IT-Security Student, @allesctf Member, Co-Founder and Security Researcher @neodyme

Joined July 2012
2 Photos and videos
D_K retweeted
May 1
CSCG/OpenECSC 2026 ist erfolgreich abgeschlossen! ๐ŸŽ‰ Die besten Player aus den Kategorien Junior und Senior werden nun zum Auswahl-Event eingeladen, bei dem das deutsche Team fรผr die ECSC in Bochum bestimmt wird.
1
5
151
D_K retweeted
Feb 23
Germany will host the European Cybersecurity Challenge (ECSC) 2026 in Bochum. NFITS e.V. will be the main organizer. ~500 participants are expected in October, with finalists competing in up to 45 national teams. ๐Ÿ‘‰ecsc2026.de/news/ecsc-2026-bโ€ฆ

8
22
656
D_K retweeted
Confirmed! Neodyme AG (@Neodyme) used a stack based buffer overflow to get a root shell on the Alpine iLX-F511, earning $20,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
4
23
2,718
D_K retweeted
Jan 14
Drones are hot - their security is not. Here is how removed the NAND, dumped firmware, and reverse-engineered ECC on a consumer drone. Stay tuned for part 2! neodyme.io/de/blog/drone_hacโ€ฆ
2
14
20
1,394
D_K retweeted
23 Oct 2025
Another amazing #Pwn2Own in the books! ๐Ÿ’ช Our team pulled off some great hacks: ๐Ÿ–จ๏ธ HP Printer โ€” $20K / 2 MoP ๐Ÿ  Home Assistant โ€” $15K / 3 MoP ๐Ÿ”Œ Smart Plug โ€” $20K / 2 MoP ๐Ÿ“ธ Canon โ€” $10K / 2 MoP Total: $65K / 9 MoP So proud of what we achieved together! ๐Ÿง โšก
3
3
24
2,027
D_K retweeted
Success! We had a little configuration confusion, but Team Neodyme (@Neodyme) hopped for joy as their exploit of the Amazon Smart Plug was successful. Their attack went over Bluetooth & WiFI, so they used the RF enclosure. They head off to the disclosure room with details. #Pwn2Own
4
13
4,854
D_K retweeted
Would you like to participate in the German Hacking Championship next year? ๐Ÿ’ป๐ŸŽ‰Then, your next chance to qualify is this weekend! Have fun at #enowars, an attack-defense CTF hosted by @ENOFLAG.
1
3
233
D_K retweeted
1 Mar 2025
The Cyber Security Challenge Germany 2025 has started! ๐ŸŽ‰ The competition runs from March 1 - 18:00 CET to May 1 - 18:00 CEST. We're excited to announce that we are inviting the top 6 DACH players in the EARTH category to the @DHM_ctf! Participate now at: play.cscg.live/

ALT Hffgf GIF

5
13
4,970
D_K retweeted
15 Jan 2025
Following our #38c3 talk about exploiting security software for privilege escalation, we're excited to kick off a new blog series! ๐ŸŽŠ Check out our first blog post on our journey to ๐Ÿ’ฅ exploit five reputable security products to gain privileges via COM hijacking: neodyme.io/blog/com_hijackinโ€ฆ
1
22
71
15,692
D_K retweeted
27 Dec 2024
ND people are @ #38c3 in Hamburg, Germany. Be sure to check out our two talks about LPEs in AV/EDR Products (Saturday, 4 PM YELL) and a not yet mitigated Bitlocker Flaw! (Saturday, 7:15 PM HUFF)
1
4
9
1,294
D_K retweeted
25 Oct 2024
Since we had used a different setup without any administrator account, our official attempt during #Pwn2Own failed. However, @thezdi provided us with a second chance to present our Lexmark exploit and it worked ๐Ÿ–จ๏ธ๐ŸŽ‰
2
2
26
2,353
24 Oct 2024
After a great #Pwn2Own with @Neodyme , I would like to share some insights I gained when working with the AeoTec Smart Home Hub. We did not manage to find any bugs in time but dumping the firmware was a great lesson. So, letโ€™s tell you the story of how I approached this target.
1
15
103
17,240
24 Oct 2024
After some reversing and looking arround, I noticed the U-Boot version was 2017.11 . A quick search revealed CVE-2020-10648. A verified boot bypass for U-Boot. What was left was crafting a new fit image and using a custom initrd with the init command replaced, by a shell.
1
1
1,045
24 Oct 2024
Now I could either reflash the emmc chip or use the nice USB-Boot mode of the custom U-Boot ;), though that required pulling Boot0 Pin high and a weird USB Flash drive config.
3
8
1,003
D_K retweeted
Our final SOHO Smashup of Day 2 ends with a partial collision. Neodyme (@Neodyme) used 4 bugs, including a stack-based buffer overflow, in their successful demonstration, but 1 bug had previously been used in the contest. They earn $21,875 and 8.75 Master of Pwn points. #Pwn2Own
5
27
13,567
D_K retweeted
22 Oct 2024
gg, this should fit nicely into our new office ๐Ÿ–จ๏ธ We'll be looking to complete the set tomorrow by attacking Lexmark CX331adwe at 3pm in the printers category and QNAP QHora-322 and Canon imageCLASS MF656Cdw at 5pm in the SOHO category. See you there!
Confirmed! Team Neodyme (@Neodyme) used a stack-based buffer overflow to exploit the HP Color LaserJet Pro MFP 3301fdw printer. The earn $20,000 and 2 Master of Pwn points. #Pwn2Own #P2OIreland
3
5
24
2,289
D_K retweeted
Confirmed! Team Neodyme (@Neodyme) used a stack-based buffer overflow to exploit the HP Color LaserJet Pro MFP 3301fdw printer. The earn $20,000 and 2 Master of Pwn points. #Pwn2Own #P2OIreland
7
61
11,148
D_K retweeted
6 Dec 2023
The cyber mimic defense starts soon thanks for the invitation. Good luck to all teams.
3
2
33
6,061