Gynvael Coldwind
@gynvael.bsky.social
2.7K followers 57 following 70 posts
Security researcher/programmer ⁂ Managing director @ HexArcana ⁂ @DragonSectorCTF founder ⁂ he/him
Posts Media Videos Starter Packs
Pinned
gynvael.bsky.social
Yet another ZIP trick...
hackarcana.com/article/yet-...

+ a hands on exercise if you want to try this yourself:
hackarcana.com/article/yet-...
gynvael.bsky.social
We've received 50 required articles for issue #7 of
@pagedout.bsky.social - this means we're publishing the issue in the few next weeks.
1. Want to get an article in #7? You should write it now and send it in in the next few days.
2. We're still looking for more issue sponsors!
gynvael.bsky.social
OK, ChatGPT 5 admittedly surprised me in a positive way. I threw a PNG with a (small) Python AST graph at it and told it to reverse it to Python code, and it successfully did that. I have expected it to fail hard, but here we are 🤷.
gynvael.bsky.social
Friendly reminder that order of operations makes a difference... more so than you think ;)
Python: 20000000000000000000.0 + 1337.0 - 20000000000000000000.0 is 0, but same numbers, with addition of 1337 moved after subtraction results in 1337.
gynvael.bsky.social
Lulu (print on demand) is increasing prices by 5% from Aug 1st, so if you were thinking of getting @pagedout.bsky.social #6 there, do it now: www.lulu.com/search?page=...
Shop the Independent Bookstore | Lulu
www.lulu.com
gynvael.bsky.social
[Please share with people outside of cybersec]
Do you have a horror story when you had to deal with cybersecurity companies / people? This is your chance to vent! → forms.gle/9aX24HrfnEQm...
I'm running an anonymous survey to listen to stories and look into the disconnect we sometimes have.
Frustration with cybersecurity people and companies
This anonymous survey if for people who are NOT working in cybersecurity and who had to contract people / buy services / buy products from companies in cybersecurity / use cybersecurity products / etc...
forms.gle
gynvael.bsky.social
Yet another ZIP trick...
hackarcana.com/article/yet-...

+ a hands on exercise if you want to try this yourself:
hackarcana.com/article/yet-...
gynvael.bsky.social
A (not so) short analysis of anonymization schema used in the "Discord Unveiled" paper: hackarcana.com/article/anon...
gynvael.bsky.social
Thanks! That's MacOS Terminal.app, right?
gynvael.bsky.social
Poll! What ANSI color types does your terminal support?

"\x1b[1;31m3bpp+attr\x1b[m \x1b[91m4bpp\x1b[m \x1b[38:5:196m8bpp\x1b[m \x1b[38;2;255;0;0m24bpp\x1b[m"

Reply with screenshot of the output of this string + add OS/terminal versions

E.g. Ubuntu 24.04.2LTS, Konsole 23.08.5
gynvael.bsky.social
Btw, is there sth like (www.web3isgoinggreat.com) but about AI fails?
gynvael.bsky.social
[PL] W przyszłym tygodniu zaczynam nową serię szkoleniową - 10 projektów w Pythonie krok po kroku (python.sekurak.pl). Coś dla osób bardziej początkujących, w szczególności dla osób, które trafiły na ścianę po hello world / kalkulatorze, albo mają problem jak ↓
gynvael.bsky.social
Doing a free webinar today at 8PM CEST (i.e. livestream with slides) about "files", as entities on the filesystem, seen through the eyes of a security researcher.
hexarcana.ch/lp/files/ ← sign up here if interested
gynvael.bsky.social
Paged Out! #6 is out!
pagedout.institute
Totally free, 80 pages, best issue so far!
'nuff said, enjoy!

(please repost to help spread out the news!)
gynvael.bsky.social
Note: This webinar is about files as seen from the perspective of the OS/filesystem/sysadmin, and not about what's INSIDE the files.
hackarcana.com/bin?utm=gyn-b ← This workshop covers what's INSIDE the files :)
gynvael.bsky.social
Next Monday I'm doing a 2h webinar on files as seen through the eyes of a cybersecurity researcher. This will cover useful stuff for programmers, more junior pentesters, and other tech enthusiasts who enjoy knowing how stuff works on a computer :)
hexarcana.ch/lp/files/?ut...
Files through the eyes of a hacker
hexarcana.ch
gynvael.bsky.social
I'm getting some specific questions about my upcoming training – I'll update the training page later today. This said, I've also recorded a short show-case / case-study of what type of skill one will acquire on my training:
www.youtube.com/watch?v=ib4Y...
Reversing unknown file download protocol
YouTube video by GynvaelEN
www.youtube.com
gynvael.bsky.social
Thank you Paweł for the very kind words – I really appreciate it! :)
gynvael.bsky.social
tmp.0ut Volume 4 just came out!!! LET'S GO!
And guess who's article is there ;)

08 .... FixedASLR: .o ELF loader in a CTF task

tmpout.sh/4/
gynvael.bsky.social
I'm running an "Intro to programming and Python" workshop (in Polish) in the evening with Sekurak / securitum and we have over 10 000 people registered. This is definitely and a new record for me!!!

If you understand Polish, you can still sign up at sklep.securitum.pl/wstep-do-pro...
gynvael.bsky.social
A lot of you were telling me I should do my courses in English, so here we go:

Mastering Binary Files and Protocols: The Complete Journey
hackarcana.com/bin?utm=gyn-b

This is an A-to-Z course teaching a fundamental skill in practical IT, useful in cybersec/coding/etc
Start Apr 8th
gynvael.bsky.social
It's been a moment since I've posted sth on my YT channel, so here we go:
www.youtube.com/watch?v=jBsV...
I'm going here through my "pressing CTRL+D is like ENTER pressing" article – enjoy!
Pressing CTRL+D Is NOT what you think!
YouTube video by GynvaelEN
www.youtube.com
gynvael.bsky.social
I've written another article, this time on the fundamental reason why we have all these XSSes/SQLIs/etc. At least that's the way I explain it ;)
hackarcana.com/article/why-...

There's also a CTF challenge for this article (misc60):
hackarcana.com/article/why-...

Enjoy!
hackarcana.com
gynvael.bsky.social
If you like CTF challenges, we've been steadily pushing some of my favorite tasks to my new edu site:
hackarcana.com/exercises
From top to bottom: Linux RE, 2x JS RE, USB PCAP, ZIP/crypto, DOS/VGA RE, 2x BMP image stegano, 5x BMP file format stegano, Python 2.7 RE, and ROP RE
HFGL