Whats Your Name?

Intro

A reconnaissance of active ports was initiated, identifying the following ports: 22, 80, and 8081.
Ports 80 and 8081 have web services running, while port 8081 displays only a blank page.
Port 80 hosts a website that allows user registration, but its registration fields are vulnerable to XSS (cross-site scripting). Through this attack vector, it is possible to obtain the moderator’s session cookies.
The moderator’s panel has a subdomain with social network management functions. The system administrator can be contacted via a chatbot, which is also vulnerable to XSS attacks. Through this vulnerability, a form was crafted that does not require user interaction, allowing the administrator’s password to be changed and thereby granting administrative access.