Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Gynvael Coldwind 🐈

@gynvael@infosec.exchange
  • Open on infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

0 Followers
0 Following
21 Posts
Joined October 31, 2022
YouTube[EN]:
https://www.youtube.com/@GynvaelEN
YouTube[PL]:
https://www.youtube.com/@GynvaelColdwind
Blog:
https://gynvael.coldwind.pl
Twitter:
https://twitter.com/gynvael

Posts

Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Aug 06, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange
An exercise in translating Abstract Syntax Tree back to Python source code: https://www.youtube.com/watch?v=iztSu3rKmH8
Translating AST back to Python
YouTube

Translating AST back to Python

GynvaelEN

0
0
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Jul 07, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange
Story time! A few weeks ago I was at the AREA41 conference and there were A LOT of CTFs there - it was almost like every village and every sponsor's booth had one. I had some time before my talk so I decided to play one of these and I ended up selecting the InfoGuard one (shoutout to super friendly organizers). One of the tasks had MQTT in the name, so I expected to have to play with the standard IoT messaging protocol, but that's not what ended up happening at all - I ended up accidentally cheesing the challenge with an unintended solution instead! From the player's perspective the task started with a website - or, to be more accurate - a web-based login panel asking for a username and password. Trying a couple of typical credentials (admin/admin and the like) didn't work, so I decided to look at the actual HTTP request sent and play a bit with it using command-line curl. The actual POST request was a pretty typical JSON and contained only two string fields: "username" and "password". I started by sending just the "username", though instead of sending it with a string value, I sent it with a number instead: { "username": 123 } ...and I received an "OK" with a session id. This isn't really what I expected. What I did expect was some form of error saying that "hey, the field has the wrong type" or "where's the password?" - these error messages are pretty useful in establishing what libraries or frameworks are used. Instead, it seems I was logged in? But was the session id I got really a "logged in" session? Why, yes, it was. And after copy-pasting the cookie to the browser, I could see the full admin panel including THE FLAG! Pretty obviously this was an unintended solution, but hey - a flag is a flag 🤷 I've chatted on the next day with the organizers about the task and apparently the code worked like this (pseudo-code from my memory): USERS = { "admin": "some long and complex plaintext password" } @app.route('/login', methods=['POST']) def login(): data = request.get_json() if USERS.get(data["username"]) != data.get("password"): return { "error": "wrong password" } ... # Continue as a logged in user. What's going on here is pretty simple and boils down to the difference between the dictionary[key] and dictionary.get(key) calls. In the first case a non-existent key leads to a KeyError exception being raised, while in case of the .get() call the second argument - None by default - gets returned. As such, USERS.get(data["username"]) for a provided but ultimately non-existent username evaluates to None, and the password field is missing in the request altogether, so we get None there as well. And hey, None is equal to None in Python, so that's a correct password, right? 😅 By the way, if you like Python stories that include surprising quirks, starting end of July I'm running a Python Cyber Summer Camp that will feature some more hardcore examples as well - check it out at hackArcana (my educational / CTF website). Eventually I finished the CTF first (tied in first place with two other participants per this CTF's "it's a conference so we allow ties" rule) and won a USB Rubber Ducky! And I've heard that at least one other CTF player cheesed this challenge the same way. Anyway, it was a fun CTF and overall I greatly enjoyed this edition of the AREA41 conference - looking forward to the next event in the series!
0
0
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Apr 27, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

I've signed up two amazing K8s experts to my edu platform, and they're making a pwning K8s challenge/mini-CTF on Wed 29th Apr evening (it will run for two weeks). If you want to check it out → https://hackarcana.com/challenge/2026-Q2-k8s-challenge/gynvaels-invitation

3
0
3
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Apr 07, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

RE: @PagedOut@infosec.exchange

This article (recommended if you're learning RE!) reminded me of a GOATed FPGA bistream reversing task from Google CTF (GPURTL by Robin), where the key to solving it for me was observing the pattern of changing bits in FPGA's registers. The pattern itself was enough to pinpont the exact algorithm.
@liveoverflow@bird.makeup made a video about this task: https://www.youtube.com/watch?v=3ac9HAsfV8c

3
0
1
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Apr 06, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

https://www.youtube.com/watch?v=gJM9pZydzVg ← my new old talk was released as a standalone; it's a fun story of how you go from being able to write '2' (0x32, 1 byte) anywhere on the FS to full RCE with admin/root privs

18
0
13
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Mar 04, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

My second article in Paged Out! #8 was about the architecture of the terminal emulator on Linux - it's a really obvious thing until you start digging into details, as usual.

