A detailed walkthrough of the HackTheBox machine 'Giveback', covering exploitation of CVE-2024-5932, an unauthenticated PHP object injection to RCE vulnerability in the GiveWP WordPress plugin. After gaining a shell in a Kubernetes pod, the attacker enumerates the cluster environment, discovers a legacy internal PHP-CGI application, pivots to another pod by exploiting a PHP-CGI vulnerability, extracts Kubernetes secrets via the API, and ultimately escalates to root on the host by abusing a custom runc wrapper.
Table of contents
Box InfoReconShell in WordPress K8 PodShell as root on legacy-internet-cms PodShell as babywyrmShell as root447 Impressions