Today, we will be continuing with our exploration of Hack the Box (HTB) machines, as seen in previous articles. An authenticated area is found with the chance to register an user but an activation code is needed.


BroScience is a Medium Difficulty Linux machine that features a web application vulnerable to `LFI`.
The centerpiece is a crazy cross-site scripting attack through a password reset interface using DNS to redirect the admin to a site I control to then have them register an account for me.

It is a medium-difficulty challenge focusing on web-related vulnerabilities, source code review, and custom Maksim Chudakov on LinkedIn: HackTheBox - BroScience Walkthrough.

After that, we find a hashed password in the database that can be cracked and it is reused in the system.

