thomasrinsma Profile Banner
Thomas Rinsma Profile
Thomas Rinsma

@thomasrinsma

Followers
1K
Following
2K
Media
9
Statuses
80

Looking for strange loops and weird machines. Lead security analyst @CodeanIO.

Netherlands
Joined March 2013
Don't wanna be here? Send us removal request.
@thomasrinsma
Thomas Rinsma
24 days
Here's the write-up for the OpenPGP.js signature spoofing bug which @b0n0b0__ and I found. The PoC is included at the end, where we demonstrate by spoofing a message by the Dutch government's Cyber Security Center ;).
3
34
144
@thomasrinsma
Thomas Rinsma
1 month
RT @yeswehack: InfoSec media has jumped on the story of a vulnerability found via the OpenPGP.js Bug Bounty program on @yeswehack that allo….
0
8
0
@thomasrinsma
Thomas Rinsma
2 months
RT @thomasrinsma: @b0n0b0__ and I found a bug in OpenPGP.js that allowed an attacker to modify a valid signature's text, without access to….
0
4
0
@thomasrinsma
Thomas Rinsma
2 months
RT @CodeanIO: Codean Labs' @b0n0b0__ and @Doyensec's @drw0if discovered CVE-2025-32464, a heap-buffer overflow in HAProxy. Read our write-u….
0
6
0
@thomasrinsma
Thomas Rinsma
5 months
Just published the write-up of two bugs I found in LibreOffice, allowing remote exfiltration of file/env data and a semi-arbitrary file write. Also relevant for document conversion/preview usecases :).
2
17
104
@thomasrinsma
Thomas Rinsma
5 months
Finally cleaned up and published my hacky "toolchain" for running custom code on vulnerable Verifone POS devices, enjoy:
0
0
1
@thomasrinsma
Thomas Rinsma
5 months
Hey cool, my PDF.js exploit made it to this list, thanks!.
@PortSwiggerRes
PortSwigger Research
5 months
The results are in! We're proud to announce the Top ten web hacking techniques of 2024!
1
1
50
@thomasrinsma
Thomas Rinsma
6 months
RT @netspooky: Ange just casually playing Tetris in a PDF
Tweet media one
0
3
0
@thomasrinsma
Thomas Rinsma
6 months
RT @angealbertini: We played with JavaScript in PDFs:.API difference, text or hex literals or indirect objects. Triggers on document openin….
0
11
0
@thomasrinsma
Thomas Rinsma
6 months
RT @linguinelabs: You know I had to do it. Bad Apple but it's a PDF
0
19
0
@thomasrinsma
Thomas Rinsma
6 months
I couldn't resist.
@thomasrinsma
Thomas Rinsma
6 months
Yes, PDF runs DOOM! (PDFium only for now)
0
0
11
@thomasrinsma
Thomas Rinsma
6 months
I got nerdsniped ;) In the end it was not too difficult, Emscripten really is magical. Source here:
1
1
33
@thomasrinsma
Thomas Rinsma
6 months
Yes, PDF runs DOOM! (PDFium only for now)
16
214
2K
@thomasrinsma
Thomas Rinsma
6 months
I wrote down some of the why/how of PDF Tetris as people were asking: Maybe I should actually try to port DOOM, hmm. .
2
3
25
@thomasrinsma
Thomas Rinsma
6 months
The PDF is in plaintext but for a more readable version see here: Some more disclaimers: this only works (AFAIK) in desktop browsers, and even then it is a bit glitchy. The Tetris implementation could also use some work but it shows the concept :).
0
9
148
@thomasrinsma
Thomas Rinsma
6 months
Here's a working game of Tetris inside a PDF. Even has keyboard controls (by typing WASD in an input box). Plus, upon game-over you can "save" your score by printing the page ;). Should work in most browsers (built for pdfium/PDF.js).
Tweet media one
53
324
2K
@thomasrinsma
Thomas Rinsma
8 months
Tweet media one
0
74
0
@thomasrinsma
Thomas Rinsma
8 months
Credits to @b0n0b0__ and @g_dellimmagine for helping find and PoC these buffer overflows :).
0
4
4
@thomasrinsma
Thomas Rinsma
8 months
We've published the final part of our research into Ghostscript, leading to CVE-2024-29506, CVE-2024-29507, CVE-2024-29508, and CVE-2024-29509. Not as practically exploitable as the previous ones, but just as fun to find, hope you enjoy.
2
23
92
@thomasrinsma
Thomas Rinsma
9 months
RT @evilsocket: Attacking UNIX Systems via CUPS, Part I .
0
1K
0