<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Guler Tech Ltd</title>
  <description>Penetration testing notes and research by Guler Tech Ltd — web, mobile, API, network/AD, cloud and privilege-escalation writeups from real engagements and lab work.</description>
  <link>https://gulertech.co.uk/</link>
  <atom:link href="https://gulertech.co.uk/feed.xml" rel="self" type="application/rss+xml"/>
  <lastBuildDate>Thu, 03 Sep 2026 00:57:23 +0100</lastBuildDate>
  
  <item>
    <title>Memory Corruption in Android Apps: Where It Still Applies (MASTG-KNOW-0005)</title>
    <description>ART protects managed code, not JNI/NDK. What to test in native libraries, why MASTG dropped its black-box tests, and how to scope this in a report.</description>
    <pubDate>Wed, 02 Sep 2026 00:00:00 +0100</pubDate>
    <link>https://gulertech.co.uk/mobile/mastg-know-0005-memory-corruption-bugs/</link>
    <guid isPermaLink="true">https://gulertech.co.uk/mobile/mastg-know-0005-memory-corruption-bugs/</guid>
    <category>android</category><category>ndk</category><category>jni</category><category>native</category><category>memory-safety</category><category>ghidra</category><category>masvs-code</category>
  </item>
  
  <item>
    <title>Third-Party Libraries in Android Apps (MASTG-KNOW-0004)</title>
    <description>Identifying bundled dependencies in an APK, mapping them to known CVEs, and the licence exposure most reports leave out.</description>
    <pubDate>Wed, 02 Sep 2026 00:00:00 +0100</pubDate>
    <link>https://gulertech.co.uk/mobile/mastg-know-0004-third-party-libraries/</link>
    <guid isPermaLink="true">https://gulertech.co.uk/mobile/mastg-know-0004-third-party-libraries/</guid>
    <category>android</category><category>sca</category><category>dependencies</category><category>cve</category><category>supply-chain</category><category>masvs-code</category>
  </item>
  
  <item>
    <title>Android App Signing: v1/v2/v3 Schemes and How to Verify Them (MASTG-KNOW-0003)</title>
    <description>Signature schemes, debug-key detection, certificate validity requirements, and why a v1-only APK is a repackaging finding.</description>
    <pubDate>Wed, 02 Sep 2026 00:00:00 +0100</pubDate>
    <link>https://gulertech.co.uk/mobile/mastg-know-0003-app-signing/</link>
    <guid isPermaLink="true">https://gulertech.co.uk/mobile/mastg-know-0003-app-signing/</guid>
    <category>android</category><category>apk</category><category>code-signing</category><category>apksigner</category><category>repackaging</category><category>masvs-resilience</category>
  </item>
  
  <item>
    <title>FingerprintManager: Testing Legacy Android Fingerprint Auth (MASTG-KNOW-0002)</title>
    <description>The deprecated pre-API 28 fingerprint API — what a correct implementation looks like, the five prerequisite checks, and how to spot the null-CryptoObject pattern.</description>
    <pubDate>Wed, 02 Sep 2026 00:00:00 +0100</pubDate>
    <link>https://gulertech.co.uk/mobile/mastg-know-0002-fingerprintmanager/</link>
    <guid isPermaLink="true">https://gulertech.co.uk/mobile/mastg-know-0002-fingerprintmanager/</guid>
    <category>android</category><category>biometrics</category><category>fingerprintmanager</category><category>keystore</category><category>legacy</category>
  </item>
  
  <item>
    <title>Android Biometric Authentication (MASTG-KNOW-0001)</title>
    <description>How Android biometric auth actually works, why event-bound implementations are trivially bypassed, and how to test for Keystore-backed flows.</description>
    <pubDate>Wed, 02 Sep 2026 00:00:00 +0100</pubDate>
    <link>https://gulertech.co.uk/mobile/mastg-know-0001-biometric-authentication/</link>
    <guid isPermaLink="true">https://gulertech.co.uk/mobile/mastg-know-0001-biometric-authentication/</guid>
    <category>android</category><category>biometrics</category><category>keystore</category><category>frida</category><category>masvs-auth</category>
  </item>
  
</channel>
</rss>
