Pentesting Lab Exercises Series - Vulnhub
Virtual Machine Name: My CMSMS: 1
Link: https://www.vulnhub.com/entry/my-cmsm...
Tips:
1. Failed to exploit MySQL UDF:
https://juggernaut-sec.com/mysql-user...
2. Failed to crack admin's password.
3. To update admin's password, comprehensive source code auditing is necessary. Here source code auditing was aiming at finding out logic of generating password. I don't think we need thorough auditing.