🐱
HTB MakeSense Complete Writeup - Client-Side Crypto, Stored XSS & Root PHP Dev Server
active Retires on: October 15, 2026
Medium

HTB MakeSense Complete Writeup - Client-Side Crypto, Stored XSS & Root PHP Dev Server

A comprehensive penetration testing guide exploiting a hardcoded client-side encryption key in a WordPress custom theme, forging encrypted payloads for stored XSS to achieve admin access, escalating to PHP code execution via malicious plugin upload, and ultimately abusing a root-owned OCR web application to reach root.

Table of Contents
Unlock this write-up to reveal its sections.

Comments