We need you. Things have been crazy with all the leaks lately. Apparently somebody gave one of our clients a tip that Julian Assange has acquired some devastating data about the US government. Our client has asked us to get this data for them. They're saying they can sell this data and makes lots of money of off it or something. Doesn't matter, they're paying us as long as we can get the data for them. The only tip we have is that Julian has been using this new security and privacy focused messaging app called Cachet to communicate with the source of the leaked data. He's supposedly taken a liking to it and uses it pretty frequently. Our interns looked at it but haven't had any luck, so we need your expertise on this one.
Get XSS on user julianassange via the enc-msg POST param when sending him a message. Use this XSS to get his private key and passphrase (julianassange reads all messages sent to him). Then use this XSS to read the read.php for julianassange,