A vulnerable .NET Windows thick client (an expense tracker) with its SQL Server Express and FTP back end on a Windows Server 2019 machine, built from real-world thick client pentest findings: insecure local storage and logging, weak cryptography, exposed decryption logic, SQL and CSV injection, DLL hijacking, clear-text traffic and client-side controls bypassed by reversing.
Pas commencéVMcommit 140e845x86_64Secret
Enable the client's Configure button, then exploit the thick client's flaws to log in as admin.
Le brief de ce lab se trouve dans son dépôt.