HackTheBox - DevHub
Description
00:00 - Introduction 00:36 - Start of nmap 01:22 - Looking at the website on port 80, which advertises MCP Inspector on port 6274. Confirming the port is open with netcat since nmap only scanned the top 1000 02:25 - Looking at port 6274, finding MCPJam 1.4.2 which has an easy RCE (CVE-2026-23744), the same exploit covered on the Kobold video 03:21 - Grabbing the PoC off GitHub and editing it to target devhub.htb:6274 with our IP/port 04:17 - Talking about the different netcat versions and the -e flag, swapping in a bash reverse shell, then getting a shell as mcp-dev and upgrading the TTY 06:31 - Dropping an ed25519 key to SSH in as mcp-dev, then ps -ef --forest to review processes: analyst running JupyterLab (token on the command line) and root running the opsmcp server 09:02 - Using ss -lntp to find the two local services (8888 and 5000) and fingerprinting them by the Server header (TornadoServer is Jupyter, Werkzeug is the Flask app) 10:54 - Forwarding port 8888 over SSH, logging into Jupyter with the leaked token, and using Launcher/Terminal to get a shell as analyst (then dropping an SSH key) 13:31 - As analyst, examining the root-owned opsmcp Flask app (/opt/opsmcp/server.py) and using touch /dev/shm/pwned to detect if/when it restarts 15:12 - Reading the source for the hard-coded API key, authenticating to opsmcp with the X-API-Key header, and working out the tools/call request for ops._admin_dump 19:00 - Dumping root's SSH private key with ops._admin_dump (target ssh_keys) and logging in as root
Trust cues for videos