HTB WingData
WingData (Easy Linux). CVE Chain: CVE-2025-47812 → Hash extraction → SSH → CVE-2025-4517. Recon: open ports 22, 80, wingdata.htb redirects to ftp.wingdata.
WingData (Easy Linux)
CVE Chain: CVE-2025-47812 → Hash extraction → SSH → CVE-2025-4517
Recon
Open ports: 22, 80. wingdata.htb redirects to ftp.wingdata.htb — Wing FTP Server 7.4.3. Add both to /etc/hosts.
CVE-2025-47812 — Wing FTP Unauthenticated RCE via Lua Injection
Wing FTP stores sessions as executable Lua scripts. A null byte in the username breaks out of the Lua string, allowing arbitrary code injection:
Hash Extraction
Wing FTP uses SHA256(pass.pass.pass.salt) with SaltingString=WingFTP:
Tip: Special characters (>, |, ') break the Lua injection. Use grep instead of cat for file reading. For reverse shells, wget from attacker HTTP server since direct callbacks are filtered.
SSH & Privilege Escalation
Same CVE-2025-4517 tarfile exploit as Facts. Root obtained.
User Flag: /home/wacky/user.txt
Root Flag: /root/root.txt
Continue the investigation
The complete field notes.
Every command, the full exploitation chain, and all scripts used in this investigation are available to members on Buy Me a Coffee.
Get the full writeup €5 one-off · or monthly membership