwing affected systems back to 1901. It is Y2K's quieter successor, and the fix is a wider integer.
Kodlama ve veriReadURL Encoding and Internationalized Hosts
URLs are restricted to a small set of ASCII characters, so everything else is encoded. Percent-encoding handles paths and queries; punycode handles non-ASCII host names. How both work, and why internationalized hosts are a phishing concern.
Kodlama ve veriWeb & HTTPReadBase64'ün ortaya çıktığı yerler: data URI, MIME, PEM ve Basic auth
İkilinin metne sarıldığı gerçek yerler, bunun boyut maliyeti ve bir kimlik doğrulama başlığındaki Base64'ün neden şifreleme olmadığı.
Kodlama ve veriReadISO 8601, RFC 3339, and the HTTP Date
Once a Unix timestamp is turned back into a human date, it gets written in one of a few standard text formats. ISO 8601 is the broad standard, RFC 3339 is its strict internet profile, and the HTTP date is the odd one out. Knowing the difference saves a lot of parsing grief.
Kodlama ve veriReadJSON String Escapes and Unicode
Inside a JSON string, a few characters must be written as escapes, and any character at all can be written as \uXXXX. The rules are small but strict, and the one that catches people is how characters beyond the basic plane, like emoji, need a surrogate pair.
Kodlama ve veriReadYAML Anchors, Aliases, and Merge Keys
YAML can define a value once and reuse it with an anchor and alias, and merge one mapping into another with a merge key. None of this exists in JSON, so converting expands and duplicates it. This covers the syntax, what happens on conversion, and the denial-of-service trap they enable.
Kodlama ve veriReadBase32, açıklandı
Base32'nin boyutu neden belirsizliği olmayan, büyük/küçük harfe duyarsız bir alfabeyle takas ettiği, 5 bitlik gruplamasının nasıl çalıştığı ve nerede ortaya çıktığı (TOTP gizleri, onion adresleri, DNS).
Kodlama ve veriReadTrailing Commas, Comments, and the JSON5 Family
Strict JSON has no comments and no trailing commas, which surprises people whose editor accepts both. The reason is that JSON is a minimal interchange format, and the tolerant variants (JSONC, JSON5) are separate things. Knowing which is which avoids config files that break in another tool.
Kodlama ve veriReadWhy Unix Time Ignores Leap Seconds
UTC occasionally inserts a leap second to stay aligned with the Earth's rotation, but Unix time pretends every day is exactly 86,400 seconds long. That deliberate simplification means a Unix timestamp is not a true count of elapsed seconds since the epoch — and it is the right trade-off for civil time.
Kodlama ve veriReadYAML Block Scalars and Multiline Strings
YAML has two ways to write a multiline string, and they treat newlines differently: literal style keeps them, folded style turns them into spaces. Chomping indicators then decide what happens to the trailing newline. Getting these wrong is why an embedded script or certificate comes out subtly mangled.
Kodlama ve veriReadFormatting, Minifying, and Canonical JSON
Whitespace does not change what JSON means, so pretty-printed and minified JSON are the same data. But when JSON is signed or hashed, the exact bytes matter, and that is where canonical JSON comes in: a deterministic way to serialize the same data to exactly the same string every time.
Kodlama ve veriReadOnaltılık kodlama (Base16), açıklandı
Onaltılığın her baytı iki karakterle nasıl temsil ettiği, ham baytları yazdırmanın neden varsayılan yolu olduğu ve Base64 ile Base32'ye kıyasla nasıl durduğu.
Kodlama ve veriReadRelative URLs and How They Resolve
A relative URL leaves out the scheme and host and is completed against a base URL. The rules for how a browser fills in the rest, and how ./ and ../ and a leading slash change the result, explain a lot of broken links and a few security surprises.
Kodlama ve veriWeb & HTTPReadRoman Numerals: How the System Actually Works
Seven symbols, no zero, and one subtraction rule that arrived a thousand years after Rome. Why IIII is on your watch and IV is in your textbook, what IL breaks, and why the classical system runs out of road at 3999.
Kodlama ve veriReadDeceptive URLs: Reading Past the Tricks
URLs are a favorite tool for phishing because the real destination is easy to disguise. The userinfo trick, redirect parameters, and look-alike characters all make a hostile link look friendly. This shows the common disguises and the one reliable habit for finding the real host.
Kodlama ve veriWeb & HTTPReadTime Arithmetic and Time Zones: Exact Durations, Honest Meetings
Why 'plus one month' has no exact answer, what ISO 8601 durations actually promise, and how one UTC instant becomes four different wall clocks. The DST trap, the day-shift trap, and the case for planning meetings with a real date.
Kodlama ve veriReadYüzde kodlama (URL kodlama), açıklandı
URL'lerin neden belirli karakterleri %XX olarak escape ettiği, hangi karakterleri olduğu gibi bırakmanın güvenli olduğu ve yüzde kodlamanın Base64'ten nasıl farklılaştığı.
Kodlama ve veriReadBase16, Base32, Base64 ve yüzde kodlama karşılaştırıldı
Dört metin kodlamasına yan yana bir bakış: alfabeleri, boyut ek yükü, okunabilirlikleri ve her birine ne zaman başvurulacağı.
Kodlama ve veriReadHow text diff works
A diff finds the smallest set of insertions and deletions that turns one text into another. Underneath is the longest common subsequence: the lines both versions share, in order, form the unchanged backbone, and everything else is an add or a remove.
Kodlama ve veriText & utilitiesReadReading a diff
How to read a line-by-line diff: unchanged, added, and removed lines, the plus and minus markers, both sides' line numbers, inline word highlighting, and what ignore-whitespace and ignore-case actually change. Plus the things a diff cannot tell you.
Kodlama ve veriText & utilitiesReadWord and Character Level Diffs
A line diff marks a whole line as changed even when a single character moved. Word-level and character-level diffs highlight the exact part of the line that changed, which is far easier to read for prose, long lines, and small edits. This covers the difference and when each is the right lens.
Kodlama ve veriText & utilitiesReadThree-Way Diffs and Merge Conflicts
A normal diff compares two versions and cannot tell which one changed. A three-way diff adds a common ancestor, which is what makes automatic merging possible and what produces the <<<<<<< ======= >>>>>>> conflict markers. This explains the third input and how to read and resolve a conflict.
Kodlama ve veriText & utilitiesReadMinimal Edits: Why a Diff Can Look Wrong
A diff shows the smallest set of insertions and deletions that turns one text into the other. Because the smallest set is not unique and the algorithm has to choose, a diff can align lines in ways that look counterintuitive, blaming the wrong block or splitting a moved section. Knowing this makes odd diffs readable.
Kodlama ve veriText & utilitiesReadReading XML Structure
XML is a tree of elements built from a handful of parts: an optional declaration, elements with attributes, text, and a few special constructs. Once you can name each part and see how they nest, reading an unfamiliar document top to bottom becomes routine rather than a guessing game.
Kodlama ve veriSecurity & WAFReadXML Namespaces Explained
When two XML vocabularies use the same element name for different things, namespaces keep them apart by binding a prefix to a unique URI. The prefix is just a local shorthand; the URI is the real identity. Understanding that split resolves most namespace confusion.
Kodlama ve veriSecurity & WAFReadWell-Formed vs Valid XML
Well-formedness is XML's baseline: one root, properly nested and matched tags, quoted attributes, and escaped specials. Validity is a stronger, separate claim that a document also follows a schema. A parser rejects ill-formed XML outright, which is why these rules come first.
Kodlama ve veriSecurity & WAFReadCDATA, Comments, and Processing Instructions
Not everything in XML is an element. CDATA sections hold raw text that would otherwise need escaping, comments annotate without affecting content, and processing instructions carry directions for an application. Recognizing these three keeps them from looking like mysterious noise.
Kodlama ve veriSecurity & WAFReadHTML Forms and Request Encoding: How the Web Ships Your Input
A form is a contract between a page and a server: which fields, which verb, which wire format. GET puts the answers in the URL; POST puts them in the body; and enctype picks the body's dialect - urlencoded's key=value chains, multipart's boundary-delimited parts built for files. What each choice means for logs, caches, size limits, and debugging, plus the fetch-era footnote: FormData kept the formats alive after forms stopped being the only sender.
Kodlama ve veriWeb & HTTPReadURI, URL, URN: What's Actually the Difference?
The three acronyms everyone uses interchangeably encode one clean idea: identify vs locate vs name. URI is the umbrella - any identifier in the standard grammar; URL is the identifier that also tells you where and how to fetch; URN was the scheme for pure, location-free names (urn:isbn:...). Why the W3C itself declared the classical trichotomy obsolete, what 'URI' means in specs vs 'URL' in conversation, and the naming lesson this site keeps collecting.
