Official RedTeam Pentesting GmbH account -- Impressum: redteam-pentesting.de/imprin…

Aachen, Germany
Wir haben eine Mission: Werde eine*r von uns! 👩‍🚀👨‍🚀 Finde gemeinsam mit uns die Schwachstellen von morgen 🔑 und manchmal auch welche aus längst vergangener Zeit 🗝️ Mehr erfahrt ihr unter jobs.redteam-pentesting.de 🚀 #infosec #cybersecurity #aachen #hiring #ITJobs #Pentesting
1
8
🚨 Rocket Remote Desktop encrypts users' saved credentials with their Windows SIDs. Every user with access to a Windows client on which the client software is installed has access to the database, where these credentials are saved. No fix available yet. redteam-pentesting.de/en/adv…
1
17
54
4,233
🚀Our tool keycred for KeyCredentialLinks and Shadow Credential attacks now works with updated domain controllers again! It turns out, Microsoft violated their own specs. Try it out: github.com/RedTeamPentesting…
Anyone know if Microsoft silently patch the Shadow Creds attack recently ? Looks like a computer object cannot write its own attribute anymore :D
4
79
240
29,997
Originally, Microsoft did not enforce their own specs for validated writes at all and only checked if a KeyCredentialLink is already present. Now they require a CustomKeyInformation field with the "MFA Not Required" flag to be present and the last logon timestamp to be absent.
2
3
14
2,177
🎄Care for some Glühwein and flags? The Haix-la-Chapelle CTF 2025 starts tomorrow! 🍷 mastodon.social/@Pwn_la_Chap…
1
2
1,027
🔥Only 10 days left until the Haix-la-Chapelle 2025 CTF is starting on November 29! We're sponsoring the prize money for the best writeups and are excited to see your creative solutions. haix-la-chapelle.eu/
1
1
1
707
🚨8 months after public disclosure, @RHEL @AlmaLinux @rocky_linux are still vulnerable for a Ghostscript RCE with a reliable public exploit (CVE-2025-27835 and others)! It can be triggered by opening LibreOffice docs or through a server that uses ImageMagick for file conversion!
2
17
65
6,115
This is neither the first, nor the second time that we can't get distros to apply upstream fixes for publicly disclosed RCEs with POCs available in Ghostscript.
🚨 Another month, another critical Ghostscript RCE, with patches rolling out rather slowly to some distros again 👻😱 #infosec #DeprecateUntrustedPostscript
1
1
857
Disclaimer: We did not discover this vulnerability (credits go to zhutyra🎉), we're just wondering why we can still exploit these vulnerabilities in pentests on patched systems 🤷 We received no response on the @RHEL bug tracker: bugzilla.redhat.com/show_bug…
1
4
706
RedTeam Pentesting retweeted
Why doesn’t pretender from @RedTeamPT get more love? It’s excellent for relaying.
3
26
130
9,312
👀Turns out MS-EVEN can do a lot more than NULL auth: In addition to leaking environment variables, it is possible to coerce authentication from arbitrary logged on users* 🤯 *If you are willing to trigger Windows Defender.
1
46
163
19,797
Another interesting tidbit was that the share path can contain environment variables, which are expanded by the host. This could reveal system level variables, which could be interesting in some configurations.
1
3
10
1,880