Web viewer: https://pagedout.institute/webview.php?issue=8&page=43&article=Linux+terminal+emulator+architecture
PDF download: https://pagedout.institute/?page=issues.php

22
0
11
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Feb 25, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

My article in newest Paged Out! about everyone's favorite Python party trick:
https://pagedout.institute/webview.php?issue=8&page=63&article=Trying+to+demo+Python%27s+is

#python #goingtoapythonprogrammersparty #pythonprogramminglanguagethemedparty #whatispythonsis

5
0
1
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Feb 16, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

Just got this link on my discord - https://www.kickstarter.com/projects/bitman/bootblock-rebels - passing it along because this book looks fun!

1
0
2
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Jan 18, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange
Replying to @TheMNWolf@furry.engineer
@TheMNWolf Hmm that sounded like Lawful Evil, but I guess it's Neutral Good? ;)
1
1
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Jan 15, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange
Replying to @TheMNWolf@furry.engineer
@TheMNWolf Good Neutral, got it!
1
1
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Jan 15, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

@mkj@social.mkj.earth Yeah, I think that might have been a better choice for chaotic evil ;)

social.mkj.earth

mkj (@mkj@social.mkj.earth) - Mastodon

0
0
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Jan 13, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange
Replying to @indigoat@infosec.exchange
@indigoat Oh this is so spot on!
1
0
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Jan 11, 2026
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

A useful chart on what type to use for flags in C/C++ depending on your D&D alignment:

38
2
19
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Dec 30, 2025
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

Glitches in games, especially used for speedrunning, are one of the most fun aspects of hacking to watch!

As an example, check out this video "How Speedrunners BEAT Hollow Knight Silksong In 10 Minutes!" by Abyssoft

https://www.youtube.com/watch?v=M6Jnj-y0G9w

11
0
4
1
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Dec 27, 2025
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

Ah Saturday morning! What a great time to...

...write a 1-page article for Paged Out! zine!

Deadline is 4th Jan - just a week away.

CFP: https://pagedout.institute/?page=cfp.php

8
0
6
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Dec 09, 2025
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

𝙿𝙰𝙶𝙴𝙳 𝙾𝚄𝚃! #𝟾 𝙳𝙴𝙰𝙳𝙻𝙸𝙽𝙴: 𝟺 𝙹𝚊𝚗𝚞𝚊𝚛𝚢 𝟸𝟶𝟸𝟼 𝙴𝚘𝙳 𝙴𝚘𝙰

Save the date if you're planning to write an article or showcase your digital art in the next issue of our magazine.

https://pagedout.institute/

P.S. We're looking for sponsors for issue #8 as well.

Paged Out!
Paged Out!

Paged Out!

Deeply technical zine. And it

5
0
4
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Dec 05, 2025
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

RE: @PagedOut@infosec.exchange

One of my favorite projects just hit a HUGE milestone of 1 million downloads!

Kudos to the team and everyone who supported us!

11
0
4
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Nov 30, 2025
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

You can write '2' (0x32) anywhere in the filesystem of a Linux-based network switch. How do you get root?

That's basically what my talk at GreHack conference was about - enjoy!
https://youtu.be/F4CudbWHZ7Y?t=504 https://youtu.be/X-ZJH4d2tuE?t=1162

15
0
6
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Nov 25, 2025
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange
Replying to @cryptax@mastodon.social
@cryptax@mastodon.social @PagedOut@infosec.exchange Got some cold and couldn't attend in the end ;/ But I've heard I might still get one ;)
1
0
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Nov 25, 2025
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange
Replying to @cryptax@mastodon.social
@cryptax@mastodon.social @PagedOut@infosec.exchange Oh, awesome! I'm looking forward to getting my hands on that one – the thermal binding is something Paged Out! hasn't seen before, so I'm curious :)
1
1
0
0
Open post
gynvael
Gynvael Coldwind 🐈 @gynvael@infosec.exchange · Dec 28, 2024
Gynvael Coldwind 🐈
@gynvael@infosec.exchange

security researcher/programmer ⁂ previously security team @ Google ⁂ Dragon Sector CTF founder/player ⁂ technical livestreamer ⁂ slide maker ⁂ he/him

infosec.exchange

Want to support security researchers from Dragon Sector in covering legal costs piling up after they went public with logic bombs in train firmware?
IBAN for donations is available here:
https://www.ccc.de/en/updates/2024/das-ist-vollig-entgleist

Talks for context
https://media.ccc.de/v/37c3-12142-breaking_drm_in_polish_trains
https://streaming.media.ccc.de/38c3/relive/336

#38c3 #dragonsector

32
0
50
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:13:00 UTC