Kodlama ve veriWeb & HTTPRead
| Article | Topic | Summary |
|---|---|---|
| Baytlar, kod noktaları ve UTF-8 | Kodlama ve veri | Bir karakter ile bir bayt arasındaki fark, Unicode ve UTF-8'in neden var olduğu ve bunun Base64 ile ne ilgisi olduğu. |
| JSON vs YAML: What Converts Cleanly and What Does Not | Kodlama ve veri | YAML was designed so that every JSON document is also valid YAML, which is why conversion between them usually just works. The interesting part is the edges: comments, anchors, multiple documents, and YAML-only types that have no JSON equivalent. |
| The Anatomy of a URL | Kodlama ve veriWeb & HTTP | Every URL is built from the same handful of parts defined by RFC 3986: scheme, authority (userinfo, host, port), path, query, and fragment. What each part means, how a parser tells them apart, and where the boundaries actually fall. |
| The JSON Grammar: Six Types and a Few Strict Rules | Kodlama ve veri | JSON is smaller than it looks. The whole format is six value types and a handful of structural characters, governed by rules that are stricter than most people remember: no comments, no trailing commas, and keys that must be quoted strings. |
| What Unix Time Actually Is | Kodlama ve veri | Unix time is a single integer: the number of seconds since 1970-01-01T00:00:00Z, the epoch. It is time-zone independent, compact, and sortable, which is why it underpins almost every system clock, log line, and API timestamp. Converting it to a calendar date is pure arithmetic. |
| Base64 ve Base64URL, açıklandı | Kodlama ve veri | İkili verinin nasıl iletime güvenli metne dönüştüğü, dolgunun neden var olduğu ve URL'ye güvenli varyantta neyin değiştiği. |
| JSON Numbers and the Precision Trap | Kodlama ve veri | JSON puts no limit on the size or precision of a number, but most parsers quietly convert every number to a 64-bit float. That mismatch silently corrupts large integers and exact decimals, which is why a formatter should preserve the original digits. |
| Query Strings: Parameters, Plus Signs, and Repeated Keys | Kodlama ve veriWeb & HTTP | The part of a URL after the question mark looks simple but hides real ambiguity: how parameters are separated, why a plus sign sometimes means a space, how repeated keys behave, and why there is no single governing standard. |
| Seconds, Milliseconds, Microseconds, Nanoseconds: Telling Epoch Units Apart | Kodlama ve veri | The same instant can be written as 1700000000, 1700000000000, or larger, depending on whether the timestamp counts seconds, milliseconds, microseconds, or nanoseconds. Mixing them up is a classic bug. You can almost always tell which is which from the number's magnitude. |
| YAML Type Coercion and the Norway Problem | Kodlama ve veri | YAML guesses the type of every unquoted scalar, and its guesses are surprising: the country code NO becomes false, a version like 1.0 becomes a number, and a zero-padded code loses its zeros. Knowing the rule is the key to safe conversion. |
| Base64URL ve URL'ye uygun alfabe | Kodlama ve veri | JWT'lerin ve PKCE'nin neden farklı bir Base64 alfabesi kullandığı, değişen iki karakter ve dolguya ne olduğu. |
| Duplicate Keys in JSON: Legal, Dangerous, and Worth Catching | Kodlama ve veri | JSON syntax allows the same key to appear more than once in an object, but the specification does not say what that means. Different parsers resolve it differently, which makes duplicate keys a quiet source of bugs and even security issues. |
| JSON and YAML in Practice: APIs, Declarations, and Orchestration | Kodlama ve veri | The split is not random: APIs and machine-to-machine declarations tend to be JSON, while human-authored orchestration and pipeline files tend to be YAML. Understanding why each domain chose what it did explains when converting between them is useful. |
| The Year 2038 Problem | Kodlama ve veri | A signed 32-bit integer can count seconds only up to 2147483647, which falls on 2038-01-19T03:14:07Z. One second later it overflows and wraps to a negative number, throwing affected systems back to 1901. It is Y2K's quieter successor, and the fix is a wider integer. |
| URL Encoding and Internationalized Hosts | Kodlama ve veriWeb & HTTP | URLs are restricted to a small set of ASCII characters, so everything else is encoded. Percent-encoding handles paths and queries; punycode handles non-ASCII host names. How both work, and why internationalized hosts are a phishing concern. |
| Base64'ün ortaya çıktığı yerler: data URI, MIME, PEM ve Basic auth | Kodlama ve veri | İkilinin metne sarıldığı gerçek yerler, bunun boyut maliyeti ve bir kimlik doğrulama başlığındaki Base64'ün neden şifreleme olmadığı. |
| ISO 8601, RFC 3339, and the HTTP Date | Kodlama ve veri | Once a Unix timestamp is turned back into a human date, it gets written in one of a few standard text formats. ISO 8601 is the broad standard, RFC 3339 is its strict internet profile, and the HTTP date is the odd one out. Knowing the difference saves a lot of parsing grief. |
| JSON String Escapes and Unicode | Kodlama ve veri | Inside a JSON string, a few characters must be written as escapes, and any character at all can be written as \uXXXX. The rules are small but strict, and the one that catches people is how characters beyond the basic plane, like emoji, need a surrogate pair. |
| YAML Anchors, Aliases, and Merge Keys | Kodlama ve veri | YAML can define a value once and reuse it with an anchor and alias, and merge one mapping into another with a merge key. None of this exists in JSON, so converting expands and duplicates it. This covers the syntax, what happens on conversion, and the denial-of-service trap they enable. |
| Base32, açıklandı | Kodlama ve veri | Base32'nin boyutu neden belirsizliği olmayan, büyük/küçük harfe duyarsız bir alfabeyle takas ettiği, 5 bitlik gruplamasının nasıl çalıştığı ve nerede ortaya çıktığı (TOTP gizleri, onion adresleri, DNS). |
| Trailing Commas, Comments, and the JSON5 Family | Kodlama ve veri | Strict JSON has no comments and no trailing commas, which surprises people whose editor accepts both. The reason is that JSON is a minimal interchange format, and the tolerant variants (JSONC, JSON5) are separate things. Knowing which is which avoids config files that break in another tool. |
| Why Unix Time Ignores Leap Seconds | Kodlama ve veri | UTC occasionally inserts a leap second to stay aligned with the Earth's rotation, but Unix time pretends every day is exactly 86,400 seconds long. That deliberate simplification means a Unix timestamp is not a true count of elapsed seconds since the epoch — and it is the right trade-off for civil time. |
| YAML Block Scalars and Multiline Strings | Kodlama ve veri | YAML has two ways to write a multiline string, and they treat newlines differently: literal style keeps them, folded style turns them into spaces. Chomping indicators then decide what happens to the trailing newline. Getting these wrong is why an embedded script or certificate comes out subtly mangled. |
| Formatting, Minifying, and Canonical JSON | Kodlama ve veri | Whitespace does not change what JSON means, so pretty-printed and minified JSON are the same data. But when JSON is signed or hashed, the exact bytes matter, and that is where canonical JSON comes in: a deterministic way to serialize the same data to exactly the same string every time. |
| Onaltılık kodlama (Base16), açıklandı | Kodlama ve veri | Onaltılığın her baytı iki karakterle nasıl temsil ettiği, ham baytları yazdırmanın neden varsayılan yolu olduğu ve Base64 ile Base32'ye kıyasla nasıl durduğu. |
| Relative URLs and How They Resolve | Kodlama ve veriWeb & HTTP | A relative URL leaves out the scheme and host and is completed against a base URL. The rules for how a browser fills in the rest, and how ./ and ../ and a leading slash change the result, explain a lot of broken links and a few security surprises. |
| Roman Numerals: How the System Actually Works | Kodlama ve veri | Seven symbols, no zero, and one subtraction rule that arrived a thousand years after Rome. Why IIII is on your watch and IV is in your textbook, what IL breaks, and why the classical system runs out of road at 3999. |
| Deceptive URLs: Reading Past the Tricks | Kodlama ve veriWeb & HTTP | URLs are a favorite tool for phishing because the real destination is easy to disguise. The userinfo trick, redirect parameters, and look-alike characters all make a hostile link look friendly. This shows the common disguises and the one reliable habit for finding the real host. |
| Time Arithmetic and Time Zones: Exact Durations, Honest Meetings | Kodlama ve veri | Why 'plus one month' has no exact answer, what ISO 8601 durations actually promise, and how one UTC instant becomes four different wall clocks. The DST trap, the day-shift trap, and the case for planning meetings with a real date. |
| Yüzde kodlama (URL kodlama), açıklandı | Kodlama ve veri | URL'lerin neden belirli karakterleri %XX olarak escape ettiği, hangi karakterleri olduğu gibi bırakmanın güvenli olduğu ve yüzde kodlamanın Base64'ten nasıl farklılaştığı. |
| Base16, Base32, Base64 ve yüzde kodlama karşılaştırıldı | Kodlama ve veri | Dört metin kodlamasına yan yana bir bakış: alfabeleri, boyut ek yükü, okunabilirlikleri ve her birine ne zaman başvurulacağı. |
| How text diff works | Kodlama ve veriText & utilities | A diff finds the smallest set of insertions and deletions that turns one text into another. Underneath is the longest common subsequence: the lines both versions share, in order, form the unchanged backbone, and everything else is an add or a remove. |
| Reading a diff | Kodlama ve veriText & utilities | How to read a line-by-line diff: unchanged, added, and removed lines, the plus and minus markers, both sides' line numbers, inline word highlighting, and what ignore-whitespace and ignore-case actually change. Plus the things a diff cannot tell you. |
| Word and Character Level Diffs | Kodlama ve veriText & utilities | A line diff marks a whole line as changed even when a single character moved. Word-level and character-level diffs highlight the exact part of the line that changed, which is far easier to read for prose, long lines, and small edits. This covers the difference and when each is the right lens. |
| Three-Way Diffs and Merge Conflicts | Kodlama ve veriText & utilities | A normal diff compares two versions and cannot tell which one changed. A three-way diff adds a common ancestor, which is what makes automatic merging possible and what produces the <<<<<<< ======= >>>>>>> conflict markers. This explains the third input and how to read and resolve a conflict. |
| Minimal Edits: Why a Diff Can Look Wrong | Kodlama ve veriText & utilities | A diff shows the smallest set of insertions and deletions that turns one text into the other. Because the smallest set is not unique and the algorithm has to choose, a diff can align lines in ways that look counterintuitive, blaming the wrong block or splitting a moved section. Knowing this makes odd diffs readable. |
| Reading XML Structure | Kodlama ve veriSecurity & WAF | XML is a tree of elements built from a handful of parts: an optional declaration, elements with attributes, text, and a few special constructs. Once you can name each part and see how they nest, reading an unfamiliar document top to bottom becomes routine rather than a guessing game. |
| XML Namespaces Explained | Kodlama ve veriSecurity & WAF | When two XML vocabularies use the same element name for different things, namespaces keep them apart by binding a prefix to a unique URI. The prefix is just a local shorthand; the URI is the real identity. Understanding that split resolves most namespace confusion. |
| Well-Formed vs Valid XML | Kodlama ve veriSecurity & WAF | Well-formedness is XML's baseline: one root, properly nested and matched tags, quoted attributes, and escaped specials. Validity is a stronger, separate claim that a document also follows a schema. A parser rejects ill-formed XML outright, which is why these rules come first. |
| CDATA, Comments, and Processing Instructions | Kodlama ve veriSecurity & WAF | Not everything in XML is an element. CDATA sections hold raw text that would otherwise need escaping, comments annotate without affecting content, and processing instructions carry directions for an application. Recognizing these three keeps them from looking like mysterious noise. |
| HTML Forms and Request Encoding: How the Web Ships Your Input | Kodlama ve veriWeb & HTTP | A form is a contract between a page and a server: which fields, which verb, which wire format. GET puts the answers in the URL; POST puts them in the body; and enctype picks the body's dialect - urlencoded's key=value chains, multipart's boundary-delimited parts built for files. What each choice means for logs, caches, size limits, and debugging, plus the fetch-era footnote: FormData kept the formats alive after forms stopped being the only sender. |
| URI, URL, URN: What's Actually the Difference? | Kodlama ve veriWeb & HTTP | The three acronyms everyone uses interchangeably encode one clean idea: identify vs locate vs name. URI is the umbrella - any identifier in the standard grammar; URL is the identifier that also tells you where and how to fetch; URN was the scheme for pure, location-free names (urn:isbn:...). Why the W3C itself declared the classical trichotomy obsolete, what 'URI' means in specs vs 'URL' in conversation, and the naming lesson this site keeps collecting. |
Operations & Fieldcraft (4)
Terminal, shell, TTY, console
Four words used interchangeably by almost everyone, including the documentation. They name four different things, and the distinction explains why Ctrl+C kills your command but not your shell.
