
Andrea Pierini
@decoder_it
Followers
8K
Following
1K
Media
236
Statuses
2K
Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"
Joined May 2009
When (NTLM) relaying potatoes lead you to domain admin. A "permanent" 0day Privilege Escalation Vulnerability in Windows RPC Protocol ;-). cc @splinter_code .Our writeup here:.
7
367
684
Regarding #CVE-2025-33073 fixing NTLM/Kerberos reflection attacks via SMB: the patch only covers SMB clients. The "CredMarshal" trick still works on RPC and HTTP. But those protocols sets the unverified target flags, which block exploitation. So, is reflection dead? Let’s see….
2
19
69
RT @ericonidentity: At @WEareTROOPERS I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable….
0
37
0
Looks like the patch for #CVE-2025-33073 might not fully resolve the issue. curious to see where this leads
2
13
82
Setting dsHeuristics flag 28 (AttributeAuthorizationOnLDAPAdd) to 1 (00000000010000000002000000010) blocks #BadSuccessor if the attacker has “Create All Children” rights. But with Full Control or WriteDACL on descendant objects, the attack still works.🤦♂️.
1
7
21
RT @LinuxHandbook: No disrespect to Linus Torvalds, but this guy is the greatest geek alive 🫡. Created UNIX in 1971 when he was 28 years ol….
0
2K
0
RT @offsectraining: Attention @kalilinux users! In the coming day(s), apt update is going to fail for pretty much everyone. The reason? W….
0
434
0
Call for Papers for #Romhack2025 is still open! If you have cool research to share, don’t hesitate to submit. The perfect setting for great talks, great company, and a chance to visit the "Città Eterna".
0
0
6
RT @_EthicalChaos_: I spoke about the initial credential guard vulnerability at #SOCON2025, but I left out the part where the fix could be….
0
32
0
RT @elad_shamir: NTLM relay is still a major threat and is now even easier to abuse. We just added new NTLM relay edges to BloodHound to he….
0
111
0
Hey, we should really switch from NTLM to something like Kerberos, yet another good reason, right? cc @ShitSecure @splinter_code . 😂🤣
5
36
186
RT @cybersaiyanIT: We know, we know, we understand that #Azure Entra ID can be quite complex. Buttttt, we assure you that Dirk-jan Molle….
0
3
0
RT @cybersaiyanIT: 🔥 HUGE #RomHack2025 updates you need to know this week. James @albinowax Kettle, one of the world’s leading figures in….
0
7
0