$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: HackTheBox machine with MCP Inspector, PrivateBin, and Arcane Docker Management. Solution: SSRF/RCE via MCP protocol, PHP injection into PrivateBin data files to leak config, password reuse to Arcane API, Docker container mount for root flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar