🐱
HTB MakeSense Complete Writeup - Client-Side Crypto, Stored XSS & Root PHP Dev Server
active Retires: October 15, 2026
Medium

HTB MakeSense Complete Writeup - Client-Side Crypto, Stored XSS & Root PHP Dev Server

A comprehensive penetration testing guide exploiting a hardcoded client-side encryption key in a WordPress custom theme, forging encrypted payloads for stored XSS to achieve admin access, escalating to PHP code execution via malicious plugin upload, and ultimately abusing a root-owned OCR web application to reach root.

🔒 Content Locked

This writeup is password-protected to comply with HTB rules.

📧 Need access? Enter the password.

Comments