active Retires on: October 15, 2026
Medium
HTB MakeSense Complete Writeup - Client-Side Crypto, Stored XSS & Root PHP Dev Server
A comprehensive penetration testing guide exploiting a hardcoded client-side encryption key in a WordPress custom theme, forging encrypted payloads for stored XSS to achieve admin access, escalating to PHP code execution via malicious plugin upload, and ultimately abusing a root-owned OCR web application to reach root.
Table of Contents
Unlock this write-up to reveal its sections.
Content Locked
Have the password? Enter it above to read this write-up.
Comments