// htb writeup 2026-02-25
Cobblestone
HackTheBox Insane
Linux Web Exploitation XML-RPC Abuse
root obtained // PWNED

🏰 Cobblestone (HTB)

Status: 🔒 Private – writeup will be published once the machine retires
Difficulty: Insane
Category: Linux | Web Exploitation | XML-RPC Abuse
Date Completed: 2025-08-10


🧠 Teaser

What happens when a seemingly harmless game skin site hides an enterprise deployment tool behind closed doors?
Let’s just say… we found the keys to the castle – and the drawbridge was operated via XML-RPC.

From cracking questionable password choices to tunneling into forgotten services, this box rewards patient enumeration and a willingness to poke at dusty sysadmin tools.


🪛 Tools You’ll Want:


✅ You’ll Need to:


📸 Proof
cobblestone.png