Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

cryptax

@cryptax@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

Anti-Virus Researcher (Mobile, IoT) and Lead organizer of Ph0wn CTF.
This account does not represent my employer.

909 Followers
365 Following
34 Posts
Joined October 30, 2022
Open post
cryptax @cryptax@mastodon.social
· 4mo ago

Mounted my first Luksbox, protected by a Yubikey. Works very well.

Compared to Gocryptfs: you have support for FIDO2 keys.

Compared to veracrypt and truecrypt, the big advantage is you don't have to reserve x Gb for the encrypted partition.

#luks #encrypted #partition #volume #fido #crypt #file #linux

cc: @Penthertz@infosec.exchange

mastodon.social
24
2
12
0
Open post
cryptax @cryptax@mastodon.social
· 3mo ago
The badge for THCon2026, a DVID board, had 2 firmware : the conference firmware, which was reversed by @virtualabs@mamot.fr here: https://virtualabs.fr/geekeries/thcon26-badge-writeup and a challenge firmeware here: https://github.com/dvid-security/dvidv2-opensource/tree/main/workshop/thcon2026 That I solved here: https://cryptax.github.io/2026-06-thconbadge/ (writeup/spoiler). #badge #hacking #challenge #ESP32 #thcon #writeup #spoiler
virtualabs.fr

virtualabs.fr - Write-up du challenge du badge THCon 2026

Le Hangar de Virtualabs

8
1
5
0
Open post
cryptax @cryptax@mastodon.social
· 2mo ago
Replying to
By the way, I personally enjoy this "community service" part of my job : combating malware, and helping - a bit - the population gives sense to my work. I know that some researchers and hackers will argue that "it's good to know how to create malware for science", to learn to fight it more efficiently. I believe there are more secure way to do so. Do you spread the plague to test how efficiently your vaccine works? No. Same for malware. #malware #creation #ethics 3/4
3
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 4mo ago

FYI, I updated my blog post on CTFs and AI, because I wasn't entirely satisfied with what was in it + people press me for my opinion... so I added it.

https://cryptax.github.io/posts/ctf-ai/

Want it brielfly?

My cool site

CTFs and AI

CTFs and Artificial Intelligence. Post Ph0wn 2026 Thoughts. Update May 26, 2026: Link to feedback from NorthSec CTF Update May 19, 2026: Re-phrased first paragraph. In particular, replaced the title “Myth #1 CTF players hate AI [..]” with “CTF players hate AI [..]: True or False?” because I found my title was too biaised. It did not express fairly enough the reality. Added a paragraph on my (current) opinion. Added references to foreman, Kabir and Sthack CTF My opinion, in short The “problem” of

4
0
2
0
Open post
cryptax @cryptax@mastodon.social
· 2mo ago
Je cherche un réparateur de confiance pour mon hautbois, proche des Alpes Maritimes (06). Il a ~50 ans, et besoin de révision. Je sais expliquer les problèmes (mais pas les résoudre lol). J'ai cherché jusqu'ici sans succès. Je cherche qqun d'honnête, qui sait comment réparer un hautbois (pas qqun qui révise un hautbois tous les 5 ans). Re-post bienvenu. #alpes-maritimes #hautbois #luthier #vent #bois #musique #reparation #oboe #repair
1
0
27
0
Open post
cryptax @cryptax@mastodon.social
· 2mo ago
Currently decompiling LabubaRAT with Ghidra. It's taking ages to perform the initial analyzing, probably because of Rust. https://blackpointcyber.com/blog/labubarat-a-rust-based-remote-access-tool-masquerading-as-nvidia-software/ #malware #rust #RAT #labubaRAT
LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software
Blackpoint Cyber

LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software

Blackpoint’s Adversary Pursuit Group discovered a previously undocumented malware sample that we are tracking as LabubaRAT, a Rust based remote access tool masquerading as NVIDIA software.

1
0
1
0
Open post
cryptax @cryptax@mastodon.social
· 2mo ago
Sunday morning, and currently fixing an unhappy update on Linux Mint 22.3 yesterday. To my understanding, Mint is not the cause, but it's the Nvidia drivers which were not rebuilt and signed (Secure Boot) correctly. Fortunately, ChatGPT is helping me out here or this would have been a horrible mess... :( #linux #nvidia #dkms #secureboot
1
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 4mo ago

https://geohot.github.io/blog/jekyll/update/2026/05/24/the-eternal-sloptember.html

Interesting point of view. I don't agree with all of it, but lots.

"the adoption of AI agents into software development will be one of the most costly mistakes in the field’s history." --> Disagree (anyway, it's done).

"Agents cannot program" --> yes and no. Agents are worse than a good software engineer, but far better than a bad one.

geohot.github.io
2
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 7mo ago

Je viens de passer ~1 jour à avoir un environnement de développement stable avec Android Studio. Entre toutes les horreurs de gradle, de dependancies bizarre, d'émulateur qui était trop lent etc.

Makefile, c'était pas parfait, mais au moins c'était bien scriptable et compact. Là, je continue à pester contre ces nouveautés qui n'améliorent au final rien.

#jaimeraler #frustration #android

mastodon.social
3
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 8mo ago
Replying to
@davidrevoy@framapiaf.org @thematic@mastodon.green this is gold mine!!!
3
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 4mo ago

Ca me "tue" le nombre grandissant de services avec une facturation "floue":

- souscription mensuelle à de l'IA : je ne vois aucun contrat, garantie de service. Par ex, pour Warp, ils ont essayé de me prélever mensuellement alors que je n'ai pas souvenir d'avoir signé pour une souscription mensuelle, juste que je voulais essayer un mois. Nuance.