Operations & FieldcraftReadWhat a Channel Systems Engineer Actually Does
Inside a distributor there is a role almost nobody outside the channel can describe: the systems engineer who supports resellers rather than customers. Bill of materials work on every project that passes through, proofs of concept, presentations, enablement, bootcamps, trade shows. Some of the resellers being supported have no technical staff at all, which is the fact that explains the rest of the job.
Operations & FieldcraftReadWhat a network operating system actually is
IOS, Junos, EOS, TMOS, FortiOS, PAN-OS and the rest, compared on the axes that matter: what they run on, how components share state, where the planes divide, and what happens when one part fails.
Operations & FieldcraftReadThe path a product takes, and the jobs along it
Between the company that builds a thing and the person who depends on it, a product passes through many hands. Each pair belongs to a job with its own clients, suppliers, accountability and measurement — and the measurement is rarely the same as the accountability.
Operations & FieldcraftRead
| Article | Topic | Summary |
|---|---|---|
| Terminal, shell, TTY, console | Operations & Fieldcraft | Four words used interchangeably by almost everyone, including the documentation. They name four different things, and the distinction explains why Ctrl+C kills your command but not your shell. |
| What a Channel Systems Engineer Actually Does | Operations & Fieldcraft | Inside a distributor there is a role almost nobody outside the channel can describe: the systems engineer who supports resellers rather than customers. Bill of materials work on every project that passes through, proofs of concept, presentations, enablement, bootcamps, trade shows. Some of the resellers being supported have no technical staff at all, which is the fact that explains the rest of the job. |
| What a network operating system actually is | Operations & Fieldcraft | IOS, Junos, EOS, TMOS, FortiOS, PAN-OS and the rest, compared on the axes that matter: what they run on, how components share state, where the planes divide, and what happens when one part fails. |
| The path a product takes, and the jobs along it | Operations & Fieldcraft | Between the company that builds a thing and the person who depends on it, a product passes through many hands. Each pair belongs to a job with its own clients, suppliers, accountability and measurement — and the measurement is rarely the same as the accountability. |
Security & WAF (56)
HTTP Security Headers: The Defense-in-Depth Layer
What HTTP security headers are, why they form a layer of defense on top of secure code rather than a replacement for it, the headers that carry the most weight, and how to read a response's posture at a glance.
Security & WAFReadRegex Quantifiers and Character Classes
A regular expression is built from two questions: what character do I want, and how many of them? Character classes answer the first, quantifiers answer the second. Get these two right and most of regex falls into place.
Security & WAFWeb & HTTPReadSAML 2.0: How Browser SSO Works
What a SAML assertion is, the roles of the identity provider and service provider, the SP-initiated Web Browser SSO flow end to end, and the difference between the HTTP-POST and HTTP-Redirect bindings that carry the messages.
Security & WAFKimlik ve token'larReadContent Security Policy, Directive by Directive
How CSP works as a control against cross-site scripting and injection: the shape of a policy, why default-src matters, what 'unsafe-inline' and 'unsafe-eval' give away, how nonces and hashes allow specific inline code safely, and what report-only mode is for.
Security & WAFReadInside a SAML Assertion: Subject, Conditions, and Audience
The anatomy of a SAML assertion: the Subject and NameID formats, bearer SubjectConfirmation and the NotOnOrAfter / Recipient / InResponseTo checks, the Conditions validity window, the AudienceRestriction, and the AuthnStatement, with the validation a service provider must perform on each.
Security & WAFKimlik ve token'larReadRegex Groups, Backreferences, and Lookarounds
Parentheses do far more than set precedence in a regex. They capture text for you to reuse, name the pieces you care about, and — with a question mark prefix — let you assert what comes before or after without consuming it.
Security & WAFWeb & HTTPReadCatastrophic Backtracking and ReDoS
Some innocent-looking patterns can take seconds, minutes, or effectively forever on a short string. The cause is catastrophic backtracking, and when an attacker controls the input it becomes a denial-of-service bug. Here is why it happens and how to write patterns that cannot.
Security & WAFWeb & HTTPReadHSTS and HTTPS Enforcement
How Strict-Transport-Security closes the HTTP downgrade window, what max-age, includeSubDomains, and preload each do, the trust-on-first-use gap that preloading removes, and the configuration mistakes that quietly disable it.
Security & WAFReadSAML Signatures and XML-DSig
How a SAML message is signed with XML Signature: the enveloped ds:Signature, the SignatureMethod and DigestMethod algorithms, why SHA-1 is weak, the difference between signing the Response and signing the Assertion, and how XML signature wrapping attacks work.
Security & WAFKimlik ve token'larReadCookie Security Flags
How Secure, HttpOnly, and SameSite protect session cookies, what each SameSite value means, why SameSite=None requires Secure, and how the __Host- and __Secure- prefixes enforce those guarantees at the browser level.
Security & WAFReadRegex Anchors and Boundaries
Anchors match a position, not a character: the start or end of the string, or the edge of a word. They are the difference between a pattern that matches anywhere and one that matches only where you mean. This covers ^, $, \b, and their multiline behavior, plus the mistakes they cause.
Security & WAFWeb & HTTPReadXXE and Why a SAML Parser Rejects DOCTYPE
How XML External Entity (XXE) attacks work, the billion-laughs denial-of-service, why both depend on a DTD, and why a hardened SAML decoder rejects any DOCTYPE or entity declaration outright rather than trying to parse it safely.
Security & WAFKimlik ve token'larReadClickjacking and Frame Control
What clickjacking is, how framing makes it possible, the difference between the legacy X-Frame-Options header and the modern CSP frame-ancestors directive, why ALLOW-FROM is obsolete, and how the two controls interact.
Security & WAFReadRegex Flags and Modes
A flag changes how the whole pattern matches: case sensitivity, whether ^ and $ see lines, whether the dot crosses newlines, and whether whitespace in the pattern is ignored. The same regex can match completely different things depending on its flags, so knowing them prevents a lot of confusion.
Security & WAFWeb & HTTPReadSAML Bindings and SP vs IdP Initiation
A SAML flow can start at the service or at the identity provider, and the messages can travel by two different bindings: an HTTP redirect with the message packed into the URL, or an auto-submitting HTML form that POSTs it. Which binding carries which message, and where the flow begins, explains a lot of SSO behavior.
Security & WAFKimlik ve token'larReadThe SAML Proxy: Inserting an Identity Layer into a Session
A SAML proxy sits in the SSO flow rather than the packet path: it terminates the user's request, forces authentication against an identity provider, and only then lets the session through, using SAML's browser-redirect model. It can act as a service provider to the IdP and an identity provider to the app at once (a proxy or broker), which is how one login federates many downstream systems. This explains the roles, the flow, and why it is a proxy at all.
Security & WAFKimlik ve token'larReadReading OGNL in a WAF Log: What the Payload Was Trying to Do
An OGNL payload in a log has two halves worth telling apart: something that tries to switch off the expression sandbox, and something that tries to run a command. A payload with both is an exploitation attempt. A payload with only the second is usually a scanner working through a list. A payload with neither is a probe checking whether input gets evaluated at all - and that answer decides whether anything else in the list could ever work.
Security & WAFWeb & HTTPKodlama ve veriReadXXE and External Entities
XML lets a document declare entities, and an external entity can point at a file or URL. A parser that resolves one can be tricked into reading local files or making server-side requests, the XXE vulnerability. The fix is blunt and effective: do not process a DOCTYPE at all.
Security & WAFReadBillion Laughs and Entity Expansion
Entities can reference other entities, and if each one multiplies the last, a tiny document can expand to gigabytes and exhaust memory. The billion laughs attack weaponizes this into a denial of service. The defense is to cap expansion or refuse the DOCTYPE outright.
Security & WAFReadHow CVSS Scoring Works
CVSS turns a short vector string into a 0 to 10 severity number using a fixed formula. The Base score is built from two sub-scores: Exploitability (how reachable and easy the flaw is) and Impact (how bad the outcome is). Everything else refines that base. This is arithmetic, not opinion, which is why a calculator can reproduce any published score exactly.
Security & WAFReadThe CVSS Base Metrics, Explained
The Base score comes from eight metrics in two families. Four exploitability metrics (Attack Vector, Attack Complexity, Privileges Required, User Interaction) describe how hard the attack is, and four impact metrics (Scope, plus Confidentiality, Integrity, Availability) describe the damage. Scope is the subtle one: it is what lets a score exceed the vulnerable component's own boundary.
Security & WAFReadCVSS Temporal and Environmental Scores
The Base score is only the starting point. Temporal metrics lower it as facts emerge, such as a patch being released, and can only reduce the score. Environmental metrics let an organization re-score the flaw for its own systems by raising or lowering the importance of confidentiality, integrity, and availability and by overriding base metrics. Both are optional but produce a more honest number.
Security & WAFReadReading a CVSS Vector String
A CVSS vector is a compact, self-describing string: a version prefix followed by slash-separated metric:value pairs. Learning to read it directly, rather than trusting a rendered score, lets you spot transcription errors and understand exactly what a vendor claimed. The Base metrics are mandatory and the rest are optional.
