Sign in

RedTeam Pentesting

@redteam-pentesting.de
84 followers 49 following 32 posts

Account for RedTeam Pentesting GmbH Imprint: redteam-pentesting.de/imprint

PostsRepliesMedia
RedTeam Pentesting @redteam-pentesting.de · 21/09/2026
🚨 Rocket Remote Desktop encrypts users' saved credentials with their Windows SIDs. Every user with access to a Windows client on which the client software is installed has access to the database, where these credentials are saved. No fix available yet. www.redteam-pentesting.de/en/advisorie...
redteam-pentesting.de
RedTeam Pentesting - Insecure Storage and Weak Encryption of Credentials in Rocket Remote Desktop
Attackers with access to a computer with Rocket Remote Desktop can read the credentials of the global database. With these credentials, they can view and decrypt the saved credentials of all users who...
010
RedTeam Pentesting @redteam-pentesting.de · 30/01/2026
This is kind of funny because CustomKeyInformation is actually forbidden for validated writes according to Microsoft's specs 🤡 learn.microsoft.com/en-us/opensp...
learn.microsoft.com
[MS-ADTS]: msDS-KeyCredentialLink
The object has class computer (or a subclass of computer). The msDS-KeyCredentialLink value satisfies the following
010
RedTeam Pentesting @redteam-pentesting.de · 30/01/2026
Originally, Microsoft did not enforce their own specs for validated writes at all and only checked if a KeyCredentialLink is already present. Now they require a CustomKeyInformation field with the "MFA Not Required" flag to be present and the last logon timestamp to be absent.
110
RedTeam Pentesting @redteam-pentesting.de · 30/01/2026
🚀Our tool keycred for KeyCredentialLinks and Shadow Credential attacks now works with updated domain controllers again! It turns out, Microsoft violated their own specs. Try it out: github.com/RedTeamPente...
111
RedTeam Pentesting @redteam-pentesting.de · 04/12/2025
🚨Nextcloud was vulnerable to XSS in PDF.js (CVE-2024-4367) found by Thomas Rinsma at CodeanIO. Although Nextcloud mitigated the vulnerability in their portal by disabling eval, the viewer.html component of the vulnerable PDF.js was still exposed. www.redteam-pentesting.de/en/advisorie...
redteam-pentesting.de
RedTeam Pentesting - Cross-Site Scripting in Nextcloud: Development files shipped in files_pdfviewer app
Nextcloud’s PDF viewer uses an outdated version of PDF.js vulnerable to CVE-2024-4367. Attackers with regular user access to a Nextcloud instance are able to prepare a special link. If this link is vi...
010
Reposted by RedTeam Pentesting
Pwn-la-Chapelle @pwn-la-chapelle.eu · 30/11/2025
Haix-la-Chapelle 2025 is over! 128 teams submitted at least one flag, 270 correct flags were submitted, and 589 drinks consumed. The winners are: 🥇 Team tjcsc with 3165 points 🥈Team THEM?! with 2665 points 🥉Team IT-Security Club with 2087 points Thanks to all participants, see you next year!
011
Reposted by RedTeam Pentesting
Pwn-la-Chapelle @pwn-la-chapelle.eu · 28/11/2025
By popular demand, registrations for Haix-la-Chapelle are now open! Register your account here: haix-la-chapelle.eu/register If you experience any issues, open a support ticket on our discord: discord.gg/ASYqv7N2Rj
haix-la-chapelle.eu
Haix-la-Chapelle 2025
022
Reposted by RedTeam Pentesting
Pwn-la-Chapelle @pwn-la-chapelle.eu · 26/11/2025
It's hard hosting a new CTF #haix25
Panic Calm meme

