Discussion — Any questions? Ask and discuss freely in the community.
Hack The Box active 203 views

HTB Devhub Writeup

Hack The Box Devhub overview: MCPJam RCE, internal service discovery, SSH key extraction via a hidden API and an OPSMCP admin tool. Steps after retirement.

Devhub
Medium active Hack The Box
Devhub completion
Protected while the machine is active

Due to Hack The Box policies this walkthrough is not publicly served until Devhub retires. See the official HTB writeup guidelines.

Machine profile

Platform
Hack The Box
Machine
Devhub
Difficulty
Medium
Published
Status
active

Devhub is a medium-difficulty Linux machine from Hack The Box themed around developer tooling, and its distinguishing feature is that part of the attack surface is a Model Context Protocol server — a newer class of target that is appearing more often as teams wire models into internal systems.

The skill areas are modern web application exploitation, internal service discovery, credential and key material recovery, and Linux privilege escalation through administrative tooling. The underlying lesson is about trust boundaries: an internal-only service still becomes an execution primitive once you have a foothold, and the tokens and keys that tooling holds are usually the real prize.

It suits readers comfortable with Linux internals who want to see protocol-level services treated as an ordinary attack surface — fingerprint it, understand how it handles requests, and then treat what it stores as the objective. It pairs well with the web-focused machines on this site and is a good companion for anyone working with MCP-style deployments.

What this machine covers

Vulnerabilities

Software, services & tooling

MCPJam Jupyter Notebook chisel Port Forwarding Rustscan Nmap

Techniques & attack classes

RCE SSRF Jupyter Privilege Escalation SSH Key Extraction Internal Service Enumeration Linux Privilege Escalation

What the finished writeup contains

When Devhub retires, the complete walkthrough publishes here unchanged — every command, output and screenshot from the actual box, in the order it was solved.

  1. Reconnaissance Port scanning, service fingerprinting and attack-surface mapping
  2. Initial foothold The first authenticated or unauthenticated execution path
  3. Enumeration Deeper inspection of the exposed services and their configuration
  4. Exploitation Chaining the weaknesses found into a working exploit
  5. Credential recovery Secrets, keys and hashes, and how they were obtained
  6. Privilege escalation The route from the foothold account to a root shell
  7. Flags User and root flag capture

203 views on this machine so far — demand is tracked, and the walkthrough publishes the moment the box retires.

Why is this walkthrough protected right now?

No active-machine solution, flag, credential, exploit chain or private asset appears on this public page. Only the machine's profile, the topics it covers and a description of what the finished writeup will contain are published while the box is live.

Topics: MCPJam, CVE-2026-23744, RCE, SSRF, Jupyter Notebook, Jupyter Privilege Escalation, SSH Key Extraction, Internal Service Enumeration, chisel Port Forwarding, Linux Privilege Escalation, Rustscan, Nmap

Comments