<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>DevHub on H4CK R007</title>
    <link>https://h4ckr00t.com/tags/devhub/</link>
    <description>Recent content in DevHub on H4CK R007</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 04 Jun 2026 22:20:04 +0300</lastBuildDate>
    <atom:link href="https://h4ckr00t.com/tags/devhub/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>HackTheBox Season 11 Writeup - DevHub</title>
      <link>https://h4ckr00t.com/posts/devhub/</link>
      <pubDate>Thu, 04 Jun 2026 22:20:04 +0300</pubDate>
      <guid>https://h4ckr00t.com/posts/devhub/</guid>
      <description>HackTheBox Season 11 — DevHub (Medium / Linux) Machine Overview DevHub is a Medium-difficulty Linux machine on HackTheBox Season 11. It presents a internal developer platform running three services: a public-facing nginx web dashboard, an externally accessible MCPJam Inspector on a non-standard port, and two internal-only services (Jupyter Lab and a custom Flask API called OPSMCP) that are not directly reachable from the network.&#xA;Table of Contents Machine Overview Reconnaissance Enumeration Vulnerability Discovery Initial Foothold — stdio RCE via MCPJam Inspector Post-Exploitation — Establishing Persistence Local Enumeration — Token Leak via Process List Lateral Movement — Jupyter WebSocket Code Execution as Analyst Privilege Escalation — OPSMCP Hidden Tool → Root SSH Key Flags Full Attack Chain Key Takeaways The attack chain is entirely modern and novel, built around the Model Context Protocol (MCP) — an open standard for connecting AI agents to external tools.</description>
    </item>
  </channel>
</rss>
