CyberSecurity student at TU/e - CTF with Superflat / @0rganizers / ICC team Europe 22/23/24/25

Joined November 2018
19 Photos and videos
Pinned Tweet
30 Jul 2024
I'm happy to announce that I just wrote my first tethered jailbreak! ... for a VTech phone. I'm still counting it as a win ๐Ÿ™ƒ
2
6
130
18,722
29
1,701
Rick de Jager retweeted
Meet our #DCTF26 speaker Rick de Jager (@rdjgr )! He will present "๐™๐ž๐ซ๐จ ๐ญ๐จ ๐‘๐‚๐„ ๐ข๐ง ๐š ๐–๐ž๐ž๐ค๐ž๐ง๐: ๐…๐ฎ๐ณ๐ณ๐ข๐ง๐  ๐Ž๐ฅ๐ ๐†๐š๐ฆ๐ž๐ฌ ๐Ÿ๐จ๐ซ ๐Œ๐ž๐ฆ๐จ๐ซ๐ฒ ๐‚๐จ๐ซ๐ซ๐ฎ๐ฉ๐ญ๐ข๐จ๐ง." Mid-2000s videogames are a great target for finding RCE exploits. In this talk we'll pick a classic 2000's game, go over the process of fuzzing the game's server with a very fancy snapshot fuzzer, and fuzzing the client with the dumbest possible bit-flipper I could write in an hour. Both of these approaches lead to bugs that we'll exploit for remote code execution. Free registration: events.dragonsec.si/dctf26/
7
111
6,242
Rick de Jager retweeted
If FIFA allowed robot players, and 99% of accomplished soccer players said "we hate this, this ruins our sport", would we all go "this is just what the the word 'soccer' means now"? The community gets some say in what the word "CTF" means. And nearly noone there enjoys AI v. AI.
2
16
119
16,357
Rick de Jager retweeted
Replying to @rdjgr @DistrictCon
Can confirm we have never seen RCT played like that before!
1
27
1,415
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit โœจ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
65
717
8,506
301,483
We (@arctic0x78 and I) ended up winning best meme target for this! Many thanks to the Junkyard crew for running the competition. It's such a cool concept and I really enjoyed all the unhinged exploits people came up with!
1
3
47
8,776
Some stuff that we ended up scrapping for time: - We were initially going to run the slides in RCT. We actually had working code for this, but dropped it in favor of the Doom demo. - The fuzzer actually had a screenshot mode to generate a timelapse of all the maps it's generating
6
4
58
7,442
Rick de Jager retweeted
Collision! PHP Hooligans / @midnightbluelab targeted the Autel MaxiCharger AC Elite Home 40A with the Charging Connector Protocol/Signal Manipulation add-on, hitting a full collision on a two-bug chain, earning $20,000 USD and 3 Master of Pwn points. #Pwn2Own #P2OAuto
4
26
7,826
We are announcing the results of ICC TOKYO 2025! The overall rankings are: 1st place - TEAM EUROPE, 2nd place - TEAM ASIA, and 3rd place - US CYBER TEAM! The winner of Jeopardy was TEAM EUROPE, and the winner of A&D was EUROPE! #icctokyo2025
1
5
33
3,152
Rick de Jager retweeted
We have another collision. The PHP Hooligans did exploit the QNAP TS-453E, but the bug they used was previously seen in the contest. They still earn $10,000 and 2 Master of Pwn points. #Pwn2Own
4
20
4,090
Rick de Jager retweeted
We have another collision. The PHP Hooligans used a buffer overflow to exploit the Phillips Hue Bridge, but the bug had been previously seen in the contest. They still earn $10,000 and 2 Master of Pwn points. #Pwn2Own
1
15
3,913
Rick de Jager retweeted
Confirmed! The PHP Hooligans used an OOB Write bug to exploit the Canon imageCLASS MF654Cdw printer. Their fifth round win earns them $10,000 and 2 Master of Pwn points. #Pwn2Own
2
34
3,530
14 Oct 2025
Writing an exploit? 3 days. Getting a hold of a security contact? 50 days and counting. Dropping a PoC in a random support ticket to meet the Junkyard deadline? Priceless. โœจ
11 Oct 2025
We still have some spots open for DistrictCon junkyard speakers! Not only do you have a chance to show off your awesome work on an end of life target that needs attention โ€“ or laughs โ€“ but also we are giving out cash prizes to winners!!!
14
1,775
Rick de Jager retweeted
11 Aug 2025
[ZDI-25-711|CVE-2025-8320] (Pwn2Own) Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability (CVSS 8.8; Credit: PHP Hooligans) zerodayinitiative.com/advisoโ€ฆ

1
8
1,074
Rick de Jager retweeted
๐ŸŒช๏ธ Tapping into the past @typhooncon with @rdjgr & Carlo Meijerโ€™s RCE via Fax Machine!
7
21
4,072
Rick de Jager retweeted
We'd like to thank the speaker who will be presenting at BSides Tokyo 2025! Speaker: Rick de Jager & Carlo Meijer Title: Dialing into the Past: RCE via the Fax Machine โ€“ Because Why Not?
1
7
739
Rick de Jager retweeted
22 Mar 2025
... and the podium for m0leCon Finals CTF! Congratulations! ๐Ÿšฉ
5
42
6,883
Rick de Jager retweeted
Weโ€™re delighted to welcome @rdjgr & Carlo Meijer to #TyphoonCon2025! ๐ŸŽค๐Ÿ”ฅ Be sure to join us in Seoul on May 29-30 for their amazing talk! ๐Ÿ”— typhooncon.com/agenda
2
8
1,288
24 Jan 2025
Third place ain't bad ๐Ÿฅณ
And thatโ€™s a wrap! #Pwn2Own Automotive 2025 is complete. In total, we awarded $886,250 for 49 0-days over the three day competition. With 30.5 points and $222,250 awarded, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) is our Master of Pwn. #P2OAuto
52
2,842