HTB: SmartHire
Exploiting Python's pickle deserialization in MLflow and abusing a poorly configured site.addsitedir() for arbitrary code execution.
Medium Read ↗
I build things, explore various security domains, and share what I learn along the way. Have a look around.
Recent projects and challenge walkthroughs.
Exploiting Python's pickle deserialization in MLflow and abusing a poorly configured site.addsitedir() for arbitrary code execution.
Helix is a medium-level ICS-focused machine with Apache NiFi running as an external service and OPC UA as an internal service.
An easy-difficulty machine with an SSRF vulnerability that exposes internal services and is running an older version of PackageKit.