First row:
New unknown haix la chapelle ctf, *panic picture*
Second row:
they have glühwein and flags, *kalm picture*
last row:
red flags, *panic picture*
021
Reposted by RedTeam Pentesting
Pwn-la-Chapelle @pwn-la-chapelle.eu · 19/11/2025
Just 10 days left until our first CTF, Haix-la-Chapelle, starts! We have been hard at work and are excited to have you play our challenges 👀 CTF starts at 10am CET on 29th November with prizes sponsored by our lovely sponsors @redteam-pentesting.de and @binary.ninja
ctftime.org
Haix-la-Chapelle 2025
Haix‑la‑Chapelle 2025 is a online Jeopardy-style CTF organized for the first time by Pwn‑la‑Chapelle and friends! It...
121
RedTeam Pentesting @redteam-pentesting.de · 19/11/2025
You can find the CTFTime event at ctftime.org/event/2951
ctftime.org
Haix-la-Chapelle 2025
Haix‑la‑Chapelle 2025 is a online Jeopardy-style CTF organized for the first time by Pwn‑la‑Chapelle and friends! It...
010
RedTeam Pentesting @redteam-pentesting.de · 19/11/2025
🔥Only 10 days left until the Haix-la-Chapelle 2025 CTF is starting on November 29! We're sponsoring the prize money for the best writeups and are excited to see your creative solutions. haix-la-chapelle.eu
haix-la-chapelle.eu
Haix-la-Chapelle 2025
121
RedTeam Pentesting @redteam-pentesting.de · 13/11/2025
That's correct. We assumed that you are pulling security updates from Red Hat and therefore either rely on their handling of CVEs or follow the bug tracker or mailing lists yourselves. You can simply apply the fix that was published by Ghostscript earlier this year.
100
RedTeam Pentesting @redteam-pentesting.de · 13/11/2025
Thanks for the hint! However, we think this is a systemic problem that should be fixed as close to the source as possible, especially since the upstream distribution is a commercial one and patches are available.
100
RedTeam Pentesting @redteam-pentesting.de · 13/11/2025
Disclaimer: We did not discover this vulnerability (credits go to zhutyra🎉), we're just wondering why we can still exploit these vulnerabilities in pentests on patched systems 🤷 We received no response on the RHEL bug tracker: bugzilla.redhat.com/show_bug.cgi...
bugzilla.redhat.com
2354947 – (CVE-2025-27835) CVE-2025-27835 Ghostscript: Buffer overflow when converting glyphs to unicode
000
RedTeam Pentesting @redteam-pentesting.de · 13/11/2025
This is neither the first, nor the second time that we can't get distros to apply upstream fixes for publicly disclosed RCEs with POCs available in Ghostscript. x.com/RedTeamPT/st...
x.com
RedTeam Pentesting on X: "🚨 Another month, another critical Ghostscript RCE, with patches rolling out rather slowly to some distros again 👻😱 #infosec #DeprecateUntrustedPostscript" / X
🚨 Another month, another critical Ghostscript RCE, with patches rolling out rather slowly to some distros again 👻😱 #infosec #DeprecateUntrustedPostscript
100
RedTeam Pentesting @redteam-pentesting.de · 13/11/2025
Red Hat is aware, but they chose not to fix it. They also assigned a low CVSS score 5.5 because it is supposed to be "only exploitable locally" even though many web apps process uploaded documents using Ghostscript: access.redhat.com/security/cve...
access.redhat.com
cve-details
100
RedTeam Pentesting @redteam-pentesting.de · 13/11/2025
🚨8 months after public disclosure, RHEL @almalinux.org @rockylinux.org are still vulnerable for a Ghostscript RCE with a reliable public exploit (CVE-2025-27835 and others)! It can be triggered by opening LibreOffice docs or through a server that uses ImageMagick for file conversion!
200
Reposted by RedTeam Pentesting
Taggart @taggart-tech.com · 20/10/2025
So CVE-2025-33073 (Reflective Kerberos Relay) has been added to CISA KEV. In the original writeup, SMB Signing (server-side) is listed as a mitigation for this vulnerability. HOWEVER... blog.redteam-pentesting.de/2025/reflect...
blog.redteam-pentesting.de
A Look in the Mirror - The Reflective Kerberos Relay Attack
It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...
131
Reposted by RedTeam Pentesting
Pwn-la-Chapelle @pwn-la-chapelle.eu · 08/10/2025
We are happy to announce that we will be hosting our first ever CTF, Haix-la-Chapelle 2025, on the 29th of November! It will be a Jeopardy style CTF and will start at 10 am Berlin time, lasting for 24 hours. You can find the CTFTime event at ctftime.org/event/2951 See you there!
haix-la-chapelle.eu
Haix-la-Chapelle 2025
033
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
Check out our Impacket PR that adds SMB signing support (NTLM and Kerberos) to smbserver.py to allow Windows 11 clients that require signing by default to connect: github.com/fortra/impac...
smbserver.py
000
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
Another interesting tidbit was that the share path can contain environment variables, which are expanded by the host. This could reveal system level variables, which could be interesting in some configurations.
100
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
If you already own the computer account, and want to coerce a logged-in admin, you can use an S4U2self impersonation ticket for that user. So if Defender prevents you from executing code on a computer with an admin, just let it snitch on the admin with a relayable NTLMv2-Hash🤯
100
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
We then discovered, that if Defender is not allowed to delete the file, it will try to re-connect with the account that triggered the coercion. Where do the credentials come from? Well, if the same user is also interactively logged on, Defender will simply steal their token 🥷🏼
100
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
By intentionally coercing a host to open a share with a virus (or an EICAR test file), Windows Defender re-connects with computer account credentials in order to quarantine/delete it 🦠😷
100
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
