HackTheBox SmartHire
September 26, 2026
Description
00:00 - Introduction 00:50 - Start of nmap 03:55 - We can enumerate valid usernames based upon time 07:00 - Enumerating subdomains with ffuf finding models.smarthire.htb 10:00 - Discovering MLFlow has Python Pickles 13:00 - Sidequest, the copy to clipboard doesn't work over http weakening our browser to allow clipboard access from HTTP 17:40 - Uploading a Python Pickle, showing that the --data-binary flag is important 25:40 - Got a HTTP Callback, getting a reverse shell 27:16 - Shell returned 29:50 - We can write to a plugins directory of a program we can run via sudo, begin of research to exploit 37:50 - Turns out for PTH files we need to put everything on one line. Getting root
Trust cues for videos
Internal ReadExternal SourceQubicweb AnalysisCommunity signalMixedSource-only