Gynvael Coldwind
Security researcher/programmer ⁂ Managing director @ HexArcana ⁂ @DragonSectorCTF founder ⁂ he/him
- Reposted by Gynvael ColdwindWe are excited to announce the CFP for the next tmp.0ut Volume 5! tmpout.sh/blog/vol5-cf...
- A useful chart on what type to use for flags in C/C++ depending on your D&D alignment:
- Glitches in games, especially used for speedrunning, are one of the most fun aspects of hacking to watch! As an example, check out this video "How Speedrunners BEAT Hollow Knight Silksong In 10 Minutes!" by Abyssoft www.youtube.com/watch?v=M6Jn...
- Ah Saturday morning! What a great time to... ...write a 1-page article for Paged Out! zine! Deadline is 4th Jan - just a week away. CFP: pagedout.institute?page=cfp.php
- 𝙿𝙰𝙶𝙴𝙳 𝙾𝚄𝚃! #𝟾 𝙳𝙴𝙰𝙳𝙻𝙸𝙽𝙴: 𝟺 𝙹𝚊𝚗𝚞𝚊𝚛𝚢 𝟸𝟶𝟸𝟼 𝙴𝚘𝙳 𝙴𝚘𝙰 Save the date if you're planning to write an article or showcase your digital art in the next issue of our magazine. pagedout.institute P.S. We're looking for sponsors for issue #8 as well.
- One of my favorite projects just hit a HUGE milestone of 1 million downloads! Kudos to the team and everyone who supported us!
- You can write '2' (0x32) anywhere in the filesystem of a Linux-based network switch. How do you get root? That's basically what my talk at GreHack conference was about - enjoy! youtu.be/F4CudbWHZ7Y?... youtu.be/X-ZJH4d2tuE?...
- With the newest Black Alps 2025 and GreHack 2025 additions, my printed Paged Out! collection is slowly growing!
- pagedout.institute ← Call for articles & art for issue #8 of this technical IT zine is open! As usual, we accept 1-page articles about everything interesting in IT and related fields (be it programming, cybersec, AI, demoscene, retro, electronics, etc).
- Here's some blursed Python code for you: a, b, c = {"alice", "has", "a cat"} print(a, b, c)
- Here's a Saturday Python 3 Puzzle for you:
- If you've liked my "Linux Terminal: CTRL+D is like pressing ENTER" article (hackarcana.com/article/ctrl...), be sure to checkout @mina86.com's "Is Ctrl+D really like Enter?" (mina86.com/2025/is-ctrl...) :)
- Heeey, ncurses/terminfo has a small virtual machine! And if there's a VM, there are CTF challenges :) hackarcana.com/public-exerc... hackarcana.com/public-exerc... (third one coming next week, will be a bit harder)
- We've received 50 required articles for issue #7 of @pagedout.bsky.social - this means we're publishing the issue in the few next weeks. 1. Want to get an article in #7? You should write it now and send it in in the next few days. 2. We're still looking for more issue sponsors!
- OK, ChatGPT 5 admittedly surprised me in a positive way. I threw a PNG with a (small) Python AST graph at it and told it to reverse it to Python code, and it successfully did that. I have expected it to fail hard, but here we are 🤷.
- Friendly reminder that order of operations makes a difference... more so than you think ;)
- Lulu (print on demand) is increasing prices by 5% from Aug 1st, so if you were thinking of getting @pagedout.bsky.social #6 there, do it now: www.lulu.com/search?page=...
- [Please share with people outside of cybersec] Do you have a horror story when you had to deal with cybersecurity companies / people? This is your chance to vent! → forms.gle/9aX24HrfnEQm... I'm running an anonymous survey to listen to stories and look into the disconnect we sometimes have.
- Yet another ZIP trick... hackarcana.com/article/yet-... + a hands on exercise if you want to try this yourself: hackarcana.com/article/yet-...
- A (not so) short analysis of anonymization schema used in the "Discord Unveiled" paper: hackarcana.com/article/anon...
