Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Gynvael Coldwind 🐈

@gynvael@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

0 Followers
0 Following
21 Posts
Joined October 31, 2022
YouTube[EN]:
https://www.youtube.com/@GynvaelEN
YouTube[PL]:
https://www.youtube.com/@GynvaelColdwind
Blog:
https://gynvael.coldwind.pl
Twitter:
https://twitter.com/gynvael
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 8mo ago

A useful chart on what type to use for flags in C/C++ depending on your D&D alignment:

38
2
19
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 6mo ago

https://www.youtube.com/watch?v=gJM9pZydzVg ← my new old talk was released as a standalone; it's a fun story of how you go from being able to write '2' (0x32, 1 byte) anywhere on the FS to full RCE with admin/root privs

18
0
13
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 7mo ago

My second article in Paged Out! #8 was about the architecture of the terminal emulator on Linux - it's a really obvious thing until you start digging into details, as usual.

Web viewer: https://pagedout.institute/webview.php?issue=8&page=43&article=Linux+terminal+emulator+architecture
PDF download: https://pagedout.institute/?page=issues.php

pagedout.institute
22
0
11
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 2mo ago
An exercise in translating Abstract Syntax Tree back to Python source code: https://www.youtube.com/watch?v=iztSu3rKmH8
2
0
0
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 10mo ago

You can write '2' (0x32) anywhere in the filesystem of a Linux-based network switch. How do you get root?

That's basically what my talk at GreHack conference was about - enjoy!
https://youtu.be/F4CudbWHZ7Y?t=504 https://youtu.be/X-ZJH4d2tuE?t=1162

15
0
6
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 9mo ago

Glitches in games, especially used for speedrunning, are one of the most fun aspects of hacking to watch!

As an example, check out this video "How Speedrunners BEAT Hollow Knight Silksong In 10 Minutes!" by Abyssoft

https://www.youtube.com/watch?v=M6Jnj-y0G9w

11
0
4
1
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 10mo ago

RE: @PagedOut@infosec.exchange

One of my favorite projects just hit a HUGE milestone of 1 million downloads!

Kudos to the team and everyone who supported us!

infosec.exchange
11
0
4
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 5mo ago

I've signed up two amazing K8s experts to my edu platform, and they're making a pwning K8s challenge/mini-CTF on Wed 29th Apr evening (it will run for two weeks). If you want to check it out → https://hackarcana.com/challenge/2026-Q2-k8s-challenge/gynvaels-invitation

hackarcana.com
3
0
3
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 9mo ago

Ah Saturday morning! What a great time to...

...write a 1-page article for Paged Out! zine!

Deadline is 4th Jan - just a week away.

CFP: https://pagedout.institute/?page=cfp.php

pagedout.institute
8
0
6
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 7mo ago

My article in newest Paged Out! about everyone's favorite Python party trick:
https://pagedout.institute/webview.php?issue=8&page=63&article=Trying+to+demo+Python%27s+is

#python #goingtoapythonprogrammersparty #pythonprogramminglanguagethemedparty #whatispythonsis

pagedout.institute
5
0
1
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 21mo ago

Want to support security researchers from Dragon Sector in covering legal costs piling up after they went public with logic bombs in train firmware?
IBAN for donations is available here:
https://www.ccc.de/en/updates/2024/das-ist-vollig-entgleist

Talks for context
https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains
https://streaming.media.ccc.de/38c3/relive/336

#38c3 #dragonsector

ccc.de
32
0
50
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 6mo ago

RE: @PagedOut@infosec.exchange

This article (recommended if you're learning RE!) reminded me of a GOATed FPGA bistream reversing task from Google CTF (GPURTL by Robin), where the key to solving it for me was observing the pattern of changing bits in FPGA's registers. The pattern itself was enough to pinpont the exact algorithm.
@liveoverflow@bird.makeup made a video about this task: https://www.youtube.com/watch?v=3ac9HAsfV8c

3
0
1
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 10mo ago

𝙿𝙰𝙶𝙴𝙳 𝙾𝚄𝚃! #𝟾 𝙳𝙴𝙰𝙳𝙻𝙸𝙽𝙴: 𝟺 𝙹𝚊𝚗𝚞𝚊𝚛𝚢 𝟸𝟶𝟸𝟼 𝙴𝚘𝙳 𝙴𝚘𝙰

Save the date if you're planning to write an article or showcase your digital art in the next issue of our magazine.

https://pagedout.institute/

P.S. We're looking for sponsors for issue #8 as well.

