October 9, 2026
Cohort Machine Write-up (Easy Linux) — HTB Walkthrough
This machine focuses on chain-exploiting web vulnerability misconfigurations and local package security flaws. The primary objectives test…
By Ahmad-aduwa Da-oh
3 min read
This machine focuses on chain-exploiting web vulnerability misconfigurations and local package security flaws. The primary objectives test an assister's capability in identifying Server-Side Request Forgery (SSRF) to discover hidden internal services, conducting targeted service enumeration on non-standard ports, and performing manual local package auditing to identify known Privilege Escalation pathways (CVEs).
Reconnaissance
An initial service scan was conducted using Nmap. As a result, three open ports were identified on the target machine: 22, 80, and 443.
Each open port hosts specific services as detailed below:
- Port 22 (SSH): Secure Shell service, which allows remote administrative access. To gain entry via this port, credentials must first be obtained through enumeration or a brute-force attack.
- Ports 80 & 443 (HTTP/HTTPS): Web services hosted on the target. These endpoints were prioritized for further enumeration.
Enumeration
During the enumeration phase, a user input field was discovered within the source URL, indicating a potential Server-Side Request Forgery (SSRF) vulnerability.
An SSRF payload retrieved from the PayloadAllTheThings GitHub repository was executed, successfully confirming the presence of the vulnerability and exposing an internal IP address.
Subsequently, directory brute-forcing was performed using ffuf to enumerate URL paths, which returned an active status path.
Upon inspecting this path, an internal subdomain running on port 8888 was identified.
Let's inspect the web page content.
Further investigation of the web page via Burp Suite revealed that the service was running Marimo, an open-source reactive Python notebook.
Thereafter, additional enumeration was conducted on this newly discovered subdomain to locate the version endpoint.
This ultimately allowed the specific version of Marimo to be identified.
Exploitation
To begin the exploitation phase, research was conducted on Marimo version 0.20.4, yielding a publicly available exploit script on ExploitDB.
Executing this exploit script successfully granted an initial foothold on the target system.
Following this, the user flag was retrieved.
Privilege Escalation
Initially, linpeas.sh was transferred to the target host via an HTTP server and executed for automated privilege escalation checks.
However, after a thorough analysis yielded no immediate leads, manual package enumeration was performed using the following commands:
pkcon --version
dpkg-query -W -f='${Package} ${Version}\n' packagekit
dpkg -l packagekit
apt-mark showholdpkcon --version
dpkg-query -W -f='${Package} ${Version}\n' packagekit
dpkg -l packagekit
apt-mark showholdThis revealed that PackageKit version 1.2.8-2ubuntu1.2 was installed on the target machine.
Research confirmed that this specific version contains a known vulnerability with a public exploit script available. Consequently, the exploit was executed, successfully elevating privileges to the root user and allowing the retrieval of the root flag.