Security & WAFReadCVSS Severity Bands, and What the Score Does Not Tell You
The 0 to 10 number maps to five qualitative bands from None to Critical. That mapping is useful for triage, but a CVSS Base score measures severity, not risk. It says nothing about whether a flaw is being exploited, how valuable the asset is, or what controls you have. Treating the base number as a priority queue is the most common way teams misuse CVSS.
Security & WAFReadCVSS v3.0, v3.1, and v4.0: What Changed
This decoder computes CVSS v3.0 and v3.1. The two v3 releases share a formula but differ in rounding and one environmental term, so scores can differ by a tenth. CVSS v4.0, released in 2023, is a larger redesign with new metric groups and no Scope metric, and its vectors are not compatible with v3 tooling. CVSS v2 is retired.
Security & WAFReadPassive TLS Fingerprinting: JA3, GREASE, and the Churn That Led to JA4
A ClientHello announces the client in the clear, and the combination of versions, ciphers, and extensions is characteristic of the software that sent it. This covers how JA3 turns that into a hash, why GREASE has to be stripped, how extension-order randomization broke JA3 (the churn), how JA3N and JA4 restore stability, and where a TLS fingerprint fits as a signal for secure web gateways and adaptive authentication.
Security & WAFReadWhat Is Server-Side Request Forgery (SSRF)
SSRF is a vulnerability where an attacker makes a server issue an HTTP request to a destination of the attacker's choosing. Because the request originates inside the server's network, it can reach internal services, cloud metadata, and loopback addresses that the attacker could never reach directly. The fix is to validate the destination, not the URL string.
Security & WAFReadPrivate, Reserved, and Public IP Ranges
An SSRF filter has to know which addresses are internal. This is the map: RFC 1918 private space, loopback, link-local, carrier-grade NAT, the documentation ranges, and everything else that is public and routable. Knowing the ranges is what turns a raw address into a safe-or-not decision.
Security & WAFReadIP Address Obfuscation Tricks
One IP address can be written in many forms: plain decimal, octal, hexadecimal, short-hand, and IPv4-mapped IPv6. Each form parses back to the same address, which is how attackers slip an internal target past a filter that only blocks the dotted-decimal spelling. This is why SSRF checks must decode, not string-match.
Security & WAFReadCloud Metadata Endpoints and SSRF
Every major cloud gives an instance a metadata service at a fixed link-local address, and it can return temporary credentials for the instance's role. That makes it the single highest-value SSRF target. Knowing the endpoints, and the IMDSv2-style defenses, is essential for both attack understanding and defense.
Security & WAFReadDefending Against SSRF with Allow-Lists
The durable SSRF defense is an allow-list of intended destinations, combined with resolving the address before you trust it and re-checking after redirects. Block-lists of internal ranges help, but they lose to obfuscation and DNS rebinding. This is the layered approach that holds up.
Security & WAFReadDangerous URL Schemes in SSRF
SSRF is not limited to http. Schemes like file, gopher, dict, and ftp let an attacker read local files or craft raw bytes to internal services such as Redis and SMTP. A URL fetcher that does not restrict the scheme hands an attacker a far more powerful primitive than a plain web request.
Security & WAFReadSSL Forward Proxy: How Outbound TLS Interception Works and What Breaks It
To inspect encrypted outbound traffic, a forward proxy performs a controlled man-in-the-middle: it terminates the user's TLS session, opens its own to the real server, and forges a certificate for that server signed by a private CA the organization's own devices trust. This explains the mechanics, the trust model that makes it safe (and dangerous), and why pinning, HSTS, and mutual TLS defeat it.
Security & WAFSertifikalar ve PKITLS ve taşımaReadThe LGPD for Engineers: The Vocabulary That Matters
Brazil's data protection law assigns you a role, gives you ten legal bases instead of one, and puts a three-working-day clock on breach notification. What controlador, operador, and encarregado mean when you are the one running the systems.
Security & WAFReadPassive Fingerprinting: What You Emit Without Being Asked
Every connection announces its stack before a byte of application data flows. How a TCP SYN, a User-Agent string, and the mere order of HTTP headers each identify a client - and why a mismatch between them is the classic proxy and bot tell.
Security & WAFAğReadCheck Point's Three-Tier Architecture: Management, Gateway, and SmartConsole
Check Point separates the place policy is written from the place it is enforced, and that split explains almost everything else about the platform: why you install policy rather than just save it, why SIC exists, and why a gateway keeps working when the management server is down.
Security & WAFReadCheck Point Administrators, Sessions, and Objects: Publish Is Not Install
Check Point gives every administrator a private working session, so your changes are invisible to colleagues until you publish and inert on the gateway until you install. Those are two separate actions and confusing them is the most common early mistake on the platform.
Security & WAFReadCheck Point Logging and Monitoring: Where Logs Go and How to Ask Them Questions
A log only exists if a rule was set to create it, and it only survives if a log server was there to receive it. Once both are true, the Logs and Monitor view is a query interface rather than a list, and learning to ask it questions is the difference between finding an answer in seconds and scrolling.
Security & WAFReadCheck Point Identity Awareness: Writing Rules About People Instead of Addresses
Identity Awareness lets a rule say who rather than where. The gateway has to learn the user-to-address mapping from somewhere, and which source you choose decides how quickly identities appear, how accurate they stay, and what happens when someone changes desk.
Security & WAFReadCheck Point HTTPS Inspection, Application Control, and URL Filtering
Most traffic is encrypted, so the controls that decide which applications and sites are permitted can only see what the handshake reveals unless the gateway decrypts. HTTPS Inspection is what makes the rest work fully, and it is also the feature most likely to break something on the day you enable it.
Security & WAFReadCheck Point Threat Prevention: The Blades, Profiles, and Prevent Versus Detect
Threat Prevention is several engines under one policy, each catching a different stage of an attack. The setting that matters most is not which engines are on but whether each is preventing or only detecting, because that single choice decides whether you have protection or a report.
Security & WAFReadCheck Point Management High Availability: Active, Standby, and Why Failover Is Manual
A second management server protects the database, not the traffic. Gateways keep enforcing whatever happens to management, so what you are buying is the ability to keep changing policy — and the synchronisation status is the thing that tells you whether you actually have it.
Security & WAFReadCheck Point Site-to-Site VPN: Communities, Encryption Domains, and Why the Tunnel Is Empty
A Check Point VPN is built from communities rather than individual tunnel definitions, which is what makes many sites manageable. The recurring fault is not that the tunnel fails to establish but that it establishes and carries nothing, and that almost always traces to the encryption domain or to NAT.
Security & WAFReadCheck Point SmartEvent and the Compliance Blade: Turning Logs into Events Worth Reading
SmartEvent correlates logs into events so that a hundred related entries become one thing a person acts on. The Compliance Blade audits the configuration itself against best practice. Both are only as useful as the tuning, and an untuned SmartEvent is a second place to ignore alerts.
Security & WAFReadCheck Point Upgrades and Migrations: Order, Compatibility, and Getting the Database Out
Upgrade order is not a preference: management goes first, because a management server can manage older gateways and an older management server cannot manage newer ones. Migration is a different operation from upgrading, and the thing being moved is the database rather than the machine.
Security & WAFReadCheck Point ElasticXL: One Cluster Object, Many Members
ElasticXL is Check Point's newer clustering approach, built so that a cluster is configured and managed as a single entity rather than as members that each need attention. The operational argument is that adding capacity should not mean repeating configuration.
Security & WAFReadHow a Proxy Knows Who You Are: User Authentication Methods Inline
Policy per user is the whole promise of an inline proxy - which means the proxy must attach an identity to every flow, including the ones that cannot log in. The four working patterns: explicit 407 challenges, cookie-based web authentication, agent-asserted identity, and the surrogate-IP compromise - plus where each one breaks, because every one of them breaks somewhere.
Security & WAFReadData Loss Prevention: How Machines Recognize Secrets
Every DLP product answers the same question - is this outbound content sensitive? - with the same four instruments: patterns, dictionaries, exact data matching against fingerprinted records, and indexed document matching against fingerprinted files. What each instrument can and cannot recognize, why confidence scores and proximity exist, and why the hard part of DLP was never the matching.
Security & WAFReadSandbox Detonation: Judging a File by What It Does
Signatures recognize malware that has been seen; a sandbox convicts malware that has not - by running the file in an instrumented cage and watching its behavior. What detonation actually observes, why verdicts take minutes, the patient-zero window that timing creates, how hash sharing turns one verdict into everyone's protection, and the evasion arms race that keeps cage-builders employed.
Security & WAFReadBrowser Isolation: When You Cannot Trust the Page, Move the Browser
Remote Browser Isolation stops asking whether a page is safe and removes the question: the real browser runs in a disposable cloud container, and the endpoint receives only a rendered projection - pixels or a reconstructed DOM. What each rendering mode trades, why isolation is the answer for the uncategorizable middle, what it costs, and where its honest limits sit.
Security & WAFReadCORS Explained: The Border Control of the Browser
CORS is the most misunderstood error message in web development, because it punishes the wrong mental model. It is not a wall - the same-origin policy is the wall; CORS is the door: a header protocol by which a server volunteers 'that other origin may read my responses.' Simple requests vs preflights, what OPTIONS is doing in your network tab, why credentials tighten every rule, why '*' is not the fix, and why CORS never protected the server in the first place.
Security & WAFWeb & HTTPReadLDAP search filters: reading the parentheses
Every directory query - PingDirectory, Active Directory, any LDAP server - comes down to one filter string in prefix notation. How to read it: the operators, the six match types, the escapes, the famous AD bit-filter OIDs, and why an unindexed filter can take down a directory.
Security & WAFKimlik ve token'larReadOAuth flows: choosing the grant in 2026
One decision starts every integration: which flow. The modern answer is short - authorization code + PKCE for humans, client credentials for machines, the device grant for TVs - and the reasons implicit and ROPC died are worth knowing by heart. RFC 9700 finally wrote it all down.
