Skip to content
View tayfuryldz's full-sized avatar

Sponsoring

@ahmtydn

Block or report tayfuryldz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tayfuryldz/README.md

Tayfur Yıldız

Security-focused developer working on open-source software, developer tooling, and practical security research.

I like problems that need a reproducible answer: trace the behavior, isolate the failure, make the smallest useful change, and leave a regression test behind.

LinkedIn · HackerOne · Bugcrowd · Intigriti · YesWeHack

Open source

Most of my recent work has been upstream: debugging existing systems, writing focused fixes, adding regression coverage, and working through maintainer review. I have 140+ merged pull requests in repositories I don't own in the last 12 months.

A few representative contributions:

Project Contribution
TheAlgorithms/Python Constrained TimSort inputs to comparable values, tightening the implementation and its typing contract.
RustDesk Fixed Windows foreground activation for an existing session.
OpenLayers Fixed MouseWheelZoom target cleanup, including lifecycle and interaction-state handling.
sktime Made SubLOF compatible with pandas 3.
OpenTelemetry PHP Fixed SDK global attribute-limit fallbacks with regression coverage across the affected limits.
Nextcloud Mail Fixed detection of application/octet-stream ICS attachments.
GitHub Advisory Database Contributed advisory metadata fixes, including PickleScan and Gitea fix references.
planning-with-files Contributed a series of reliability fixes across project attestation, PowerShell pointer replacement, OpenCode replay handling, and active-plan state; for example #297 and #287.

HeaderProof

HeaderProof is the security project I maintain. It is built around evidence rather than noisy heuristics: probe HTTP behavior, preserve the response that supports a finding, and keep conclusions reproducible.

The current work covers CORS and CSRF behavior, response/header injection, cache-related issues, content reflection and other HTTP security checks, with profiles for controlling scan behavior and output intended to be useful during authorized testing.

Related repositories: headerproof-action · headerproof-templates

Working set

Python   Rust   TypeScript   JavaScript   PHP   Linux   Git   GitHub   Docker

Security research: HTTP behavior, web application security, bug bounty, attack-surface analysis, validation, and low-noise automation. Daily environment includes Linux/WSL, Burp Suite, Nuclei, Nmap, and ProjectDiscovery tooling.


Security work is performed in authorized environments and within the applicable program or project scope.

Pinned Loading

  1. headerproof headerproof Public

    Evidence-gated active scanner for CORS, CSRF, header injection, cache poisoning, and content spoofing

    Python 2 3

  2. marrow marrow Public

    Fail-closed, evidence-based HTTP request minimizer for authorized security research

    Python 1