HeartBleed — TryHackMe

A vulnerable nginx server exposes OpenSSL’s Heartbleed bug (CVE-2014-0160), allowing unauthenticated heap memory disclosure that leaks a plaintext HTTP POST body — and the flag — straight out of an active SSL session.

June 8, 2026 · 16 min · 3262 words · Th3B0yWh0L1v3d

Heart Part 7 — DalCTF 2026

A Kendrick-themed Flask app chains UNION-based SQLi to leak admin creds, an admin panel exposes an internal cipher microservice, and a Heartbleed-style over-read bleeds the AES-256 master key from heap memory to decrypt the flag.

June 6, 2026 · 7 min · 1325 words · Th3B0yWh0L1v3d