All writeupsField notes / Hack The Box

HTB WingData

The investigation

WingData (Easy Linux). CVE Chain: CVE-2025-47812 → Hash extraction → SSH → CVE-2025-4517. Recon: open ports 22, 80, wingdata.htb redirects to ftp.wingdata.

WingData (Easy Linux)

CVE Chain: CVE-2025-47812 → Hash extraction → SSH → CVE-2025-4517

Recon

Open ports: 22, 80. wingdata.htb redirects to ftp.wingdata.htb — Wing FTP Server 7.4.3. Add both to /etc/hosts.

CVE-2025-47812 — Wing FTP Unauthenticated RCE via Lua Injection

Wing FTP stores sessions as executable Lua scripts. A null byte in the username breaks out of the Lua string, allowing arbitrary code injection:

Commands are included in the full writeup.Unlock
Commands are included in the full writeup.Unlock

Hash Extraction

Wing FTP uses SHA256(pass.pass.pass.salt) with SaltingString=WingFTP:

Commands are included in the full writeup.Unlock
Commands are included in the full writeup.Unlock

Tip: Special characters (>, |, ') break the Lua injection. Use grep instead of cat for file reading. For reverse shells, wget from attacker HTTP server since direct callbacks are filtered.

SSH & Privilege Escalation

Commands are included in the full writeup.Unlock

Same CVE-2025-4517 tarfile exploit as Facts. Root obtained.

User Flag: /home/wacky/user.txt Root Flag: /root/root.txt

Continue the investigation

The complete field notes.

Every command, the full exploitation chain, and all scripts used in this investigation are available to members on Buy Me a Coffee.

Get the full writeup €5 one-off · or monthly membership
End of field noteBack to the archive