Security & WAFKimlik ve token'larReadMemory safety: the bug classes and the defenses that answer them
Buffer overflow, use-after-free, null dereference, integer overflow - four names for two failures, staying inside an object and only touching it while it is alive. How each one works, why roughly seventy percent of serious vulnerabilities in large C and C++ codebases belong to this family, and what each defensive layer actually buys.
Security & WAFReadTor: how onion routing actually works, and what it does not protect
Onion routing was invented at a US Navy lab, and that paradox is the key to understanding it: anonymity only works if the crowd is diverse. How a three-hop circuit is built, what onion services really are, the threat model Tor openly admits it loses to, and why most Tor traffic never touches the dark web at all.
Security & WAFReadDNS blocklists: RPZ, ratings, and what a refused answer costs
Blocking a domain at the resolver is the cheapest security control there is, which is why every vendor sells one. How RPZ feeds work, what a vendor DNS rating actually rates, the two failure modes nobody plans for, and why the block you cannot see is worse than the one you can.
Security & WAFRead
| Article | Topic | Summary |
|---|---|---|
| HTTP Security Headers: The Defense-in-Depth Layer | Security & WAF | What HTTP security headers are, why they form a layer of defense on top of secure code rather than a replacement for it, the headers that carry the most weight, and how to read a response's posture at a glance. |
| Regex Quantifiers and Character Classes | Security & WAFWeb & HTTP | A regular expression is built from two questions: what character do I want, and how many of them? Character classes answer the first, quantifiers answer the second. Get these two right and most of regex falls into place. |
| SAML 2.0: How Browser SSO Works | Security & WAFKimlik ve token'lar | What a SAML assertion is, the roles of the identity provider and service provider, the SP-initiated Web Browser SSO flow end to end, and the difference between the HTTP-POST and HTTP-Redirect bindings that carry the messages. |
| Content Security Policy, Directive by Directive | Security & WAF | How CSP works as a control against cross-site scripting and injection: the shape of a policy, why default-src matters, what 'unsafe-inline' and 'unsafe-eval' give away, how nonces and hashes allow specific inline code safely, and what report-only mode is for. |
| Inside a SAML Assertion: Subject, Conditions, and Audience | Security & WAFKimlik ve token'lar | The anatomy of a SAML assertion: the Subject and NameID formats, bearer SubjectConfirmation and the NotOnOrAfter / Recipient / InResponseTo checks, the Conditions validity window, the AudienceRestriction, and the AuthnStatement, with the validation a service provider must perform on each. |
| Regex Groups, Backreferences, and Lookarounds | Security & WAFWeb & HTTP | Parentheses do far more than set precedence in a regex. They capture text for you to reuse, name the pieces you care about, and — with a question mark prefix — let you assert what comes before or after without consuming it. |
| Catastrophic Backtracking and ReDoS | Security & WAFWeb & HTTP | Some innocent-looking patterns can take seconds, minutes, or effectively forever on a short string. The cause is catastrophic backtracking, and when an attacker controls the input it becomes a denial-of-service bug. Here is why it happens and how to write patterns that cannot. |
| HSTS and HTTPS Enforcement | Security & WAF | How Strict-Transport-Security closes the HTTP downgrade window, what max-age, includeSubDomains, and preload each do, the trust-on-first-use gap that preloading removes, and the configuration mistakes that quietly disable it. |
| SAML Signatures and XML-DSig | Security & WAFKimlik ve token'lar | How a SAML message is signed with XML Signature: the enveloped ds:Signature, the SignatureMethod and DigestMethod algorithms, why SHA-1 is weak, the difference between signing the Response and signing the Assertion, and how XML signature wrapping attacks work. |
| Cookie Security Flags | Security & WAF | How Secure, HttpOnly, and SameSite protect session cookies, what each SameSite value means, why SameSite=None requires Secure, and how the __Host- and __Secure- prefixes enforce those guarantees at the browser level. |
| Regex Anchors and Boundaries | Security & WAFWeb & HTTP | Anchors match a position, not a character: the start or end of the string, or the edge of a word. They are the difference between a pattern that matches anywhere and one that matches only where you mean. This covers ^, $, \b, and their multiline behavior, plus the mistakes they cause. |
| XXE and Why a SAML Parser Rejects DOCTYPE | Security & WAFKimlik ve token'lar | How XML External Entity (XXE) attacks work, the billion-laughs denial-of-service, why both depend on a DTD, and why a hardened SAML decoder rejects any DOCTYPE or entity declaration outright rather than trying to parse it safely. |
| Clickjacking and Frame Control | Security & WAF | What clickjacking is, how framing makes it possible, the difference between the legacy X-Frame-Options header and the modern CSP frame-ancestors directive, why ALLOW-FROM is obsolete, and how the two controls interact. |
| Regex Flags and Modes | Security & WAFWeb & HTTP | A flag changes how the whole pattern matches: case sensitivity, whether ^ and $ see lines, whether the dot crosses newlines, and whether whitespace in the pattern is ignored. The same regex can match completely different things depending on its flags, so knowing them prevents a lot of confusion. |
| SAML Bindings and SP vs IdP Initiation | Security & WAFKimlik ve token'lar | A SAML flow can start at the service or at the identity provider, and the messages can travel by two different bindings: an HTTP redirect with the message packed into the URL, or an auto-submitting HTML form that POSTs it. Which binding carries which message, and where the flow begins, explains a lot of SSO behavior. |
| The SAML Proxy: Inserting an Identity Layer into a Session | Security & WAFKimlik ve token'lar | A SAML proxy sits in the SSO flow rather than the packet path: it terminates the user's request, forces authentication against an identity provider, and only then lets the session through, using SAML's browser-redirect model. It can act as a service provider to the IdP and an identity provider to the app at once (a proxy or broker), which is how one login federates many downstream systems. This explains the roles, the flow, and why it is a proxy at all. |
| Reading OGNL in a WAF Log: What the Payload Was Trying to Do | Security & WAFWeb & HTTPKodlama ve veri | An OGNL payload in a log has two halves worth telling apart: something that tries to switch off the expression sandbox, and something that tries to run a command. A payload with both is an exploitation attempt. A payload with only the second is usually a scanner working through a list. A payload with neither is a probe checking whether input gets evaluated at all - and that answer decides whether anything else in the list could ever work. |
| XXE and External Entities | Security & WAF | XML lets a document declare entities, and an external entity can point at a file or URL. A parser that resolves one can be tricked into reading local files or making server-side requests, the XXE vulnerability. The fix is blunt and effective: do not process a DOCTYPE at all. |
| Billion Laughs and Entity Expansion | Security & WAF | Entities can reference other entities, and if each one multiplies the last, a tiny document can expand to gigabytes and exhaust memory. The billion laughs attack weaponizes this into a denial of service. The defense is to cap expansion or refuse the DOCTYPE outright. |
| How CVSS Scoring Works | Security & WAF | CVSS turns a short vector string into a 0 to 10 severity number using a fixed formula. The Base score is built from two sub-scores: Exploitability (how reachable and easy the flaw is) and Impact (how bad the outcome is). Everything else refines that base. This is arithmetic, not opinion, which is why a calculator can reproduce any published score exactly. |
| The CVSS Base Metrics, Explained | Security & WAF | The Base score comes from eight metrics in two families. Four exploitability metrics (Attack Vector, Attack Complexity, Privileges Required, User Interaction) describe how hard the attack is, and four impact metrics (Scope, plus Confidentiality, Integrity, Availability) describe the damage. Scope is the subtle one: it is what lets a score exceed the vulnerable component's own boundary. |
| CVSS Temporal and Environmental Scores | Security & WAF | The Base score is only the starting point. Temporal metrics lower it as facts emerge, such as a patch being released, and can only reduce the score. Environmental metrics let an organization re-score the flaw for its own systems by raising or lowering the importance of confidentiality, integrity, and availability and by overriding base metrics. Both are optional but produce a more honest number. |
| Reading a CVSS Vector String | Security & WAF | A CVSS vector is a compact, self-describing string: a version prefix followed by slash-separated metric:value pairs. Learning to read it directly, rather than trusting a rendered score, lets you spot transcription errors and understand exactly what a vendor claimed. The Base metrics are mandatory and the rest are optional. |
| CVSS Severity Bands, and What the Score Does Not Tell You | Security & WAF | The 0 to 10 number maps to five qualitative bands from None to Critical. That mapping is useful for triage, but a CVSS Base score measures severity, not risk. It says nothing about whether a flaw is being exploited, how valuable the asset is, or what controls you have. Treating the base number as a priority queue is the most common way teams misuse CVSS. |
| CVSS v3.0, v3.1, and v4.0: What Changed | Security & WAF | This decoder computes CVSS v3.0 and v3.1. The two v3 releases share a formula but differ in rounding and one environmental term, so scores can differ by a tenth. CVSS v4.0, released in 2023, is a larger redesign with new metric groups and no Scope metric, and its vectors are not compatible with v3 tooling. CVSS v2 is retired. |
| Passive TLS Fingerprinting: JA3, GREASE, and the Churn That Led to JA4 | Security & WAF | A ClientHello announces the client in the clear, and the combination of versions, ciphers, and extensions is characteristic of the software that sent it. This covers how JA3 turns that into a hash, why GREASE has to be stripped, how extension-order randomization broke JA3 (the churn), how JA3N and JA4 restore stability, and where a TLS fingerprint fits as a signal for secure web gateways and adaptive authentication. |
| What Is Server-Side Request Forgery (SSRF) | Security & WAF | SSRF is a vulnerability where an attacker makes a server issue an HTTP request to a destination of the attacker's choosing. Because the request originates inside the server's network, it can reach internal services, cloud metadata, and loopback addresses that the attacker could never reach directly. The fix is to validate the destination, not the URL string. |
| Private, Reserved, and Public IP Ranges | Security & WAF | An SSRF filter has to know which addresses are internal. This is the map: RFC 1918 private space, loopback, link-local, carrier-grade NAT, the documentation ranges, and everything else that is public and routable. Knowing the ranges is what turns a raw address into a safe-or-not decision. |
| IP Address Obfuscation Tricks | Security & WAF | One IP address can be written in many forms: plain decimal, octal, hexadecimal, short-hand, and IPv4-mapped IPv6. Each form parses back to the same address, which is how attackers slip an internal target past a filter that only blocks the dotted-decimal spelling. This is why SSRF checks must decode, not string-match. |