In May 2025 Sergey Bureev (@TCross) released his research on coercion using MS-EVEN, which by itself only uses NULL authentication, as the service runs as network restricted LOCAL SERVICE. habr.com/ru/companies...
habr.com
Атаки на защиту: Evilent или ещё один coerce
Привет! Меня зовут Сергей Буреев (@TCross \ THunter HackTeam ), я специалист по пентесту и исследователь в области информационной безопасности. Пост будет посвящен ещё одной Coerce атаке, про которую....
100
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
👀 Turns out MS-EVEN can do a lot more than NULL auth: In addition to leaking environment variables, it is possible to coerce authentication from arbitrary logged on users* 🤯 *If you are willing to trigger Windows Defender.
110
RedTeam Pentesting @redteam-pentesting.de · 17/06/2025
We're excited to host our XSS workshop for RWTH Aachen University's SecLab, again. Today, the students will face XSS challenges as well as a hunt for IT security easter eggs to climb the leaderboard 🏆 #rwth #informatik #aachen
Screenshot of the XSS Lab web application showing the leaderboard.
000
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
Based on our testing, MS seems to have fixed CVE-2025-33073 by blocking the CredUnmarshalTargetInfo/CREDENTIAL_TARGET_INFORMATIONW trick! @tiraniddo.dev @decoder-it.bsky.social @synacktiv.com #infosecsky #infosec #pentests #redteam #cybersky #cybersecurity bsky.app/profile/redt...
x.com
RedTeam Pentesting on X: "🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞 The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: https://t.co/ab21IXtp9T" / X
🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞 The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: https://t.co/ab21IXtp9T
010
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
👀 We have also released a paper which really goes into the nitty-gritty for those who are interested 🕵️‍♀️: www.redteam-pentesting.de/publications... For those that only need a short overview, here's our advisory 🚨: www.redteam-pentesting.de/advisories/r...
redteam-pentesting.de
011
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: blog.redteam-pentesting.de/2025/reflect...
blog.redteam-pentesting.de
A Look in the Mirror - The Reflective Kerberos Relay Attack
It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...
173
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
We are referencing CVE-2025-33073: Windows SMB Client Elevation of Privilege Vulnerability (when we sent the tweet, the title was not public, yet)
010
RedTeam Pentesting @redteam-pentesting.de · 10/06/2025
📰 We can recommend last week's blog post about Windows authentication coercion 🔑🔫 as preparation for the upcoming post: blog.redteam-pentesting.de/2025/windows...
blog.redteam-pentesting.de
The Ultimate Guide to Windows Coercion Techniques in 2025
Windows authentication coercion often feels like a magic bullet against the average Active Directory. With any old low-privileged account, it usually allows us to gain full administrative access to al...
110
RedTeam Pentesting @redteam-pentesting.de · 10/06/2025
🚨🚨🚨 Just a heads-up: Microsoft will release a fix for a vulnerability we discovered as part of Patch Tuesday, today. MS classified CVE-2025-33073 as "important" and we recommend patching soon. Stay tuned for our blog post and paper about it tomorrow at 10:00 am CEST 🔥
111
RedTeam Pentesting @redteam-pentesting.de · 05/06/2025
Newer Windows clients often enforce signing ✍️ when using SMB fileshares. To quickly deploy an SMB server with signing supported we implemented this in impacket's smbserver.​py based on a prior work by @lowercasedrm.bsky.social . github.com/fortra/impac...
github.com
smbserver.py: add signing support by using computer account with NetLogon by rtpt-romankarwacik · Pull Request #1975 · fortra/impacket
This pull requests adds the option to support signing for arbitrary clients in a domain. Most of the NetLogon code is based on this gist by @ThePirateWhoSmellsOfSunflowers. To use this functionalit...
021
RedTeam Pentesting @redteam-pentesting.de · 04/06/2025
We also used modified sploutchy's RPC server for impacket's ntlmrelayx.py to also provide a generic endpoint mapper (EPM) to abuse PrinterBug on newer versions of Windows 11. github.com/fortra/impac...
ntlmrelayx.py
021
RedTeam Pentesting @redteam-pentesting.de · 04/06/2025
And this is our pull request to NetExec which adds efsr_spray which can re-enable EFSR/PetitPotam on up-to-date Windows 11 hosts 🤯 if they have a writeable share: github.com/Pennyw0rth/N...
github.com
Add efsr_spray module by rtpt-romankarwacik · Pull Request #718 · Pennyw0rth/NetExec
Description Since Windows 11 23H2 the EFS service is only activated on demand. One ways to activate it is to write an encrypted file to a share on the respective device. This module automates this ...
131
RedTeam Pentesting @redteam-pentesting.de · 04/06/2025
🔥 We also released an cross-platform implementation of WSPCoerce in Python, which should work against all Windows clients: github.com/RedTeamPente...
github.com
GitHub - RedTeamPentesting/wspcoerce: wspcoerce coerces a Windows computer account via SMB to an arbitrary target using MS-WSP
wspcoerce coerces a Windows computer account via SMB to an arbitrary target using MS-WSP - RedTeamPentesting/wspcoerce
110
RedTeam Pentesting @redteam-pentesting.de · 04/06/2025
🎉 It is finally time for a new blog post! Join us on our deep dive into Windows Authentication Coercion and its current state in 2025, including some brand-new tooling ✨ #infosecsky #infosec #pentests #redteam #cybersky #cybersecurity blog.redteam-pentesting.de/2025/windows...
blog.redteam-pentesting.de
The Ultimate Guide to Windows Coercion Techniques in 2025
Windows authentication coercion often feels like a magic bullet against the average Active Directory. With any old low-privileged account, it usually allows us to gain full administrative access to al...
132