Paged Out!
Paged Out!

Paged Out!

Deeply technical zine. And it

5
0
4
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 7mo ago

Just got this link on my discord - https://www.kickstarter.com/projects/bitman/bootblock-rebels - passing it along because this book looks fun!

kickstarter.com
1
0
2
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 8mo ago
Replying to
@TheMNWolf Hmm that sounded like Lawful Evil, but I guess it's Neutral Good? ;)
1
1
0
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 8mo ago
Replying to
@TheMNWolf Good Neutral, got it!
1
1
0
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 8mo ago
Replying to
@indigoat Oh this is so spot on!
1
0
0
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 10mo ago
Replying to
@cryptax@mastodon.social @PagedOut@infosec.exchange Got some cold and couldn't attend in the end ;/ But I've heard I might still get one ;)
1
0
0
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 10mo ago
Replying to on mastodon.social
@cryptax@mastodon.social @PagedOut@infosec.exchange Oh, awesome! I'm looking forward to getting my hands on that one – the thermal binding is something Paged Out! hasn't seen before, so I'm curious :)
1
1
0
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 8mo ago

@mkj@social.mkj.earth Yeah, I think that might have been a better choice for chaotic evil ;)

0
0
0
0
Open post
Gynvael Coldwind 🐈 @gynvael@infosec.exchange
· 3mo ago
Story time! A few weeks ago I was at the AREA41 conference and there were A LOT of CTFs there - it was almost like every village and every sponsor's booth had one. I had some time before my talk so I decided to play one of these and I ended up selecting the InfoGuard one (shoutout to super friendly organizers). One of the tasks had MQTT in the name, so I expected to have to play with the standard IoT messaging protocol, but that's not what ended up happening at all - I ended up accidentally cheesing the challenge with an unintended solution instead! From the player's perspective the task started with a website - or, to be more accurate - a web-based login panel asking for a username and password. Trying a couple of typical credentials (admin/admin and the like) didn't work, so I decided to look at the actual HTTP request sent and play a bit with it using command-line curl. The actual POST request was a pretty typical JSON and contained only two string fields: "username" and "password". I started by sending just the "username", though instead of sending it with a string value, I sent it with a number instead: { "username": 123 } ...and I received an "OK" with a session id. This isn't really what I expected. What I did expect was some form of error saying that "hey, the field has the wrong type" or "where's the password?" - these error messages are pretty useful in establishing what libraries or frameworks are used. Instead, it seems I was logged in? But was the session id I got really a "logged in" session? Why, yes, it was. And after copy-pasting the cookie to the browser, I could see the full admin panel including THE FLAG! Pretty obviously this was an unintended solution, but hey - a flag is a flag 🤷 I've chatted on the next day with the organizers about the task and apparently the code worked like this (pseudo-code from my memory): USERS = { "admin": "some long and complex plaintext password" } @app.route('/login', methods=['POST']) def login(): data = request.get_json() if USERS.get(data["username"]) != data.get("password"): return { "error": "wrong password" } ... # Continue as a logged in user. What's going on here is pretty simple and boils down to the difference between the dictionary[key] and dictionary.get(key) calls. In the first case a non-existent key leads to a KeyError exception being raised, while in case of the .get() call the second argument - None by default - gets returned. As such, USERS.get(data["username"]) for a provided but ultimately non-existent username evaluates to None, and the password field is missing in the request altogether, so we get None there as well. And hey, None is equal to None in Python, so that's a correct password, right? 😅 By the way, if you like Python stories that include surprising quirks, starting end of July I'm running a Python Cyber Summer Camp that will feature some more hardcore examples as well - check it out at hackArcana (my educational / CTF website). Eventually I finished the CTF first (tied in first place with two other participants per this CTF's "it's a conference so we allow ties" rule) and won a USB Rubber Ducky! And I've heard that at least one other CTF player cheesed this challenge the same way. Anyway, it was a fun CTF and overall I greatly enjoyed this edition of the AREA41 conference - looking forward to the next event in the series!
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:33:28 UTC