| Cloud Metadata Endpoints and SSRF | Security & WAF | Every major cloud gives an instance a metadata service at a fixed link-local address, and it can return temporary credentials for the instance's role. That makes it the single highest-value SSRF target. Knowing the endpoints, and the IMDSv2-style defenses, is essential for both attack understanding and defense. |
| Defending Against SSRF with Allow-Lists | Security & WAF | The durable SSRF defense is an allow-list of intended destinations, combined with resolving the address before you trust it and re-checking after redirects. Block-lists of internal ranges help, but they lose to obfuscation and DNS rebinding. This is the layered approach that holds up. |
| Dangerous URL Schemes in SSRF | Security & WAF | SSRF is not limited to http. Schemes like file, gopher, dict, and ftp let an attacker read local files or craft raw bytes to internal services such as Redis and SMTP. A URL fetcher that does not restrict the scheme hands an attacker a far more powerful primitive than a plain web request. |
| SSL Forward Proxy: How Outbound TLS Interception Works and What Breaks It | Security & WAFSertifikalar ve PKITLS ve taşıma | To inspect encrypted outbound traffic, a forward proxy performs a controlled man-in-the-middle: it terminates the user's TLS session, opens its own to the real server, and forges a certificate for that server signed by a private CA the organization's own devices trust. This explains the mechanics, the trust model that makes it safe (and dangerous), and why pinning, HSTS, and mutual TLS defeat it. |
| The LGPD for Engineers: The Vocabulary That Matters | Security & WAF | Brazil's data protection law assigns you a role, gives you ten legal bases instead of one, and puts a three-working-day clock on breach notification. What controlador, operador, and encarregado mean when you are the one running the systems. |
| Passive Fingerprinting: What You Emit Without Being Asked | Security & WAFAğ | Every connection announces its stack before a byte of application data flows. How a TCP SYN, a User-Agent string, and the mere order of HTTP headers each identify a client - and why a mismatch between them is the classic proxy and bot tell. |
| Check Point's Three-Tier Architecture: Management, Gateway, and SmartConsole | Security & WAF | Check Point separates the place policy is written from the place it is enforced, and that split explains almost everything else about the platform: why you install policy rather than just save it, why SIC exists, and why a gateway keeps working when the management server is down. |
| Check Point Administrators, Sessions, and Objects: Publish Is Not Install | Security & WAF | Check Point gives every administrator a private working session, so your changes are invisible to colleagues until you publish and inert on the gateway until you install. Those are two separate actions and confusing them is the most common early mistake on the platform. |
| Check Point Logging and Monitoring: Where Logs Go and How to Ask Them Questions | Security & WAF | A log only exists if a rule was set to create it, and it only survives if a log server was there to receive it. Once both are true, the Logs and Monitor view is a query interface rather than a list, and learning to ask it questions is the difference between finding an answer in seconds and scrolling. |
| Check Point Identity Awareness: Writing Rules About People Instead of Addresses | Security & WAF | Identity Awareness lets a rule say who rather than where. The gateway has to learn the user-to-address mapping from somewhere, and which source you choose decides how quickly identities appear, how accurate they stay, and what happens when someone changes desk. |
| Check Point HTTPS Inspection, Application Control, and URL Filtering | Security & WAF | Most traffic is encrypted, so the controls that decide which applications and sites are permitted can only see what the handshake reveals unless the gateway decrypts. HTTPS Inspection is what makes the rest work fully, and it is also the feature most likely to break something on the day you enable it. |
| Check Point Threat Prevention: The Blades, Profiles, and Prevent Versus Detect | Security & WAF | Threat Prevention is several engines under one policy, each catching a different stage of an attack. The setting that matters most is not which engines are on but whether each is preventing or only detecting, because that single choice decides whether you have protection or a report. |
| Check Point Management High Availability: Active, Standby, and Why Failover Is Manual | Security & WAF | A second management server protects the database, not the traffic. Gateways keep enforcing whatever happens to management, so what you are buying is the ability to keep changing policy — and the synchronisation status is the thing that tells you whether you actually have it. |
| Check Point Site-to-Site VPN: Communities, Encryption Domains, and Why the Tunnel Is Empty | Security & WAF | A Check Point VPN is built from communities rather than individual tunnel definitions, which is what makes many sites manageable. The recurring fault is not that the tunnel fails to establish but that it establishes and carries nothing, and that almost always traces to the encryption domain or to NAT. |
| Check Point SmartEvent and the Compliance Blade: Turning Logs into Events Worth Reading | Security & WAF | SmartEvent correlates logs into events so that a hundred related entries become one thing a person acts on. The Compliance Blade audits the configuration itself against best practice. Both are only as useful as the tuning, and an untuned SmartEvent is a second place to ignore alerts. |
| Check Point Upgrades and Migrations: Order, Compatibility, and Getting the Database Out | Security & WAF | Upgrade order is not a preference: management goes first, because a management server can manage older gateways and an older management server cannot manage newer ones. Migration is a different operation from upgrading, and the thing being moved is the database rather than the machine. |
| Check Point ElasticXL: One Cluster Object, Many Members | Security & WAF | ElasticXL is Check Point's newer clustering approach, built so that a cluster is configured and managed as a single entity rather than as members that each need attention. The operational argument is that adding capacity should not mean repeating configuration. |
| How a Proxy Knows Who You Are: User Authentication Methods Inline | Security & WAF | Policy per user is the whole promise of an inline proxy - which means the proxy must attach an identity to every flow, including the ones that cannot log in. The four working patterns: explicit 407 challenges, cookie-based web authentication, agent-asserted identity, and the surrogate-IP compromise - plus where each one breaks, because every one of them breaks somewhere. |
| Data Loss Prevention: How Machines Recognize Secrets | Security & WAF | Every DLP product answers the same question - is this outbound content sensitive? - with the same four instruments: patterns, dictionaries, exact data matching against fingerprinted records, and indexed document matching against fingerprinted files. What each instrument can and cannot recognize, why confidence scores and proximity exist, and why the hard part of DLP was never the matching. |
| Sandbox Detonation: Judging a File by What It Does | Security & WAF | Signatures recognize malware that has been seen; a sandbox convicts malware that has not - by running the file in an instrumented cage and watching its behavior. What detonation actually observes, why verdicts take minutes, the patient-zero window that timing creates, how hash sharing turns one verdict into everyone's protection, and the evasion arms race that keeps cage-builders employed. |
| Browser Isolation: When You Cannot Trust the Page, Move the Browser | Security & WAF | Remote Browser Isolation stops asking whether a page is safe and removes the question: the real browser runs in a disposable cloud container, and the endpoint receives only a rendered projection - pixels or a reconstructed DOM. What each rendering mode trades, why isolation is the answer for the uncategorizable middle, what it costs, and where its honest limits sit. |
| CORS Explained: The Border Control of the Browser | Security & WAFWeb & HTTP | CORS is the most misunderstood error message in web development, because it punishes the wrong mental model. It is not a wall - the same-origin policy is the wall; CORS is the door: a header protocol by which a server volunteers 'that other origin may read my responses.' Simple requests vs preflights, what OPTIONS is doing in your network tab, why credentials tighten every rule, why '*' is not the fix, and why CORS never protected the server in the first place. |
| LDAP search filters: reading the parentheses | Security & WAFKimlik ve token'lar | Every directory query - PingDirectory, Active Directory, any LDAP server - comes down to one filter string in prefix notation. How to read it: the operators, the six match types, the escapes, the famous AD bit-filter OIDs, and why an unindexed filter can take down a directory. |
| OAuth flows: choosing the grant in 2026 | Security & WAFKimlik ve token'lar | One decision starts every integration: which flow. The modern answer is short - authorization code + PKCE for humans, client credentials for machines, the device grant for TVs - and the reasons implicit and ROPC died are worth knowing by heart. RFC 9700 finally wrote it all down. |
| Memory safety: the bug classes and the defenses that answer them | Security & WAF | Buffer overflow, use-after-free, null dereference, integer overflow - four names for two failures, staying inside an object and only touching it while it is alive. How each one works, why roughly seventy percent of serious vulnerabilities in large C and C++ codebases belong to this family, and what each defensive layer actually buys. |
| Tor: how onion routing actually works, and what it does not protect | Security & WAF | Onion routing was invented at a US Navy lab, and that paradox is the key to understanding it: anonymity only works if the crowd is diverse. How a three-hop circuit is built, what onion services really are, the threat model Tor openly admits it loses to, and why most Tor traffic never touches the dark web at all. |
| DNS blocklists: RPZ, ratings, and what a refused answer costs | Security & WAF | Blocking a domain at the resolver is the cheapest security control there is, which is why every vendor sells one. How RPZ feeds work, what a vendor DNS rating actually rates, the two failure modes nobody plans for, and why the block you cannot see is worse than the one you can. |
Sertifikalar ve PKI (14)
Bir X.509 sertifikasının anatomisi
Bir TLS sertifikasının içinde ne yaşadığı, ASN.1/DER baytlarının nasıl yapılandırıldığı, v3 uzantılarının aslında neyi denetlediği ve bir sertifikayı kod çözmenin ona güvenmekle aynı şey olmadığı.
Sertifikalar ve PKIReadPEM, DER ve sertifika dosya biçimleri
Aynı sertifikanın neden bu kadar çok dosya biçiminde geldiği, PEM ve DER'in aslında ne olduğu ve .crt, .pem, .pfx ile .p12'nin gerçekte ne tuttuğu.
Sertifikalar ve PKIReadSertifika imzalama istekleri ve sertifikaların nasıl verildiği
Bir CSR'nin ne içerdiği, özel anahtarınızın neden asla makinenizden ayrılmadığı, bir CA'nın nasıl doğruladığı ve verdiği, ve ACME'nin tüm alışverişi nasıl otomatikleştirdiği.
Sertifikalar ve PKIReadSertifika doğrulaması aslında nasıl çalışır
Bir istemcinin bir sertifikanın güvenilir olduğuna karar vermek için çalıştırdığı adımlar: zinciri kurmak, imzaları ve tarihleri denetlemek, adı eşleştirmek ve kısıtlamaları uygulamak.
