Skip to content
View iamcanturk's full-sized avatar
🎯
Focusing
🎯
Focusing

Highlights

  • Pro

Block or report iamcanturk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
iamcanturk/README.md

Can Türk

Kod × Tasarım × Güvenlik  ·  Code × Design × Security

Application-security-focused full-stack developer.
I write software, then try to break it — and disclose what I find (two turned into CVEs).
The rest of the time I design brands and the interfaces that sit on top of them.

📍 Bursa, Türkiye  ·  hybrid / remote-friendly


Three disciplines, one hand

I can take a product end to end — from the database schema to the logo, from a penetration test to the ad creative.

⌨️  Software

Six years building corporate systems with PHP & Laravel: e-commerce, CRM, payment integrations, IoT dashboards.

PHP   Laravel   Go   TypeScript   MySQL

🔒  Security

I test what I build with an attacker's mindset and responsibly disclose the bugs I find. Two became CVEs.

OWASP Top 10   SANS 25   Pentest   Threat Modeling

🎨  Design

The full visual identity for a new business — logo, corporate identity, social templates — and the product UI from the same hand.

Logo   Brand Identity   UI/UX


📦 Featured open source

Most of my client & enterprise work is under NDA — happy to walk you through it. These are the ones I can share openly.

  • DoctorDocka doctor for your Docker: local-first, AI-free Docker security & cleanup diagnostics, CLI + macOS app. doctordock.iamcanturk.dev  Go · Security · CLI
  • MergenFlow — a "freelancer operating system."  TypeScript · SaaS
  • Erklig — a backdoor analysis engine.  Go · Security

🛡️ Disclosed CVEs

CVEVulnerabilitySeverityTargetReferences
CVE-2026-28403 Cross-Site WebSocket Hijacking Textream NVD · GHSA
CVE-2026-28412 Uncontrolled Resource Consumption Textream NVD · GHSA

Started as a factory IT intern in 2015 · I also chase good light with a camera 📷


iamcanturk.dev — projects, writing, and how to reach me.

Pinned Loading

  1. DoctorDock DoctorDock Public

    Local-first Docker diagnostics — find security problems, misconfigurations and reclaimable resources. No AI, no network calls, no telemetry.

    Go

  2. erklig erklig Public

    ⚔️ ERKLIG - Mighty Backdoor Analysis Engine | Open-source web shell & backdoor detection tool

    Go

  3. mergenflow mergenflow Public

    MergenFlow Pro: The Ultimate Freelancer OS. An open-source SaaS platform offering comprehensive Financial Projection, Recurring Budget Management, and integrated Kanban Workflow Tracking for freela…

    TypeScript 1