HTB: SmartHire
Exploiting Python's pickle deserialization in MLflow and abusing a poorly configured site.addsitedir() for arbitrary code execution.
Documented guides on challenges, user access, and privilege escalation.
Exploiting Python's pickle deserialization in MLflow and abusing a poorly configured site.addsitedir() for arbitrary code execution.
Helix is a medium-level ICS-focused machine with Apache NiFi running as an external service and OPC UA as an internal service.
An easy-difficulty machine with an SSRF vulnerability that exposes internal services and is running an older version of PackageKit.
A very simple machine with vulnerable versions of Craft CMS and Telnet.
Exploiting CVE-2025-57819 in the FreePBX system, and abusing incron.d and dahdi.conf for privilege escalation.
Easy machine running Flowise AI. It's vulnerable to CVE-2025-58434, which leaks user credentials, and CVE-2025-59528, which enables RCE through the CustomMCP node.