<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>HackTheBox - FormulaX</title>
        <link>https://stream.echo6.co/videos/watch/b5c9c3c0-819a-4f9d-bbd2-a613b1e1c2e9</link>
        <description>00:00 - Introduction 01:00 - Start of nmap 04:30 - Examining the Change Password functionality 06:20 - Discovering XSS In the Contact Form 11:15 - Building an XSS Cradle that manipulates the DOM to load an external JS file 18:35 - Creating an XSS that will send interact with the webchat and exfil messages back to us 26:30 - Discovering a new subdomain from the Online Chat 30:15 - Showing why we could not use Script SRC with our XSS Attack and why we used the DOM Technique 37:34 - Looking at the Git Auto Report Generating and discovering it uses simple-git v3.14 which has an RCE Vulnerability 44:40 - Shell on the box, dumping the mongo database 52:00 - Shell as Frank_Dorky 52:30 - Looking at the services running on the box to enumerate what each port is 55:30 - Showing bad permissions on the LibreNMS Directory which allows us to read and execute files in /opt/librenms 59:30 - Using the Templates in LibreNMS to get code execution 01:04:00 - Showing the intended way to exploit LibreNMS which is using a malicious SNMP Trap to attack an admin via XSS 1:17:30 - Exploiting the OpenOffice network port</description>
        <lastBuildDate>Wed, 15 Apr 2026 13:57:29 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>PeerTube - https://stream.echo6.co</generator>
        <image>
            <title>HackTheBox - FormulaX</title>
            <url>https://stream.echo6.co/client/assets/images/icons/icon-512x512.png</url>
            <link>https://stream.echo6.co/videos/watch/b5c9c3c0-819a-4f9d-bbd2-a613b1e1c2e9</link>
        </image>
        <copyright>All rights reserved, unless otherwise specified in the terms specified at https://stream.echo6.co/about and potential licenses granted by each content's rightholder.</copyright>
        <atom:link href="https://stream.echo6.co/feeds/video-comments.xml?videoId=b5c9c3c0-819a-4f9d-bbd2-a613b1e1c2e9" rel="self" type="application/rss+xml"/>
    </channel>
</rss>