- Poll! What ANSI color types does your terminal support? "\x1b[1;31m3bpp+attr\x1b[m \x1b[91m4bpp\x1b[m \x1b[38:5:196m8bpp\x1b[m \x1b[38;2;255;0;0m24bpp\x1b[m" Reply with screenshot of the output of this string + add OS/terminal versions E.g. Ubuntu 24.04.2LTS, Konsole 23.08.5
- Btw, is there sth like (www.web3isgoinggreat.com) but about AI fails?
- [PL] W przyszłym tygodniu zaczynam nową serię szkoleniową - 10 projektów w Pythonie krok po kroku (python.sekurak.pl). Coś dla osób bardziej początkujących, w szczególności dla osób, które trafiły na ścianę po hello world / kalkulatorze, albo mają problem jak ↓
- Doing a short livestream in ~30 minutes with inspecting a pcap with USB traffic from a gamepad – www.youtube.com/live/xVrxfEk...
- Doing a free webinar today at 8PM CEST (i.e. livestream with slides) about "files", as entities on the filesystem, seen through the eyes of a security researcher. hexarcana.ch/lp/files/ ← sign up here if interested
- Paged Out! #6 is out! pagedout.institute Totally free, 80 pages, best issue so far! 'nuff said, enjoy! (please repost to help spread out the news!)
- Next Monday I'm doing a 2h webinar on files as seen through the eyes of a cybersecurity researcher. This will cover useful stuff for programmers, more junior pentesters, and other tech enthusiasts who enjoy knowing how stuff works on a computer :) hexarcana.ch/lp/files/?ut...
- I'm getting some specific questions about my upcoming training – I'll update the training page later today. This said, I've also recorded a short show-case / case-study of what type of skill one will acquire on my training: www.youtube.com/watch?v=ib4Y...
- tmp.0ut Volume 4 just came out!!! LET'S GO! And guess who's article is there ;) 08 .... FixedASLR: .o ELF loader in a CTF task tmpout.sh/4/
- I'm running an "Intro to programming and Python" workshop (in Polish) in the evening with Sekurak / securitum and we have over 10 000 people registered. This is definitely and a new record for me!!! If you understand Polish, you can still sign up at sklep.securitum.pl/wstep-do-pro...
- A lot of you were telling me I should do my courses in English, so here we go: Mastering Binary Files and Protocols: The Complete Journey hackarcana.com/bin?utm=gyn-b This is an A-to-Z course teaching a fundamental skill in practical IT, useful in cybersec/coding/etc Start Apr 8th
- It's been a moment since I've posted sth on my YT channel, so here we go: www.youtube.com/watch?v=jBsV... I'm going here through my "pressing CTRL+D is like ENTER pressing" article – enjoy!
- I've written another article, this time on the fundamental reason why we have all these XSSes/SQLIs/etc. At least that's the way I explain it ;) hackarcana.com/article/why-... There's also a CTF challenge for this article (misc60): hackarcana.com/article/why-... Enjoy!
- If you like CTF challenges, we've been steadily pushing some of my favorite tasks to my new edu site: hackarcana.com/exercises From top to bottom: Linux RE, 2x JS RE, USB PCAP, ZIP/crypto, DOS/VGA RE, 2x BMP image stegano, 5x BMP file format stegano, Python 2.7 RE, and ROP RE HFGL
- Did you know that pressing CTRL+D in linux terminal is like pressing ENTER? (to some extent, of course) Well, I didn't, so after randomly investigating what CTRL+D actually does, I've decided it's a fun topic to write about: hackarcana.com/article/ctrl...
- Reposted by Gynvael Coldwind[Not loaded yet]
- Worth reading!
- This one is a fun one hackarcana.com/public-exerc... USB PCAP of a gamepad selecting the flag :) (Dejan, who was re-flagging this task, had to listen to my "back in my days the second thing you've learnt in programming was how to read the state of a joystick!" story. I am not sorry.)