gynvael Profile Banner
Gynvael Coldwind Profile
Gynvael Coldwind

@gynvael

Followers
38K
Following
11K
Media
488
Statuses
6K

security researcher/programmer/director @ HexArcana Cybersecurity GmbH ⁂ @pagedout_zine ⁂ @DragonSectorCTF ⁂ https://t.co/ShG2c5As1K ⁂ ex-Google ⁂ he/him

Zürich, Switzerland
Joined July 2009
Don't wanna be here? Send us removal request.
@gynvael
Gynvael Coldwind
1 month
Yet another ZIP trick.
Tweet media one
1
23
103
@gynvael
Gynvael Coldwind
11 hours
Friendly reminder that order of operations makes a difference. more so than you think ;)
Tweet media one
5
5
73
@grok
Grok
15 hours
Generate videos in just a few seconds. Try Grok Imagine, free for a limited time.
230
74
1K
@gynvael
Gynvael Coldwind
14 hours
RT @richinseattle: Proud moment. The 40th anniversary @phrack release was a full success. We gave away 12,000 full color 150pg printed zine….
0
30
0
@gynvael
Gynvael Coldwind
6 days
RT @phaldrzynski: Nice trick showing that the very same zip can be seen differently by two different programs. I've examined how this quirk….
Tweet card summary image
blog.isec.pl
Recently, I stumbled upon a very interesting article – Yet another ZIP trick. It demonstrates a concept called schizophrenic file – a file which is interpreted differently by two different programs....
0
25
0
@gynvael
Gynvael Coldwind
7 days
RT @terjanq: Another challenge that I prepared for justCTF2025 was about a neat Prototype Pollution variation that bypasses commong mitigat….
0
37
0
@gynvael
Gynvael Coldwind
8 days
This actually reminds me of that 0-sized executable which would re-run the last executed program on some old 8-bit comptuer.
1
0
2
@gynvael
Gynvael Coldwind
8 days
Back in the days this "feature" was the result of pressing = performing the math operation, but NOT cleaning the operand / operation registers. Pressing = again would reuse the content of these registers. A cool feature for free!.Nowadays it seems folks do clear these regs on =.
1
0
0
@gynvael
Gynvael Coldwind
8 days
So I've noticed this when running a workshop on Python — we were implementing a GUI calculator app and I wanted to show folks that repeatedly pressing = repeats the operation in my OS' calc app. And to my surprise, it didn't. (continued. ).
1
0
0
@gynvael
Gynvael Coldwind
8 days
Topic: Calculators.Open any calculator app and press:.1 + 1 = = = =. What do you get? .(also put calculator app name / result in reply). It seems modern "simple" GUI calculator apps lost the feature/side-effect of what pressing = used to do (basically repeat last operation).
5
0
2
@gynvael
Gynvael Coldwind
9 days
RT @kinugawamasato: I don't know who this will help but I put together a page listing JavaScript APIs that can break Shadow DOM encapsulati….
Tweet card summary image
github.com
Contribute to masatokinugawa/ShadowBreakers development by creating an account on GitHub.
0
52
0
@gynvael
Gynvael Coldwind
9 days
RT @justCatTheFish: JustCTF 2025 is live! 🚀. Check the challenges at
0
5
0
@gynvael
Gynvael Coldwind
10 days
RT @lukOlejnik: Malicious Firefox extensions are being used to steal crypto wallets (eed phrases). I analyzed the current big (continuous?)….
0
7
0
@gynvael
Gynvael Coldwind
12 days
RT @paradoxengine: CVEs for prompt injections. Great idea or annoying noise?. (Spoiler alert, given the state of vuln mgmt I support cves m….
0
1
0
@gynvael
Gynvael Coldwind
12 days
RT @justCatTheFish: 🎯 JustCTF 2025 - 37h of top-tier online jeopardy CTF action!.🗓️ Starts Aug 2, 0600 UTC.💰 $8,628 prize pool + IDA Pro li….
0
17
0
@gynvael
Gynvael Coldwind
13 days
RT @phrack: Going to @defcon?! We'll have 9500 print copies of Phrack, and Sunday @ noon @netspooky @richinseattle and @chompie will be on….
0
90
0
@gynvael
Gynvael Coldwind
14 days
RT @r0keb: Good Morning! Just published a blog post diving into Windows Kernel LFH exploitation in the latest Windows 24h2 build, Focusing….
r0keb.github.io
Good morning! In today’s blog post, we’re going one step further than in the previous post Windows Kernel Pool Internals (which I recommend reading to understand some of the concepts discussed here),...
0
79
0
@gynvael
Gynvael Coldwind
1 month
Lulu (print on demand) is increasing prices by 5% from Aug 1st, so if you were thinking of getting @pagedout_zine #6 there, do it now:
0
1
4
@gynvael
Gynvael Coldwind
1 month
[Please share with people outside of cybersec].Do you have a horror story when you had to deal with cybersecurity companies / people? This is your chance to vent! → I'm running an anonymous survey to listen to stories and look into the disconnect we have.
Tweet card summary image
docs.google.com
This anonymous survey if for people who are NOT working in cybersecurity and who had to contract people / buy services / buy products from companies in cybersecurity / use cybersecurity products /...
1
6
15
@gynvael
Gynvael Coldwind
1 month
RT @sirdarckcat: I wrote two challenges for this year's Google CTF. One of them is Circo - A challenge inspired by EntrySign (the AMD ucode….
0
44
0