Sertifikalar ve PKIReadSertifika iptali: CRL, OCSP ve kısa ömürlü sertifikalar
Bir sertifikanın bazen süresi dolmadan iptal edilmesi gerektiği, klasik iptal sistemlerinin neden zayıf çalıştığı ve sektörün bunun yerine neden sertifika ömürlerini küçülttüğü.
Sertifikalar ve PKIReadAuthority Information Access: The OCSP and CA Issuers URLs
The AIA extension carries two kinds of pointer: where to ask whether a certificate is revoked (OCSP) and where to fetch the issuer's own certificate (CA Issuers). What each is for, why they are easy to confuse, and what the inspector shows.
Sertifikalar ve PKIReadOCSP Must-Staple: Closing the Soft-Fail Gap
Real-time OCSP checking has a fatal weakness: when the responder is unreachable, clients usually proceed anyway. OCSP stapling and the Must-Staple flag are the fix. What the TLS Feature extension declares, and the operational risk it carries.
Sertifikalar ve PKIReadACME: how certificates issue and renew themselves
How the ACME protocol automates certificate issuance end to end: the account, the order, the three challenge types, the dns-01 record you publish, and the finalize-and-download step that produces the certificate.
Sertifikalar ve PKIReadThe 47-day era: how TLS certificate lifetimes are shrinking
The CA/Browser Forum's SC-081v3 schedule takes maximum public TLS validity from 398 days down to 47 by 2029, in three steps. What the phases are, why 47, and what it does to renewal volume.
Sertifikalar ve PKIReadCertificate validity windows: notBefore, notAfter, and renewal lead time
How a certificate's lifetime is defined by two timestamps, how that length is measured against the cap, why validity is not the same as time remaining, and how to choose a renewal lead time.
Sertifikalar ve PKIReadLet's Encrypt: the free CA and its rate limits
What Let's Encrypt is, why its certificates are short-lived, and how its rate limits actually work: the per-registered-domain and per-account limits, the exact-set and authorization-failure limits, and why ARI renewals are exempt from all of them.
Sertifikalar ve PKIReadDCV and SII reuse: the validation cadence behind the renewal cadence
Issuing a certificate means proving domain control and, for OV/EV, organization identity. SC-081v3 shrinks how long those proofs can be reused — DCV to 10 days by 2029 — which reshapes renewal as much as validity does.
Sertifikalar ve PKIReadRenewing before expiry: lead time, ACME, and ARI
Why late renewal causes outages, how ACME automates issuance and renewal, how the ARI extension lets a CA steer the renewal window, and how to pick a lead time that leaves room to retry.
Sertifikalar ve PKIReadPublic vs private PKI: which certificates SC-081v3 governs
The 47-day schedule binds publicly trusted TLS certificates only. What separates public from private PKI, why internal CAs are exempt, and how to read the planner's compliance verdict for an internal certificate.
Sertifikalar ve PKIRead
| Article | Topic | Summary |
|---|---|---|
| Bir X.509 sertifikasının anatomisi | Sertifikalar ve PKI | Bir TLS sertifikasının içinde ne yaşadığı, ASN.1/DER baytlarının nasıl yapılandırıldığı, v3 uzantılarının aslında neyi denetlediği ve bir sertifikayı kod çözmenin ona güvenmekle aynı şey olmadığı. |
| PEM, DER ve sertifika dosya biçimleri | Sertifikalar ve PKI | Aynı sertifikanın neden bu kadar çok dosya biçiminde geldiği, PEM ve DER'in aslında ne olduğu ve .crt, .pem, .pfx ile .p12'nin gerçekte ne tuttuğu. |
| Sertifika imzalama istekleri ve sertifikaların nasıl verildiği | Sertifikalar ve PKI | Bir CSR'nin ne içerdiği, özel anahtarınızın neden asla makinenizden ayrılmadığı, bir CA'nın nasıl doğruladığı ve verdiği, ve ACME'nin tüm alışverişi nasıl otomatikleştirdiği. |
| Sertifika doğrulaması aslında nasıl çalışır | Sertifikalar ve PKI | Bir istemcinin bir sertifikanın güvenilir olduğuna karar vermek için çalıştırdığı adımlar: zinciri kurmak, imzaları ve tarihleri denetlemek, adı eşleştirmek ve kısıtlamaları uygulamak. |
| Sertifika iptali: CRL, OCSP ve kısa ömürlü sertifikalar | Sertifikalar ve PKI | Bir sertifikanın bazen süresi dolmadan iptal edilmesi gerektiği, klasik iptal sistemlerinin neden zayıf çalıştığı ve sektörün bunun yerine neden sertifika ömürlerini küçülttüğü. |
| Authority Information Access: The OCSP and CA Issuers URLs | Sertifikalar ve PKI | The AIA extension carries two kinds of pointer: where to ask whether a certificate is revoked (OCSP) and where to fetch the issuer's own certificate (CA Issuers). What each is for, why they are easy to confuse, and what the inspector shows. |
| OCSP Must-Staple: Closing the Soft-Fail Gap | Sertifikalar ve PKI | Real-time OCSP checking has a fatal weakness: when the responder is unreachable, clients usually proceed anyway. OCSP stapling and the Must-Staple flag are the fix. What the TLS Feature extension declares, and the operational risk it carries. |
| ACME: how certificates issue and renew themselves | Sertifikalar ve PKI | How the ACME protocol automates certificate issuance end to end: the account, the order, the three challenge types, the dns-01 record you publish, and the finalize-and-download step that produces the certificate. |
| The 47-day era: how TLS certificate lifetimes are shrinking | Sertifikalar ve PKI | The CA/Browser Forum's SC-081v3 schedule takes maximum public TLS validity from 398 days down to 47 by 2029, in three steps. What the phases are, why 47, and what it does to renewal volume. |
| Certificate validity windows: notBefore, notAfter, and renewal lead time | Sertifikalar ve PKI | How a certificate's lifetime is defined by two timestamps, how that length is measured against the cap, why validity is not the same as time remaining, and how to choose a renewal lead time. |
| Let's Encrypt: the free CA and its rate limits | Sertifikalar ve PKI | What Let's Encrypt is, why its certificates are short-lived, and how its rate limits actually work: the per-registered-domain and per-account limits, the exact-set and authorization-failure limits, and why ARI renewals are exempt from all of them. |
| DCV and SII reuse: the validation cadence behind the renewal cadence | Sertifikalar ve PKI | Issuing a certificate means proving domain control and, for OV/EV, organization identity. SC-081v3 shrinks how long those proofs can be reused — DCV to 10 days by 2029 — which reshapes renewal as much as validity does. |
| Renewing before expiry: lead time, ACME, and ARI | Sertifikalar ve PKI | Why late renewal causes outages, how ACME automates issuance and renewal, how the ARI extension lets a CA steer the renewal window, and how to pick a lead time that leaves room to retry. |
| Public vs private PKI: which certificates SC-081v3 governs | Sertifikalar ve PKI | The 47-day schedule binds publicly trusted TLS certificates only. What separates public from private PKI, why internal CAs are exempt, and how to read the planner's compliance verdict for an internal certificate. |
Tanımlayıcılar (5)
UUID'ler: rastgele v4 ve zaman sıralı v7
128 bitlik bir tanımlayıcının merkezi bir otorite olmadan nasıl benzersiz kaldığı ve v7'nin veritabanı anahtarları için neden varsayılan hâline geldiği.
TanımlayıcılarReadUUID sürümleri açıklandı: v1'den v8'e
Tüm UUID ailesi tek bir yerde, zaman-ve-MAC v1'den rastgele v4'e ve zaman sıralı v7'ye, artı ad tabanlı sürümler ve sürüm ile varyant bitlerinin nasıl okunduğu.
TanımlayıcılarReadUUID'ler çakışır mı? Olasılık ve doğum günü sınırı
Bir UUID'nin gerçekte kaç rastgele bite sahip olduğu, bir çakışma için doğum günü matematiği ve ne zaman deterministik UUID'ler istendiği.
TanımlayıcılarReadVeritabanı anahtarı olarak UUID'ler: v4, v7 ve dizin yerelliği
UUID'ler ile otomatik artan tam sayılar arasındaki gerçek ödünleşim ve rastgele v4 anahtarlarının veritabanı başarımına nasıl sessizce zarar verdiği.
TanımlayıcılarReadULID, KSUID, Snowflake ve diğer sıralanabilir kimlikler
Zaman sıralı tanımlayıcılar için UUID'lere popüler alternatifler, her birinin nasıl kurulduğu ve UUIDv7'nin artık icat edildikleri şeyin çoğunu nasıl kapsadığı.
TanımlayıcılarRead
| Article | Topic | Summary |
|---|---|---|
| UUID'ler: rastgele v4 ve zaman sıralı v7 | Tanımlayıcılar | 128 bitlik bir tanımlayıcının merkezi bir otorite olmadan nasıl benzersiz kaldığı ve v7'nin veritabanı anahtarları için neden varsayılan hâline geldiği. |
| UUID sürümleri açıklandı: v1'den v8'e | Tanımlayıcılar | Tüm UUID ailesi tek bir yerde, zaman-ve-MAC v1'den rastgele v4'e ve zaman sıralı v7'ye, artı ad tabanlı sürümler ve sürüm ile varyant bitlerinin nasıl okunduğu. |
| UUID'ler çakışır mı? Olasılık ve doğum günü sınırı | Tanımlayıcılar | Bir UUID'nin gerçekte kaç rastgele bite sahip olduğu, bir çakışma için doğum günü matematiği ve ne zaman deterministik UUID'ler istendiği. |
| Veritabanı anahtarı olarak UUID'ler: v4, v7 ve dizin yerelliği | Tanımlayıcılar | UUID'ler ile otomatik artan tam sayılar arasındaki gerçek ödünleşim ve rastgele v4 anahtarlarının veritabanı başarımına nasıl sessizce zarar verdiği. |
| ULID, KSUID, Snowflake ve diğer sıralanabilir kimlikler | Tanımlayıcılar | Zaman sıralı tanımlayıcılar için UUID'lere popüler alternatifler, her birinin nasıl kurulduğu ve UUIDv7'nin artık icat edildikleri şeyin çoğunu nasıl kapsadığı. |
Text & utilities (1)
| Article | Topic | Summary |
|---|---|---|
| The Greek Alphabet: Engineering's Second Alphabet | Text & utilities | Why Ω means ohms, μ means micro, and λ runs both wavelengths and serverless functions. The 24 letters, the final-sigma rule, and the transliteration gotchas between modern and classical Greek that quietly rename beta and eta. |
TLS ve taşıma (12)
Bir TLS şifre paketinin anatomisi
Bir TLS şifre paketinin gerçekte neyi adlandırdığı, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 gibi bir paketin parça parça nasıl okunacağı ve aynı iki baytlık kod noktasının üç farklı adlandırma kuralı altında nasıl göründüğü.
