| Field | Detail |
|---|---|
| Name | WingData |
| OS | Linux (Debian) |
| Difficulty | Easy |
| Target | wingdata.htb (subdomain ftp.wingdata.htb) |
| Attack Path | Wing FTP Server Unauthenticated RCE → Config File Disclosure → Fixed-Salt Hash Cracking → SSH Access → Sudo Python Script → tarfile.extractall() Symlink Escape (CVE-2025-4138) → Root |
| CVEs Referenced | CVE-2025-47812 (Wing FTP Server unauthenticated RCE), CVE-2025-4517 / CVE-2025-4138 (Python tarfile arbitrary filesystem write) |
WingData is an easy-difficulty Linux machine centered on a Wing FTP Server web client exposed via a subdomain. An unauthenticated remote code execution vulnerability in Wing FTP Server 7.4.3 provides an initial shell, after which locally stored admin credentials — protected by a fixed, disclosed salt — are cracked offline. The recovered credentials grant SSH access, where a sudo rule around a Python backup-restore script is abused via a tarfile.extractall() symlink-escape vulnerability to obtain a root shell.
An Nmap scan reveals only two open services:
PORT STATE SERVICE REASON
22/tcp open ssh syn-ack ttl 63
80/tcp open http syn-ack ttl 63
Upon browsing the web service, a subdomain named ftp is quickly identified, hosting a Wing FTP Server 7.4.3 web client panel:

Wing FTP Server 7.4.3 is publicly documented as vulnerable to an unauthenticated remote code execution vulnerability:
| CVE | Author | Type | Platform | Date |
|---|---|---|---|---|
| 2025-47812 | 4M3RR0R | Remote | Multiple | 2025-07-02 |
The vulnerability is confirmed against the target using a public exploit:

Running the exploit with a reverse shell payload grants command execution on the target. Using this foothold, an attempt is made to obtain an SSH key from the Wing FTP Server installation directory:

None of the default keys shown above are valid for authentication. Even so, a working command-execution primitive is retained, which is used to read files inside the Data directory — among them, what appear to be administrator password hashes:

Continuing to enumerate the filesystem through the obtained shell, a hashes.txt file is located containing additional credentials — including one for a user named wacky, matching a local system account:
admin:a8339f8e4465a9c47158394d8efe7cc45a5f361ab983844c8562bef2193bafba
john:c1f14672feec3bba27231048271fcdcddeb9d75ef79f6889139aa78c9d398f10
maria:a70221f33a51dca76dfd46c17ab17116a97823caf40aeecfbc611cae47421b03
steve:5916c7481fa2f20bd86f4bdb900f0342359ec19a77b7e3ae118f3b5d0d3334ca
wacky:32940defd3c3ef70a2dd44a5301ff984c4742f0baae76ff5b8783994f8a503ca
None of these hashes crack with a straightforward attempt. Checking the application's configuration files reveals why: password salting is enabled, and — critically — the salt value is static and disclosed in the same configuration file:

With the fixed salt known, hashcat successfully recovers a plaintext password:
hashcat --show -m 1410 hashes_john.txt

This corresponds to the wacky account:
Cracked credentials: wacky : !#7Blushing^*Bride5
The recovered credentials are used to authenticate over SSH:

Enumerating sudo privileges for wacky reveals a passwordless rule allowing execution of a Python backup-restore script as root:

sudo -l
This script appears to handle the restoration of client backups from a tarball. Its help output confirms the expected input format:

tarfile.extractall())Further research uncovers a Python tarfile vulnerability affecting archive extraction:
"Allows arbitrary filesystem writes outside the extraction directory during extraction with
filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives usingTarFile.extractall()orTarFile.extract()using the filter= parameter with a value of 'data' or 'tar'..."
This vulnerability would allow writing files outside the intended restore directory — for example, into /etc/cron.d. Checking the Python version on the target confirms it falls within the affected range:

A public proof-of-concept exploit (CVE-2025-4138-poc) is located, capable of bypassing the extraction filter by generating a chain of symlinks:
The exploit is used to generate a malicious tarball that, once processed by the vulnerable restore_backup_clients.py script running as root, writes an entry directly into /etc/sudoers.d/, granting the wacky user full, passwordless sudo privileges:

| Stage | Technique |
|---|---|
| Recon | Nmap identifies only SSH (22) and HTTP (80) |
| Enumeration | ftp subdomain discovered, hosting Wing FTP Server 7.4.3 |
| Initial foothold | Unauthenticated RCE (CVE-2025-47812) against Wing FTP Server yields command execution |
| Credential access | admins.xml and hashes.txt disclose salted password hashes for multiple users, including wacky |
| Weakness identified | Salting is enabled but uses a static, disclosed salt (WingFTP) found in the application config |
| Credential cracking | hashcat (mode 1410) recovers the wacky password using the known fixed salt |
| Lateral movement | Recovered credentials used to authenticate via SSH as wacky |
| Privilege escalation | sudo NOPASSWD rule on restore_backup_clients.py combined with a Python tarfile.extractall() symlink-escape vulnerability (CVE-2025-4138 / CVE-2025-4517) allows writing an arbitrary sudoers.d entry |
| Root | sudo su after the malicious sudoers entry is written |