Discussion — Any questions? Ask and discuss freely in the community.
Hack The Box active 291 views

HTB Cohort Writeup

Hack The Box Cohort machine overview: an SSRF localhost filter bypass, pre-auth Marimo WebSocket RCE and PackageKit TOCTOU privesc. Full steps after retirement.

Cohort
Easy active Hack The Box
Cohort completion
Protected while the machine is active

Due to Hack The Box policies this walkthrough is not publicly served until Cohort retires. See the official HTB writeup guidelines.

Machine profile

Platform
Hack The Box
Machine
Cohort
Difficulty
Easy
Published
Status
active

Cohort is an easy-difficulty Linux machine from Hack The Box that moves from a web application weakness to a local privilege escalation, and it is one of the shortest complete chains on this site.

The skill areas are server-side request forgery and filter bypass, interactive development services exposed to the network, and Linux privilege escalation through the desktop package manager. Two ideas carry most of the weight: that a blocklist which only matches one literal string is not a security control, and that modern package managers are a privileged process worth understanding.

Cohort suits readers who want to practise filter bypass, network-exposed development tooling, and contemporary Linux escalation in a compact and readable machine. It is short enough to complete in one sitting, and structured so that each stage only becomes possible once the previous one is understood.

What this machine covers

Vulnerabilities

Software, services & tooling

Marimo Python PackageKit Rustscan Nmap

Techniques & attack classes

SSRF SSRF Localhost Filter Bypass Marimo WebSocket RCE Pre-Auth RCE TOCTOU Race Condition Linux Privilege Escalation

What the finished writeup contains

When Cohort retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.

  1. Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
  2. Initial foothold The first authenticated or unauthenticated execution path
  3. Enumeration Deeper inspection of the exposed services and their configuration
  4. Exploitation Chaining the weaknesses found into a working exploit
  5. Credential recovery Secrets, keys and hashes, and how they were obtained
  6. Privilege escalation The route from the foothold account to a root shell
  7. Flags User and root flag capture

291 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.

Why is this walkthrough protected right now?

No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.

Topics: SSRF, SSRF Localhost Filter Bypass, Marimo, Marimo WebSocket RCE, CVE-2026-39987, Pre-Auth RCE, Python, PackageKit, CVE-2026-41651, TOCTOU Race Condition, Linux Privilege Escalation, Rustscan, Nmap

Comments