Rick de Jager

CyberSecurity student at TU Eindhoven - CTF with superfl.at / org.anize.rs

2023-01-04

This was supposed to be a quick 2-3 day project over the holidays to learn some Windows pwn, but it ended up taking over a week 😅.

I might still write a blog post on it, but don't expect a full weaponized POC as the game is EOL.

2023-01-04

I managed to get code execution through a Trackmania Nations Forever map.

By loading or joining a server with a malicious track, an attacker could potentially take over your system.

youtube.com/watch?v=MpfY8r-4xW

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst