Meet our #DCTF26 speaker Rick de Jager (@rdjgr )! He will present "๐๐๐ซ๐จ ๐ญ๐จ ๐๐๐ ๐ข๐ง ๐ ๐๐๐๐ค๐๐ง๐: ๐ ๐ฎ๐ณ๐ณ๐ข๐ง๐ ๐๐ฅ๐ ๐๐๐ฆ๐๐ฌ ๐๐จ๐ซ ๐๐๐ฆ๐จ๐ซ๐ฒ ๐๐จ๐ซ๐ซ๐ฎ๐ฉ๐ญ๐ข๐จ๐ง."
Mid-2000s videogames are a great target for finding RCE exploits. In this talk we'll pick a classic 2000's game, go over the process of fuzzing the game's server with a very fancy snapshot fuzzer, and fuzzing the client with the dumbest possible bit-flipper I could write in an hour. Both of these approaches lead to bugs that we'll exploit for remote code execution.
Free registration: https://t.co/FE1JBJadlQ
@LiveOverflow@_mixy1 If FIFA allowed robot players, and 99% of accomplished soccer players said "we hate this, this ruins our sport", would we all go "this is just what the the word 'soccer' means now"?
The community gets some say in what the word "CTF" means. And nearly noone there enjoys AI v. AI.
Some stuff that we ended up scrapping for time:
- We were initially going to run the slides in RCT. We actually had working code for this, but dropped it in favor of the Doom demo.
- The fuzzer actually had a screenshot mode to generate a timelapse of all the maps it's generating
May I present to you; a full copy of doom, running inside of a Rollercoaster Tycoon 1 save game exploit โจ
Thanks for everyone that came to check out our @DistrictCon Junkyard talk! We had a lot of fun putting it together. (check the thread for slides / exploit)
We (@arctic0x78 and I) ended up winning best meme target for this!
Many thanks to the Junkyard crew for running the competition. It's such a cool concept and I really enjoyed all the unhinged exploits people came up with!
Collision! PHP Hooligans / @midnightbluelab targeted the Autel MaxiCharger AC Elite Home 40A with the Charging Connector Protocol/Signal Manipulation add-on, hitting a full collision on a two-bug chain, earning $20,000 USD and 3 Master of Pwn points. #Pwn2Own#P2OAuto
We are announcing the results of ICC TOKYO 2025!
The overall rankings are: 1st place - TEAM EUROPE, 2nd place - TEAM ASIA, and 3rd place - US CYBER TEAM!
The winner of Jeopardy was TEAM EUROPE, and the winner of A&D was EUROPE! #icctokyo2025
We have another collision. The PHP Hooligans did exploit the QNAP TS-453E, but the bug they used was previously seen in the contest. They still earn $10,000 and 2 Master of Pwn points. #Pwn2Own
We have another collision. The PHP Hooligans used a buffer overflow to exploit the Phillips Hue Bridge, but the bug had been previously seen in the contest. They still earn $10,000 and 2 Master of Pwn points. #Pwn2Own
Confirmed! The PHP Hooligans used an OOB Write bug to exploit the Canon imageCLASS MF654Cdw printer. Their fifth round win earns them $10,000 and 2 Master of Pwn points. #Pwn2Own
Writing an exploit? 3 days.
Getting a hold of a security contact? 50 days and counting.
Dropping a PoC in a random support ticket to meet the Junkyard deadline? Priceless. โจ
We still have some spots open for DistrictCon junkyard speakers! Not only do you have a chance to show off your awesome work on an end of life target that needs attention โ or laughs โ but also we are giving out cash prizes to winners!!!
We'd like to thank the speaker who will be presenting at BSides Tokyo 2025!
Speaker: Rick de Jager & Carlo Meijer
Title: Dialing into the Past: RCE via the Fax Machine โ Because Why Not?
Weโre delighted to welcome @rdjgr & Carlo Meijer to #TyphoonCon2025! ๐ค๐ฅ
Be sure to join us in Seoul on May 29-30 for their amazing talk!
๐ https://t.co/BewhLLAhGi