// htb writeup HackTheBox 2026-05-24
DevArea
HackTheBox Medium HackTheBox
seasonal
root obtained // PWNED

🛠️ DevArea

Difficulty: Medium OS: Linux Release: HTB Season 10

A Linux developer box with a surprisingly long chain for Medium difficulty. Foothold requires you to reverse a JAR, find an ancient-but-working SOAP endpoint, and abuse a SSRF primitive that’s been around since 2022. Getting to root involves forging a Flask session cookie and chaining two hops through a deliberately restricted sudo command. Each step is gated by something you found in the previous one.


📸 Proof


🧠 Concepts Covered


💡 Hints (No Spoilers)

Foothold

User

Root


📚 Useful Reading