RedTeam Pentesting

@redteam-pentesting.de

Account for RedTeam Pentesting GmbH Imprint: https://redteam-pentesting.de/imprint/

Haix-la-Chapelle 2025 is over! 128 teams submitted at least one flag, 270 correct flags were submitted, and 589 drinks consumed. The winners are: 🥇 Team tjcsc with 3165 points 🥈Team THEM?! with 2665 points 🥉Team IT-Security Club with 2087 points Thanks to all participants, see you next year!

👀 Turns out MS-EVEN can do a lot more than NULL auth: In addition to leaking environment variables, it is possible to coerce authentication from arbitrary logged on users* 🤯 *If you are willing to trigger Windows Defender.

🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: blog.redteam-pentesting.de/2025/reflect...

A Look in the Mirror - The Reflective Kerberos Relay Attack

It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...

blog.redteam-pentesting.de

🚨🚨🚨 Just a heads-up: Microsoft will release a fix for a vulnerability we discovered as part of Patch Tuesday, today. MS classified CVE-2025-33073 as "important" and we recommend patching soon. Stay tuned for our blog post and paper about it tomorrow at 10:00 am CEST 🔥