~/mbt
back to writeups
Full writeup loaded from GitHub repository.
hack the-boxmediumLinux retired

SmartHire

SmartHire - hack the-box active machine walkthrough.

Approach

01

MLflow Default Credentials

02

CVE-2024-37054 -- pickle deserialization RCE via malicious PyFunc model

03

Sudo Privilege Escalation -- Exploited writable MLflow plugins and .pth file execution as root.

04

SUID Bash -- Created a root-owned SUID Bash binary and obtained root access.

Full Writeup

Loading writeup from GitHub...