http://mail.nowherejezfoltodf4jiyl6r56jnzintap5vyjlia7fkirfsnfizflqd.onion/HTB/Medium/6.html
Nmap done: 1 IP address (1 host up) scanned in 11.10 seconds Part 2 : Getting User Access Our nmap scan picked up port 80 running apache 2.4.7, so investigating it we are greeted with a webservice allowing us to register an account, so heading over there,
we register an account and intercept our request with burpsuite : Here we can change the cookie before sending it, which gets us an invalid padding error.