HTB: Valentine
Summary Valentine is an easy Linux box that can be exploited by enumerating the HTTP(S)-service properly and identifying that the host is vulnerable to heartbleed. By exploiting heartbleed you can gain a Base64-encoded password that can be used in combination with a private key file to gain an initial foothold on Valentine. The PrivEsc is done by exploiting Tmux running as root. Discovery Nmap discovered the following open ports and services:...