LazyTitan33 Profile Banner
LazyTitan Profile
LazyTitan

@LazyTitan33

Followers
2K
Following
2K
Media
278
Statuses
1K

Pentester | eWPTXv2 | eCPTXv2 | eCPPTv2 | eWPT | CNPen | eJPT CVE-2025-22458: https://t.co/qX6CTzNepe

Joined February 2012
Don't wanna be here? Send us removal request.
@LazyTitan33
LazyTitan
3 months
šŸŽŠI got my first CVE in your favorite security product: CVE-2025-22458 – LPE with built-in persistence in Ivanti Endpoint Manager. Patch available – update ASAP ā—ļø.Full advisory: .#CyberSecurity #CVE2025 #Ivanti #EPM #ExploitDev #DLLHijacking.
sec-consult.com
@sec_consult
SEC Consult
3 months
āš ļø We discovered CVE-2025-22458 – a privilege escalation vuln in Ivanti Endpoint Manager. A SYSTEM task loads DLLs from user-writable paths, enabling local escalation & persistence. Patch available! .Full advisory: .@LazyTitan33 #CVE2025 #Ivanti #EPM.
5
3
47
@LazyTitan33
LazyTitan
4 days
I just pwned Mirage on @hackthebox_eu! I enjoyed the path up to a point, but there comes a step which is very hard to enumerate or figure out. Without some help, it is very nearly a guess, a shot in the dark. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
Tweet media one
2
4
49
@LazyTitan33
LazyTitan
12 days
I just pwned Outbound on @hackthebox_eu! This was a fun box. It only requires a bit of attention to detail and some minor google/github searching. Apply what you learn and you'll get root in no time. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
Tweet media one
3
1
73
@LazyTitan33
LazyTitan
19 days
I just pwned Voleur on @hackthebox_eu! Clean attack path with a satisfying flow. Nothing too complex, but a few steps might stall you without prior experience. Heed the creator's hints and you'll do fine. #HackTheBox #HTB #CyberSecurity #InfoSec #EthicalHacking #PenTesting
Tweet media one
1
1
64
@LazyTitan33
LazyTitan
24 days
I just pwned RustyKey on @hackthebox_eu! This is a very tough AD box by @EmSec0. It has serious challenges and no hand holding. Prepare to enumerate your eyes out. The cleanups are a pain as usual. Overall I liked the ideas. #htb #CyberSecurity #EthicalHacking #InfoSec #PenTest
Tweet media one
1
2
56
@LazyTitan33
LazyTitan
1 month
I just pwned Artificial on @hackthebox_eu! This is a nifty little box for which I had to pull out a trick/technique I learned from a mini prolab, just had to make it smaller, then smaller still. Privesc was easy. Good box. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
Tweet media one
3
0
76
@LazyTitan33
LazyTitan
1 month
Just pwned Sorcery on @hackthebox_eu! This box is insanely complex—not just the attack chain, but the whole setup @tomadimitrie crafted. Couldn’t have done it solo. Don’t try alone—team up and bring the patience of a dozen saints. #HackTheBox #HTB #CyberSecurity #EthicalHacking
Tweet media one
6
2
71
@LazyTitan33
LazyTitan
1 month
Excellent article from @Synacktiv detailing CVE-2025-33073. It's an easy peasy LPE on any server where SMB signing is not enforced. I have already replicated it and works a charm. If you still aren't enforcing SMB signing. what are you doing?! Harden your environment & patch!
Tweet media one
@Synacktiv
Synacktiv
1 month
Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn_ and @wil_fri3d.
1
94
394
@LazyTitan33
LazyTitan
2 months
Ranked #1 in Romania on @hackthebox_eu today. It takes consistency & perseverance. I hope more skilled Romanian hackers get active—HTB is an amazing place to learn and practice. What are you waiting for?!.#HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
Tweet media one
6
2
88
@LazyTitan33
LazyTitan
2 months
RT @YuG0rd: Many missed this on #BadSuccessor: it’s also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dump….
0
148
0
@LazyTitan33
LazyTitan
2 months
I just pwned Puppy on @hackthebox! This was a fun Assumed Breach scenario. The box is well designed and satisfying to complete. I should've finished it quicker but I was enumerating in the wrong place. A 🐰hole of my own. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
Tweet media one
4
4
53
@LazyTitan33
LazyTitan
3 months
During an engagement, I was pwd spraying with @dafthack's tool and later, after getting DA through other means, I realized that it didn't find an Expired Password for a Domain Admin. I made a PR. It now filters based on LDAP codes. Hope you like it.
Tweet media one
0
8
60
@LazyTitan33
LazyTitan
3 months
I just pwned Eureka on @hackthebox_eu! Getting the user was fun, just some regular enumeration at first, reading some blog and docs, then a lot of fiddling with the payload to get the callback. Root privesc was too easy. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
Tweet media one
2
2
80
@LazyTitan33
LazyTitan
3 months
I just pwned Scepter on @hackthebox_eu! This one was fun. Battled through it until I got user eventually but I got hard stuck on root privesc. Thanks to @seriotonctf I was able to push through and get it done. Much appreciated. #HackTheBox #htb #CyberSecurity #EthicalHacking
Tweet media one
4
2
75
@LazyTitan33
LazyTitan
3 months
Finished 13th in Season 7 from @hackthebox_eu. This is a personal record for me in major part due to the root blood I got. Best season so far. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
Tweet media one
8
3
83
@LazyTitan33
LazyTitan
4 months
I just pwned WhiteRabbit on @hackthebox_eu! I have to be honest, I didn't like this box. It wasn't because of the difficulty. There were just parts of it that weren't fun for me, design wise. But overall it was my best season so far. Great experience! #HackTheBox #HTB
Tweet media one
7
1
93
@LazyTitan33
LazyTitan
4 months
I just pwned Haze on @hackthebox_eu! I thoroughly enjoyed this box. It takes good enumeration and lots of lateral movement. Keep your eye on the ball, don't stray to far from the path and you'll easily get there. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec
Tweet media one
2
2
90
@LazyTitan33
LazyTitan
4 months
Good news, a CVE ID was assigned and soon there will be something published about it. It's a nice little finding. It will be my first CVE and I'm happy it will make the internet and some companies a little safer šŸ˜šŸŽ‰.
@LazyTitan33
LazyTitan
5 months
Aaand this paved the way for me to get DA šŸŽ‰. It's going to be a crazy report to write šŸ˜…. They had a very solid network since I had to pull a 0day out of my ass and also learned a cool way to bypass RunAsPPL (lsass protection).
7
0
40
@LazyTitan33
LazyTitan
4 months
I just pwned Code on @hackthebox_eu! I was much slower this week. I'm a bit disappointed in myself but I guess my brain is a bit mush from CyberApocalypse. In any case, didn't like the foothold, not realistic. #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting
Tweet media one
4
3
69
@LazyTitan33
LazyTitan
4 months
I just pwned TheFrizz on @hackthebox_eu ! In 4 years, this is the first time I'm getting #Blood on a machine. Feel good!!! This was a great machine that requires careful enumeration. For now this also puts me in 1st in the season leaderboard #HackTheBox #htb #CyberSecurity
Tweet media one
Tweet media two
19
5
167