One of my favorite projects just hit a HUGE milestone of 1 million downloads!
Kudos to the team and everyone who supported us!
@gynvael.bsky.social
Security researcher/programmer ⁂ Managing director @ HexArcana ⁂ @DragonSectorCTF founder ⁂ he/him
One of my favorite projects just hit a HUGE milestone of 1 million downloads!
Kudos to the team and everyone who supported us!
You can write '2' (0x32) anywhere in the filesystem of a Linux-based network switch. How do you get root?
That's basically what my talk at GreHack conference was about - enjoy!
youtu.be/F4CudbWHZ7Y?...
youtu.be/X-ZJH4d2tuE?...
Btw, you can get Paged Out! either at events (pagedout.institute?page=event-p...) or, if you want to buy one, we have #6 and #7 available on lulu: www.lulu.com/spotlight/pa...
And if you want Paged Out! at your event - or you want to sponsor Paged Out! prints for events, get in touch with us :)
9 printed magazines lined up; the side one is visibly matte, next ones are glossy, apart from two last ones which seem to be in-between. There's issue 1, issue 5, 3 times issue 6, and 4 times issue 7. As per text on the photo, they are either from print series for various conferences, or just test-prints ordered at lulu.
With the newest Black Alps 2025 and GreHack 2025 additions, my printed Paged Out! collection is slowly growing!
29.11.2025 09:05 — 👍 9 🔁 0 💬 2 📌 0pagedout.institute ← Call for articles & art for issue #8 of this technical IT zine is open! As usual, we accept 1-page articles about everything interesting in IT and related fields (be it programming, cybersec, AI, demoscene, retro, electronics, etc).
24.11.2025 09:23 — 👍 6 🔁 5 💬 0 📌 0Exactly this!
13.11.2025 10:49 — 👍 0 🔁 0 💬 1 📌 0Yup! It's called Hash flooding / HashDoS (en.wikipedia.org/wiki/Collisi...)
They can collide due to the pigeon hole principle of course.
True - but why does it have to be random? There's a cool reason ;)
13.11.2025 10:06 — 👍 0 🔁 0 💬 1 📌 0Agreed! Also, the reason why the effective order is different in every run is pretty interesting ;)
13.11.2025 09:31 — 👍 0 🔁 0 💬 1 📌 0Ah, but this isn't just about the order - it's about why it's non-deterministic! There's an interesting story and reason behind that :)
13.11.2025 09:31 — 👍 0 🔁 0 💬 1 📌 0First run: has alice a cat Second run: a cat alice has Third run: has alice a cat Fourth run: alice a cat has
Here's some blursed Python code for you:
a, b, c = {"alice", "has", "a cat"}
print(a, b, c)
Yup. To be more exact, cPython's compiler does constant deduplication inside a compilation unit (i.e. a single "code" object). If it compiles lines separately like in normal REPL use, it won't deduplicate 257. If it would compile them at the same time (like in that py file), they get deduplicated.
09.11.2025 09:30 — 👍 1 🔁 0 💬 0 📌 0Source: a question asked by an attentive attendee at my Python workshop yesterday.
08.11.2025 10:01 — 👍 1 🔁 0 💬 0 📌 0Left side: in Python Repl: Line 1: a = 257. Line 2: b = 257. Line 3: a is b. Result: False. Now right side: a python source file called is.py has the following content: Line 1: a = 257. Line 2: b = 257. Line 3: print(a is b). When running this code with python the result is: True Left side had result False. Right side has result True. Code looks identical.
Here's a Saturday Python 3 Puzzle for you:
08.11.2025 09:59 — 👍 7 🔁 0 💬 4 📌 0If you've liked my "Linux Terminal: CTRL+D is like pressing ENTER" article (hackarcana.com/article/ctrl...), be sure to checkout @mina86.com's "Is Ctrl+D really like Enter?" (mina86.com/2025/is-ctrl...) :)
05.11.2025 11:41 — 👍 3 🔁 0 💬 0 📌 0Heeey, ncurses/terminfo has a small virtual machine! And if there's a VM, there are CTF challenges :)
hackarcana.com/public-exerc...
hackarcana.com/public-exerc...
(third one coming next week, will be a bit harder)
We've received 50 required articles for issue #7 of
@pagedout.bsky.social - this means we're publishing the issue in the few next weeks.
1. Want to get an article in #7? You should write it now and send it in in the next few days.
2. We're still looking for more issue sponsors!
OK, ChatGPT 5 admittedly surprised me in a positive way. I threw a PNG with a (small) Python AST graph at it and told it to reverse it to Python code, and it successfully did that. I have expected it to fail hard, but here we are 🤷.
02.09.2025 08:40 — 👍 8 🔁 1 💬 0 📌 0Python: 20000000000000000000.0 + 1337.0 - 20000000000000000000.0 is 0, but same numbers, with addition of 1337 moved after subtraction results in 1337.
Friendly reminder that order of operations makes a difference... more so than you think ;)
11.08.2025 10:06 — 👍 6 🔁 0 💬 2 📌 0Lulu (print on demand) is increasing prices by 5% from Aug 1st, so if you were thinking of getting @pagedout.bsky.social #6 there, do it now: www.lulu.com/search?page=...
10.07.2025 06:49 — 👍 3 🔁 1 💬 0 📌 0[Please share with people outside of cybersec]
Do you have a horror story when you had to deal with cybersecurity companies / people? This is your chance to vent! → forms.gle/9aX24HrfnEQm...
I'm running an anonymous survey to listen to stories and look into the disconnect we sometimes have.
Yet another ZIP trick...
hackarcana.com/article/yet-...
+ a hands on exercise if you want to try this yourself:
hackarcana.com/article/yet-...
A (not so) short analysis of anonymization schema used in the "Discord Unveiled" paper: hackarcana.com/article/anon...
23.05.2025 12:38 — 👍 2 🔁 0 💬 0 📌 0Thanks! That's MacOS Terminal.app, right?
18.05.2025 06:44 — 👍 1 🔁 0 💬 1 📌 0Poll! What ANSI color types does your terminal support?
"\x1b[1;31m3bpp+attr\x1b[m \x1b[91m4bpp\x1b[m \x1b[38:5:196m8bpp\x1b[m \x1b[38;2;255;0;0m24bpp\x1b[m"
Reply with screenshot of the output of this string + add OS/terminal versions
E.g. Ubuntu 24.04.2LTS, Konsole 23.08.5
Btw, is there sth like (www.web3isgoinggreat.com) but about AI fails?
12.05.2025 14:53 — 👍 5 🔁 1 💬 1 📌 0[PL] W przyszłym tygodniu zaczynam nową serię szkoleniową - 10 projektów w Pythonie krok po kroku (python.sekurak.pl). Coś dla osób bardziej początkujących, w szczególności dla osób, które trafiły na ścianę po hello world / kalkulatorze, albo mają problem jak ↓
28.04.2025 10:10 — 👍 1 🔁 0 💬 0 📌 0Doing a short livestream in ~30 minutes with inspecting a pcap with USB traffic from a gamepad – www.youtube.com/live/xVrxfEk...
02.04.2025 16:25 — 👍 1 🔁 0 💬 0 📌 0Doing a free webinar today at 8PM CEST (i.e. livestream with slides) about "files", as entities on the filesystem, seen through the eyes of a security researcher.
hexarcana.ch/lp/files/ ← sign up here if interested
Paged Out! #6 is out!
pagedout.institute
Totally free, 80 pages, best issue so far!
'nuff said, enjoy!
(please repost to help spread out the news!)