TLS ve taşımaReadŞifre paketi adlarını okumak: IANA, OpenSSL ve GnuTLS
Aynı şifre paketinin neden üç farklı adı ve iki baytlık bir kod noktası olduğu, IANA, OpenSSL ve GnuTLS kuralları arasında nasıl çeviri yapılacağı ve IANA'nın Y, N ve D içeren Recommended sütununun gerçekte ne anlama geldiği.
TLS ve taşımaReadAEAD'a karşı CBC: mod neden önemlidir
AES-GCM gibi bir AEAD şifresi ile ayrı bir HMAC'li daha eski bir CBC şifresi arasındaki pratik fark, MAC-then-encrypt'i ortadan kaldıran dolgu kâhini saldırıları ve AEAD'ın hâlâ istediği tek ödün.
TLS ve taşımaReadİleri gizlilik ve anahtar değişimi
İleri gizliliğin ne sağladığı, statik RSA anahtar taşımasının neden onu sunmadığı, ECDHE ile DHE'nin nasıl sunduğu ve kimlik doğrulama ile anahtar değişiminin, bir paketin adının ayrı tuttuğu iki farklı görev olduğu.
TLS ve taşımaReadTLS 1.3 şifre paketleri: neler değişti
Bir TLS 1.3 paketinin neden yalnızca bir şifre ve bir özet adlandırdığı, anahtar değişimi ile kimlik doğrulamanın nereye gittiği ve paket listesinin neden yüzlerceden bir avuca düştüğü.
TLS ve taşımaReadWhat a Quantum Computer Would Break, and What It Would Not
A large quantum computer would not weaken all cryptography equally. Shor's algorithm breaks the public-key math behind RSA, Diffie-Hellman, and elliptic curves outright; Grover's algorithm only halves the strength of symmetric ciphers and hashes, which AES-256 and SHA-384 already survive. This explains the split, why 'harvest now, decrypt later' makes it a today problem, and why a broken candidate like SIKE is a reminder to stay humble.
TLS ve taşımaReadThe NIST Post-Quantum Standards: ML-KEM, ML-DSA, and SLH-DSA
In August 2024 NIST finalized the first three post-quantum standards: FIPS 203 (ML-KEM, from Kyber) for key establishment, and FIPS 204 (ML-DSA, from Dilithium) and FIPS 205 (SLH-DSA, from SPHINCS+) for signatures. This explains what each one is for, why there are two signature standards on different math, and where HQC and FN-DSA fit as the backups still coming down the pipeline.
TLS ve taşımaReadHybrid Key Exchange in TLS 1.3: What X25519MLKEM768 Does on the Wire
The web did not swap classical key exchange for post-quantum; it runs both at once. X25519MLKEM768 combines a 1990s elliptic curve with lattice-based ML-KEM-768 in a single TLS 1.3 group, so a break of either still leaves the session secure. This covers why hybrid rather than replacement, the wire format and its size problem, and where deployment stands across browsers, servers, and the middleboxes it breaks.
TLS ve taşımaReadInbound TLS: Offload, Bridging, and Passthrough at the Reverse Proxy
A reverse proxy handling inbound HTTPS has three choices for the TLS session: terminate it and send plaintext to the backend (offload), terminate and re-encrypt to the backend (bridging), or forward the encrypted bytes untouched (passthrough). Each trades visibility against confidentiality and cost differently. This explains all three, why the proxy holds the server's certificate, and what SNI and mutual TLS change.
TLS ve taşımaSertifikalar ve PKIReadTLS 1.2 vs TLS 1.3 vs DTLS vs QUIC: One Handshake Family, Four Shapes
TLS 1.2 and TLS 1.3 secure a TCP stream, DTLS carries the same guarantees over datagrams, and QUIC absorbs the TLS 1.3 handshake into the transport itself. What each one is, which RFC defines it today, what actually changed between them, and where each one runs.
TLS ve taşımaReadWhat Is a JA4 TLS Fingerprint?
How a TLS ClientHello becomes a stable fingerprint of the client software, why JA3 faded once browsers began randomizing extension order, how JA4 fixes that by sorting before hashing, and what JA4 can and cannot tell you.
TLS ve taşımaSecurity & WAFReadWhy Do We Say SSL When We Mean TLS?
SSL has been prohibited, deprecated, and dead for years - and the industry still sells 'SSL certificates,' configures 'SSL inspection,' and links openssl. The history explains the habit: Netscape's SSL, the political rename to TLS in 1999 (the wire version field still said 3.1), and a quarter century of marketing inertia. Plus the musing the question deserves: what would a protocol-independent name even look like, and do any exist?
TLS ve taşımaRead
| Article | Topic | Summary |
|---|---|---|
| Bir TLS şifre paketinin anatomisi | TLS ve taşıma | Bir TLS şifre paketinin gerçekte neyi adlandırdığı, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 gibi bir paketin parça parça nasıl okunacağı ve aynı iki baytlık kod noktasının üç farklı adlandırma kuralı altında nasıl göründüğü. |
| Şifre paketi adlarını okumak: IANA, OpenSSL ve GnuTLS | TLS ve taşıma | Aynı şifre paketinin neden üç farklı adı ve iki baytlık bir kod noktası olduğu, IANA, OpenSSL ve GnuTLS kuralları arasında nasıl çeviri yapılacağı ve IANA'nın Y, N ve D içeren Recommended sütununun gerçekte ne anlama geldiği. |
| AEAD'a karşı CBC: mod neden önemlidir | TLS ve taşıma | AES-GCM gibi bir AEAD şifresi ile ayrı bir HMAC'li daha eski bir CBC şifresi arasındaki pratik fark, MAC-then-encrypt'i ortadan kaldıran dolgu kâhini saldırıları ve AEAD'ın hâlâ istediği tek ödün. |
| İleri gizlilik ve anahtar değişimi | TLS ve taşıma | İleri gizliliğin ne sağladığı, statik RSA anahtar taşımasının neden onu sunmadığı, ECDHE ile DHE'nin nasıl sunduğu ve kimlik doğrulama ile anahtar değişiminin, bir paketin adının ayrı tuttuğu iki farklı görev olduğu. |
| TLS 1.3 şifre paketleri: neler değişti | TLS ve taşıma | Bir TLS 1.3 paketinin neden yalnızca bir şifre ve bir özet adlandırdığı, anahtar değişimi ile kimlik doğrulamanın nereye gittiği ve paket listesinin neden yüzlerceden bir avuca düştüğü. |
| What a Quantum Computer Would Break, and What It Would Not | TLS ve taşıma | A large quantum computer would not weaken all cryptography equally. Shor's algorithm breaks the public-key math behind RSA, Diffie-Hellman, and elliptic curves outright; Grover's algorithm only halves the strength of symmetric ciphers and hashes, which AES-256 and SHA-384 already survive. This explains the split, why 'harvest now, decrypt later' makes it a today problem, and why a broken candidate like SIKE is a reminder to stay humble. |
| The NIST Post-Quantum Standards: ML-KEM, ML-DSA, and SLH-DSA | TLS ve taşıma | In August 2024 NIST finalized the first three post-quantum standards: FIPS 203 (ML-KEM, from Kyber) for key establishment, and FIPS 204 (ML-DSA, from Dilithium) and FIPS 205 (SLH-DSA, from SPHINCS+) for signatures. This explains what each one is for, why there are two signature standards on different math, and where HQC and FN-DSA fit as the backups still coming down the pipeline. |
| Hybrid Key Exchange in TLS 1.3: What X25519MLKEM768 Does on the Wire | TLS ve taşıma | The web did not swap classical key exchange for post-quantum; it runs both at once. X25519MLKEM768 combines a 1990s elliptic curve with lattice-based ML-KEM-768 in a single TLS 1.3 group, so a break of either still leaves the session secure. This covers why hybrid rather than replacement, the wire format and its size problem, and where deployment stands across browsers, servers, and the middleboxes it breaks. |
| Inbound TLS: Offload, Bridging, and Passthrough at the Reverse Proxy | TLS ve taşımaSertifikalar ve PKI | A reverse proxy handling inbound HTTPS has three choices for the TLS session: terminate it and send plaintext to the backend (offload), terminate and re-encrypt to the backend (bridging), or forward the encrypted bytes untouched (passthrough). Each trades visibility against confidentiality and cost differently. This explains all three, why the proxy holds the server's certificate, and what SNI and mutual TLS change. |
| TLS 1.2 vs TLS 1.3 vs DTLS vs QUIC: One Handshake Family, Four Shapes | TLS ve taşıma | TLS 1.2 and TLS 1.3 secure a TCP stream, DTLS carries the same guarantees over datagrams, and QUIC absorbs the TLS 1.3 handshake into the transport itself. What each one is, which RFC defines it today, what actually changed between them, and where each one runs. |
| What Is a JA4 TLS Fingerprint? | TLS ve taşımaSecurity & WAF | How a TLS ClientHello becomes a stable fingerprint of the client software, why JA3 faded once browsers began randomizing extension order, how JA4 fixes that by sorting before hashing, and what JA4 can and cannot tell you. |
| Why Do We Say SSL When We Mean TLS? | TLS ve taşıma | SSL has been prohibited, deprecated, and dead for years - and the industry still sells 'SSL certificates,' configures 'SSL inspection,' and links openssl. The history explains the habit: Netscape's SSL, the political rename to TLS in 1999 (the wire version field still said 3.1), and a quarter century of marketing inertia. Plus the musing the question deserves: what would a protocol-independent name even look like, and do any exist? |