thomasrinsma Profile Banner
Thomas Rinsma Profile
Thomas Rinsma

@thomasrinsma

Followers
1K
Following
2K
Statuses
72

Looking for strange loops and weird machines. Lead security analyst @CodeanIO.

Netherlands
Joined March 2013
Don't wanna be here? Send us removal request.
@thomasrinsma
Thomas Rinsma
1 day
Finally cleaned up and published my hacky "toolchain" for running custom code on vulnerable Verifone POS devices, enjoy:
0
0
0
@thomasrinsma
Thomas Rinsma
6 days
Hey cool, my PDF.js exploit made it to this list, thanks!
@PortSwiggerRes
PortSwigger Research
6 days
The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
1
1
49
@thomasrinsma
Thomas Rinsma
21 days
RT @netspooky: Ange just casually playing Tetris in a PDF
Tweet media one
0
3
0
@thomasrinsma
Thomas Rinsma
21 days
RT @angealbertini: We played with JavaScript in PDFs: API difference, text or hex literals or indirect objects. Triggers on document openin…
0
12
0
@thomasrinsma
Thomas Rinsma
28 days
@Reelix I guess it was the inevitable next step so we had the same idea ;) Their execution is much neater though!
0
0
19
@thomasrinsma
Thomas Rinsma
28 days
RT @linguinelabs: You know I had to do it Bad Apple but it's a PDF
0
19
0
@thomasrinsma
Thomas Rinsma
28 days
@linguinelabs Love it!
0
0
1
@thomasrinsma
Thomas Rinsma
28 days
I couldn't resist.
@thomasrinsma
Thomas Rinsma
28 days
Yes, PDF runs DOOM! (PDFium only for now)
0
0
11
@thomasrinsma
Thomas Rinsma
28 days
I got nerdsniped ;) In the end it was not too difficult, Emscripten really is magical. Source here:
1
1
32
@thomasrinsma
Thomas Rinsma
28 days
@gzaloprgm Hah! Good catch, fixed ;)
0
0
0
@thomasrinsma
Thomas Rinsma
1 month
The PDF is in plaintext but for a more readable version see here: Some more disclaimers: this only works (AFAIK) in desktop browsers, and even then it is a bit glitchy. The Tetris implementation could also use some work but it shows the concept :)
0
9
151
@thomasrinsma
Thomas Rinsma
3 months
Tweet media one
0
74
0
@thomasrinsma
Thomas Rinsma
3 months
Credits to @b0n0b0__ and @g_dellimmagine for helping find and PoC these buffer overflows :)
0
4
4
@thomasrinsma
Thomas Rinsma
5 months
RT @evilsocket: Attacking UNIX Systems via CUPS, Part I
0
1K
0
@thomasrinsma
Thomas Rinsma
6 months
@ben221199 Ah grappig. Als je serieuze dingen in die richting wil doen, dan alvast sterkte ;) Het is een hoop bureaucratie en je werkt met protocollen uit de jaren '80. Wel weer leuk vanuit een security oogpunt!
1
0
1