Laboratory - HackTheBox Writeup (10.10.10.216)

Posted on Sun, Apr 18, 2021 Easy Linux GitLab Docker PATH Hijacking
Easy-difficulty Linux box with a focus on exploiting local file inclusion and insecure deserialisation vulnerabilities in GitLab 12.8.1. Privilege escalation by escaping the Docker container and abusing a SUID binary with a PATH hijacking attack.

Recon

Enumeration

HTTP Enumeration

HTTPS Enumeration

Exploitation

Exploiting LFI in GitLab

Setting up our own GitLab instance

Privilege Escalation

Persistence

Resources

  1. https://hackerone.com/reports/827052
  2. https://www.hackingarticles.in/linux-privilege-escalation-using-path-variable/