Rick de Jager

119 posts

Rick de Jager banner
Rick de Jager

Rick de Jager

@rdjgr

Security Researcher @v12sec - CTF with Superflat / @0rganizers / ICC team Europe 22/23/24/25

Katılım Kasım 2018
664 Takip Edilen1.8K Takipçiler
Sabitlenmiş Tweet
Rick de Jager
Rick de Jager@rdjgr·
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
English
65
694
8.4K
303.2K
Rick de Jager
Rick de Jager@rdjgr·
@CapkaKarel Honestly mostly intuition. I saw there was a custom file format that unpacks other files to disk and just guessed it might have path traversal.
English
0
1
8
477
Rick de Jager
Rick de Jager@rdjgr·
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
English
44
251
2.4K
231.7K
Rick de Jager
Rick de Jager@rdjgr·
Finally, two huge shout-outs for the RE work: • @ZetaTwo for the excellent RE//verse talk • The intern who released AoE2DE_s_original.exe without obfuscation ;) The bug was patched in April (update 174992); MSRC just took a while to assign the CVE.
English
0
3
43
6.4K
Rick de Jager
Rick de Jager@rdjgr·
With this proxy, we can: 1. Advertise a custom map named with a path traversal. 2. Overwrite the bug reporter exe. 3. Crash the victim’s game using a crash bug. (left as an exercise to the reader) A stealthier attacker would overwrite a game DLL instead and go undetected.
English
1
3
32
6.8K
Sylvie
Sylvie@_sy1vi3·
@v12sec glad to know that this was the last vulnerability to exist in any database software.
English
1
0
5
335
Rick de Jager retweetledi
V12
V12@v12sec·
AnyPwn: AnyDesk preauth 0click RCE (heap buffer overflow) we will release PoC post disclosure and patch
English
28
239
1.6K
129.3K
Rick de Jager retweetledi
DragonSec SI
DragonSec SI@DragonSec_SI·
Meet our #DCTF26 speaker Rick de Jager (@rdjgr )! He will present "𝐙𝐞𝐫𝐨 𝐭𝐨 𝐑𝐂𝐄 𝐢𝐧 𝐚 𝐖𝐞𝐞𝐤𝐞𝐧𝐝: 𝐅𝐮𝐳𝐳𝐢𝐧𝐠 𝐎𝐥𝐝 𝐆𝐚𝐦𝐞𝐬 𝐟𝐨𝐫 𝐌𝐞𝐦𝐨𝐫𝐲 𝐂𝐨𝐫𝐫𝐮𝐩𝐭𝐢𝐨𝐧." Mid-2000s videogames are a great target for finding RCE exploits. In this talk we'll pick a classic 2000's game, go over the process of fuzzing the game's server with a very fancy snapshot fuzzer, and fuzzing the client with the dumbest possible bit-flipper I could write in an hour. Both of these approaches lead to bugs that we'll exploit for remote code execution. Free registration: events.dragonsec.si/dctf26/
DragonSec SI tweet media
English
0
7
115
6.5K
Rick de Jager retweetledi
Manfred Paul
Manfred Paul@_manfp·
@LiveOverflow @_mixy1 If FIFA allowed robot players, and 99% of accomplished soccer players said "we hate this, this ruins our sport", would we all go "this is just what the the word 'soccer' means now"? The community gets some say in what the word "CTF" means. And nearly noone there enjoys AI v. AI.
English
2
16
118
16.6K
Rick de Jager
Rick de Jager@rdjgr·
Some stuff that we ended up scrapping for time: - We were initially going to run the slides in RCT. We actually had working code for this, but dropped it in favor of the Doom demo. - The fuzzer actually had a screenshot mode to generate a timelapse of all the maps it's generating
English
6
4
56
7.6K
Rick de Jager
Rick de Jager@rdjgr·
We (@arctic0x78 and I) ended up winning best meme target for this! Many thanks to the Junkyard crew for running the competition. It's such a cool concept and I really enjoyed all the unhinged exploits people came up with!
Rick de Jager tweet media
English
1
3
45
8.9K
Rick de Jager
Rick de Jager@rdjgr·
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
English
65
694
8.4K
303.2K