HTB Cohort Writeup
Hack The Box Cohort machine overview: an SSRF localhost filter bypass, pre-auth Marimo WebSocket RCE and PackageKit TOCTOU privesc. Full steps after retirement.
Due to Hack The Box policies this walkthrough is not publicly served until Cohort retires. See the official HTB writeup guidelines.
Machine profile
- Platform
- Hack The Box
- Machine
- Cohort
- Difficulty
- Easy
- Published
- Status
- active
Cohort is an easy-difficulty Linux machine from Hack The Box that moves from a web application weakness to a local privilege escalation, and it is one of the shortest complete chains on this site.
The skill areas are server-side request forgery and filter bypass, interactive development services exposed to the network, and Linux privilege escalation through the desktop package manager. Two ideas carry most of the weight: that a blocklist which only matches one literal string is not a security control, and that modern package managers are a privileged process worth understanding.
Cohort suits readers who want to practise filter bypass, network-exposed development tooling, and contemporary Linux escalation in a compact and readable machine. It is short enough to complete in one sitting, and structured so that each stage only becomes possible once the previous one is understood.
What this machine covers
Vulnerabilities
Software, services & tooling
Techniques & attack classes
What the finished writeup contains
When Cohort retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.
- Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
- Initial foothold The first authenticated or unauthenticated execution path
- Enumeration Deeper inspection of the exposed services and their configuration
- Exploitation Chaining the weaknesses found into a working exploit
- Credential recovery Secrets, keys and hashes, and how they were obtained
- Privilege escalation The route from the foothold account to a root shell
- Flags User and root flag capture
291 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.
Why is this walkthrough protected right now?
No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.
Topics: SSRF, SSRF Localhost Filter Bypass, Marimo, Marimo WebSocket RCE, CVE-2026-39987, Pre-Auth RCE, Python, PackageKit, CVE-2026-41651, TOCTOU Race Condition, Linux Privilege Escalation, Rustscan, Nmap
Comments
No comments yet — be the first to share your thoughts.