@rdjgr

Security Researcher @v12sec - CTF with Superflat / @0rganizers / ICC team Europe 22/23/24/25

Joined November 2018
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit ✨ Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
63
675
34
8,315
304,418
How it _feels_ to write thumbnailer exploits on my own system
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
3
5
1
66
7,349
Rick de Jager retweeted
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
7
19
4
193
37,933
Rick de Jager retweeted
We can use our Ghostscript exploits to directly attack KDE's file manager from a single link click in Chrome. This PoC Downloads the file, then pops open the file manager for unsandboxed RCE (lovingly refered to as the full chain from temu)
Memory corruption in Ghostscript 👻 This 1980's image parser might still get you shells in the big '26 PoC below
6
36
5
437
27,539
Rick de Jager retweeted
Security researchers from Zellic and V12 are presenting at BSides Canberra this week! @farazsth98 on weaponizing a subtle kernel bug. @rdjgr on heap corruption bugs in ghostscript, and the many targets affected. Both talks will be on main stage on Friday morning, come say hi!
2
9
62
3,099
Interestingly this is a very similar primitive to one of the "unexploitable" dead ends in @trailofbits recent article about sandbox escapes. (although this is a slightly different bug) It did take some manual nudging for me to convince 5.6-sol that AppArmor could be bypassed :)
user → root privesc 0-day in CUPS a free PoC while we wait for some bigger disclosures to go through 😇
5
31
3,653
Rick de Jager retweeted
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
44
253
36
2,370
467,745
Rick de Jager retweeted
Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page. This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps. PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance... Breakdown and POC. 🧵
5
55
3
332
47,495
Rick de Jager retweeted
Stored XSS in Forgejo, leading to full control over a victim's account:
1
10
41
4,517
Rick de Jager retweeted
XSS to full account takeover and wallet drain in Ditto. V12 found a deeplink parser bug that steals Nostr private keys with just one click. Here's how. 🧵
5
13
2
100
20,658
Rick de Jager retweeted
Signal's Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud. V12 broke into that enclave and leaked the key, allowing the server host to decrypt everything. Two separate critical bugs: arbitrary read and RCE. Here's how. 🧵
17
146
41
724
137,444
Rick de Jager retweeted
another one (poc) for redis server RCE: github.com/v12-security/pocs… handleClientsBlockedOnKey() use-after-free. patched in release 8.8.2.
found another one! redis 8.8.0 bidirectional RCE we will release poc after the patch
2
17
1
128
22,842
Rick de Jager retweeted
and here's our poc for postgres server RCE: github.com/v12-security/pocs… CVE-2026-14669. patched postgreSQL 18.6. poc for client RCE 🔜
And here's postgres bidirectional RCE no admin required, client infects server, server infects client ♻️🐛
4
56
1
300
33,103
Rick de Jager retweeted
🐬🐬🐬 dolphin rce 🐬🐬🐬
41
104
16
2,164
205,782
Rick de Jager retweeted
Type text into Wikipedia. Get the shell's output back on the page. A bug introduced 22 years ago. Still alive in the wild, until it was found by V12. Here's how EasyTimeline allowed arbitrary code execution (RCE) directly from wikitext.
9
86
12
663
122,221
If you like my reverse-engineering, deobfuscation or malware work, I'm looking for a job - I am a security researcher with a knack for deep tooling/capability development and I've also done blue-team/pentesting work. DM me if you want my resume or if you want to ask questions!
I continue being a reverse-engineering thing. LyticEnzyme has been updated to support both closed and open type worlds, and to enable recovery of method symbols even from stripped bins! Stretch goal is pseudocode cleanup of SubstrateVM snippets using a custom Lang. Repr.
2
15
128
9,808
Rick de Jager retweeted
here's a mariadb RCE, what should we look at next?
13
45
5
396
72,156
Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and you get remote code execution.
44
253
36
2,370
467,745
With this proxy, we can: 1. Advertise a custom map named with a path traversal. 2. Overwrite the bug reporter exe. 3. Crash the victim’s game using a crash bug. (left as an exercise to the reader) A stealthier attacker would overwrite a game DLL instead and go undetected.
1
2
33
7,246
Finally, two huge shout-outs for the RE work: • @ZetaTwo for the excellent RE//verse talk • The intern who released AoE2DE_s_original.exe without obfuscation ;) The bug was patched in April (update 174992); MSRC just took a while to assign the CVE.
1
2
1
43
7,561