- supermarchés où on te donne de moins en moins ta facture.

- etc

Vous avez trop d'argent, vous voulez plus regarder ce qu'on vous facture ?

1
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 5mo ago
Replying to

BTW, don't run the exploit without understanding, in particular, you should backup your su. Something with cp -a su su.orig.

You'll see the exploit is devastating, because it gets rid of the password protection, but you don't see anything on the disk : the binary looks the same, original size, original date.

1
0
1
0
Open post
cryptax @cryptax@mastodon.social
· 6mo ago
Replying to
@davidrevoy excellent !
1
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 6mo ago

Y a qqun qui me dit demande si j'ai du temps pour discuter avec lui sur un sujet.

Ma réponse est "non désolée, pas avant la fin de la semaine prochaine".

Et il insiste "je dois rendre ma réponse vendredi".

Certes. Mais qu'est-ce qui n'est pas suffisamment précis dans le "non" et "pas avant la fin de la semaine prochaine" ? ;-)

NB. Je fais rarement ce genre de réponses.

1
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 7mo ago

Je ne savais pas que Cline, dans VS, était capable d'ouvrir un navigateur et d'aller cliquer là où il faut se loguer et faire les taches demandées. Wow.

#IA

mastodon.social

Mastodon

1
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 7mo ago

@davbucci@mastodon.sdf.org --> @ghspacefr@infosec.exchange peut être ?

1
4
1
0
Open post
cryptax @cryptax@mastodon.social
· 7mo ago

https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/

#Android #malware #AI

welivesecurity.com
1
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 8mo ago
Replying to
@davidrevoy@framapiaf.org amazing! But I'm surprised you put in the text first, image after! I do it the other way, but I'm a real amateur, so maybe actually what I do is stupid!
1
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 10mo ago
Replying to
@gynvael@infosec.exchange @PagedOut@infosec.exchange oh you didn't manage to grab one at BlackAlps?
1
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 11mo ago
Replying to
@claushoumann lol! But now, I do understand organizers: when this happens in your venue, you feel a bit responsible, and it can jeopardize the fact that the event wants to host you next year. So, yes, have fun, but put it back.
1
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 37mo ago
Replying to
@Azeria@mastodon.social wow!!!!!!!!
1
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 2mo ago
Replying to
Submitting such a paper is just IRRESPONSIBLE. We, malware analysts and other anti-malware jobs, spend hours trying to secure lives / money of your family, friends, colleagues, companies. Trying to help malware authors feels like spitting on our jobs. Or shooting in your leg. To correlate it to current events in France, it's just like lighting a fire in front of fire-fighters. Will you tell people who lost their house, their life that it's fun to "try"? #malware #paper #research #ethics 2/4
0
2
0
0
Open post
cryptax @cryptax@mastodon.social
· 2mo ago
Replying to
If you really insist on "creating malware for science", please pay attention to contain it (air-gapped, strict container), use a void payload (no impact) and present your research in closed conferences with no picture and no recording. But again, please don't. Use your intelligence to fight malware. It's very interesting too, and it requires lots of brains and skills! Want to prove your value? Far more efficient. Don't give in the dark side ;P 4/4
0
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 6mo ago

RE: @laluka@infosec.exchange

Ph0wn CTF Social Challenge. So many awesome submissions, I enjoyed seeing them all, and this one is particularly excellent :)

#ph0wn

infosec.exchange
0
0
1
0
Open post
cryptax @cryptax@mastodon.social
· 7mo ago

Il n'y avait pas de lumière dans ces toilettes. Je suppose que là, c'était parce que c'est inutile aux malvoyants ?

#humour

mastodon.social

Mastodon

0
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 7mo ago

Message privé: bisous maman !

#24ans #heaven

mastodon.social
0
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 26mo ago
Replying to
@radareorg what a pity that I can't be there!
0
2
0
0
Open post
cryptax @cryptax@mastodon.social
· 4mo ago

My CTF team at Auvergn'hack was fabulous. We had awesome discussions about Java, Python, security in general, but also Saint Nectaire and French pastry.

Thanks to my team mates, and again thanks so much for the Saint Nectaire.

Write-up for the Crypto challenge: https://cryptax.github.io/auvergn2026-crypto/

cryptax.github.io
0
0
1
0
Open post
cryptax @cryptax@mastodon.social
· 4mo ago

Last Friday, I was at Auvergn'hack, a small single-tracked conference in the middle of France.

A very friendly atmosphere, beautiful weather, great venue, and several very interesting talks.

https://cryptax.github.io/posts/auvergnhack-2026/

My cool site

Auvergn

Back from Auvergn’hack 2026 Auvergn’hack is a recent, local security conference in Clermont Ferrand (France). It is rather small: a single day and a single track, but it was a great discovery with an excellent ratio of interesting talks. Yes, when you’re a “senior” with “20+ years of experience” (a kinder way of saying you’re old), you’ve already seen quite a lot. You don’t say it too often not to sound old and grumpy, but you are often disappointed with talks because they tell a story so simila

0
0
0
0
Open post
cryptax @cryptax@mastodon.social
· 4mo ago

Learning about Landlock with a sandboxed opencode in nono. Nono is a sandbox, uses Landlock, and for example we can restrict directories opencode can go into.

#auvergnhack #landlock #sekoia

mastodon.social
0
1
0
0
Open post
cryptax @cryptax@mastodon.social
· 5mo ago
Replying to
@pancake@infosec.exchange I'm not sure NetBSD or FreeBSD are really more secure, just less targeted, and yes probably less features. If you do shift, let me know how it goes!
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:48:10 UTC