MySQL 5.5.23, vulnerable to CVE-2012-2122: the result of memcmp in the password check is cast to a char, so with some builds a wrong password is accepted about once in 256 tries; repeating the login gets root.
Pas commencéDockercommit d553596x86_64 · aarch64Secret
Exploit CVE-2012-2122 to log in to MySQL as root without the password and read the flag.
Le brief de ce lab se trouve dans son dépôt.