active Retires: October 15, 2026
Medium
HTB MakeSense Complete Writeup - Client-Side Crypto, Stored XSS & Root PHP Dev Server
A comprehensive penetration testing guide exploiting a hardcoded client-side encryption key in a WordPress custom theme, forging encrypted payloads for stored XSS to achieve admin access, escalating to PHP code execution via malicious plugin upload, and ultimately abusing a root-owned OCR web application to reach root.
Comments