
LazyTitan
@LazyTitan33
Followers
2K
Following
2K
Media
278
Statuses
1K
Pentester | eWPTXv2 | eCPTXv2 | eCPPTv2 | eWPT | CNPen | eJPT CVE-2025-22458: https://t.co/qX6CTzNepe
Joined February 2012
šI got my first CVE in your favorite security product: CVE-2025-22458 ā LPE with built-in persistence in Ivanti Endpoint Manager. Patch available ā update ASAP āļø.Full advisory: .#CyberSecurity #CVE2025 #Ivanti #EPM #ExploitDev #DLLHijacking.
sec-consult.com
ā ļø We discovered CVE-2025-22458 ā a privilege escalation vuln in Ivanti Endpoint Manager. A SYSTEM task loads DLLs from user-writable paths, enabling local escalation & persistence. Patch available! .Full advisory: .@LazyTitan33 #CVE2025 #Ivanti #EPM.
5
3
47
I just pwned Mirage on @hackthebox_eu! I enjoyed the path up to a point, but there comes a step which is very hard to enumerate or figure out. Without some help, it is very nearly a guess, a shot in the dark. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
2
4
49
I just pwned Outbound on @hackthebox_eu! This was a fun box. It only requires a bit of attention to detail and some minor google/github searching. Apply what you learn and you'll get root in no time. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
3
1
73
I just pwned Voleur on @hackthebox_eu! Clean attack path with a satisfying flow. Nothing too complex, but a few steps might stall you without prior experience. Heed the creator's hints and you'll do fine. #HackTheBox #HTB #CyberSecurity #InfoSec #EthicalHacking #PenTesting
1
1
64
I just pwned RustyKey on @hackthebox_eu! This is a very tough AD box by @EmSec0. It has serious challenges and no hand holding. Prepare to enumerate your eyes out. The cleanups are a pain as usual. Overall I liked the ideas. #htb #CyberSecurity #EthicalHacking #InfoSec #PenTest
1
2
56
I just pwned Artificial on @hackthebox_eu! This is a nifty little box for which I had to pull out a trick/technique I learned from a mini prolab, just had to make it smaller, then smaller still. Privesc was easy. Good box. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
3
0
76
Just pwned Sorcery on @hackthebox_eu! This box is insanely complexānot just the attack chain, but the whole setup @tomadimitrie crafted. Couldnāt have done it solo. Donāt try aloneāteam up and bring the patience of a dozen saints. #HackTheBox #HTB #CyberSecurity #EthicalHacking
6
2
71
Excellent article from @Synacktiv detailing CVE-2025-33073. It's an easy peasy LPE on any server where SMB signing is not enforced. I have already replicated it and works a charm. If you still aren't enforcing SMB signing. what are you doing?! Harden your environment & patch!
Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn_ and @wil_fri3d.
1
94
394
Ranked #1 in Romania on @hackthebox_eu today. It takes consistency & perseverance. I hope more skilled Romanian hackers get activeāHTB is an amazing place to learn and practice. What are you waiting for?!.#HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
6
2
88
RT @YuG0rd: Many missed this on #BadSuccessor: itās also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dumpā¦.
0
148
0
I just pwned Puppy on @hackthebox! This was a fun Assumed Breach scenario. The box is well designed and satisfying to complete. I should've finished it quicker but I was enumerating in the wrong place. A š°hole of my own. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
4
4
53
During an engagement, I was pwd spraying with @dafthack's tool and later, after getting DA through other means, I realized that it didn't find an Expired Password for a Domain Admin. I made a PR. It now filters based on LDAP codes. Hope you like it.
0
8
60
I just pwned Eureka on @hackthebox_eu! Getting the user was fun, just some regular enumeration at first, reading some blog and docs, then a lot of fiddling with the payload to get the callback. Root privesc was too easy. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
2
2
80
I just pwned Scepter on @hackthebox_eu! This one was fun. Battled through it until I got user eventually but I got hard stuck on root privesc. Thanks to @seriotonctf I was able to push through and get it done. Much appreciated. #HackTheBox #htb #CyberSecurity #EthicalHacking
4
2
75
Finished 13th in Season 7 from @hackthebox_eu. This is a personal record for me in major part due to the root blood I got. Best season so far. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
8
3
83
I just pwned WhiteRabbit on @hackthebox_eu! I have to be honest, I didn't like this box. It wasn't because of the difficulty. There were just parts of it that weren't fun for me, design wise. But overall it was my best season so far. Great experience! #HackTheBox #HTB
7
1
93
I just pwned Haze on @hackthebox_eu! I thoroughly enjoyed this box. It takes good enumeration and lots of lateral movement. Keep your eye on the ball, don't stray to far from the path and you'll easily get there. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
2
2
90
Good news, a CVE ID was assigned and soon there will be something published about it. It's a nice little finding. It will be my first CVE and I'm happy it will make the internet and some companies a little safer šš.
Aaand this paved the way for me to get DA š. It's going to be a crazy report to write š
. They had a very solid network since I had to pull a 0day out of my ass and also learned a cool way to bypass RunAsPPL (lsass protection).
7
0
40
I just pwned Code on @hackthebox_eu! I was much slower this week. I'm a bit disappointed in myself but I guess my brain is a bit mush from CyberApocalypse. In any case, didn't like the foothold, not realistic. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
4
3
69
I just pwned TheFrizz on @hackthebox_eu ! In 4 years, this is the first time I'm getting #Blood on a machine. Feel good!!! This was a great machine that requires careful enumeration. For now this also puts me in 1st in the season leaderboard #HackTheBox #htb #CyberSecurity
19
5
167