~ / writeups / cohort

Cohort

Hack The Box · Easy · Linux

Easy Linux User + Root owned

Machine Overview

Field Value
Name Cohort
Difficulty Easy
OS Linux (Ubuntu, nginx 1.24.0)
IP 10.129.146.191
Vhosts cohort.htb (portal), nb-1be3782a8afd3ad5.cohort.htb (internal Marimo)
Key components Flask "cohort-insights" API (127.0.0.1:5000), Marimo 0.20.4 (127.0.0.1:8888), PackageKit 1.2.8
Open ports 22 (SSH OpenSSH 9.6p1), 80/443 (nginx; *.cohort.htb wildcard cert)

Flags

Flag Path Value
User /home/marimo/user.txt [REDACTED]
Root /root/root.txt [REDACTED]

Attack Chain

1. Reconnaissance

2. SSRF via URL-validation feature

3. Marimo enumeration

4. Initial Access — CVE-2026-39987 (Marimo pre-auth WebSocket RCE)

5. User Flag

6. Privilege Escalation — CVE-2026-41651 (PackageKit "Pack2TheRoot" TOCTOU)

Techniques Demonstrated

  1. Directory/content enumeration → hidden portal
  2. SSRF with loopback-blocklist bypass (decimal/hex/short IP representations)
  3. Internal nginx status endpoint disclosure (upstream map → internal vhost)
  4. Reverse-proxy vhost pivoting (reaching a loopback-bound service over its vhost name)
  5. Pre-auth WebSocket RCE (CVE-2026-39987, Marimo /terminal/ws)
  6. PackageKit TOCTOU race → SUID binary (CVE-2026-41651, Pack2TheRoot)

Tools Used

nmap, curl, Python 3 (requests/websocket-client), cve-2026-39987 terminal WebSocket PoC, CVE-2026-41651-Python (Pack2TheRoot) PoC.

← all writeups