HackTheBox — WingData

Machine Overview

Field Detail
Name WingData
OS Linux (Debian)
Difficulty Easy
Target wingdata.htb (subdomain ftp.wingdata.htb)
Attack Path Wing FTP Server Unauthenticated RCE → Config File Disclosure → Fixed-Salt Hash Cracking → SSH Access → Sudo Python Script → tarfile.extractall() Symlink Escape (CVE-2025-4138) → Root
CVEs Referenced CVE-2025-47812 (Wing FTP Server unauthenticated RCE), CVE-2025-4517 / CVE-2025-4138 (Python tarfile arbitrary filesystem write)

WingData is an easy-difficulty Linux machine centered on a Wing FTP Server web client exposed via a subdomain. An unauthenticated remote code execution vulnerability in Wing FTP Server 7.4.3 provides an initial shell, after which locally stored admin credentials — protected by a fixed, disclosed salt — are cracked offline. The recovered credentials grant SSH access, where a sudo rule around a Python backup-restore script is abused via a tarfile.extractall() symlink-escape vulnerability to obtain a root shell.


1. Reconnaissance

An Nmap scan reveals only two open services:

PORT    STATE SERVICE REASON
22/tcp  open  ssh     syn-ack ttl 63
80/tcp  open  http    syn-ack ttl 63

2. Web Enumeration

Upon browsing the web service, a subdomain named ftp is quickly identified, hosting a Wing FTP Server 7.4.3 web client panel:

276fe94ce91048a254db8237f8d98150.png

Wing FTP Server 7.4.3 is publicly documented as vulnerable to an unauthenticated remote code execution vulnerability:

CVE Author Type Platform Date
2025-47812 4M3RR0R Remote Multiple 2025-07-02

3. Gaining a Foothold — Wing FTP Server RCE

The vulnerability is confirmed against the target using a public exploit:

653c888ae01073d60961a4f8f5ffc555.png

Running the exploit with a reverse shell payload grants command execution on the target. Using this foothold, an attempt is made to obtain an SSH key from the Wing FTP Server installation directory:

d8655402aeee5a77875aabd4272ae843.png

None of the default keys shown above are valid for authentication. Even so, a working command-execution primitive is retained, which is used to read files inside the Data directory — among them, what appear to be administrator password hashes:

a076ab09ac5fa882804f24192ba0a53d.png

4. Post-Exploitation — Reading Local Data

Continuing to enumerate the filesystem through the obtained shell, a hashes.txt file is located containing additional credentials — including one for a user named wacky, matching a local system account:

admin:a8339f8e4465a9c47158394d8efe7cc45a5f361ab983844c8562bef2193bafba
john:c1f14672feec3bba27231048271fcdcddeb9d75ef79f6889139aa78c9d398f10
maria:a70221f33a51dca76dfd46c17ab17116a97823caf40aeecfbc611cae47421b03
steve:5916c7481fa2f20bd86f4bdb900f0342359ec19a77b7e3ae118f3b5d0d3334ca
wacky:32940defd3c3ef70a2dd44a5301ff984c4742f0baae76ff5b8783994f8a503ca

None of these hashes crack with a straightforward attempt. Checking the application's configuration files reveals why: password salting is enabled, and — critically — the salt value is static and disclosed in the same configuration file:

eb137310985dbcb87ef62709ba05a0ac.png

5. Cracking the Fixed-Salt Password Hashes

With the fixed salt known, hashcat successfully recovers a plaintext password:

hashcat --show -m 1410 hashes_john.txt

4d20698fea97d4972096e5a4e886771b.png

This corresponds to the wacky account:

Cracked credentials: wacky : !#7Blushing^*Bride5

6. User Access

The recovered credentials are used to authenticate over SSH:

a357dd11b9b421a4a91dd28b1a24a6ff.png

7. Privilege Escalation — Sudo Python Script

Enumerating sudo privileges for wacky reveals a passwordless rule allowing execution of a Python backup-restore script as root:

25965565a4f18919f10797989a6569fb.png

sudo -l

This script appears to handle the restoration of client backups from a tarball. Its help output confirms the expected input format:

8f36dfec4fa9c24f1431cb2d365336b7.png

8. Exploiting CVE-2025-4138 (tarfile.extractall())

Further research uncovers a Python tarfile vulnerability affecting archive extraction:

"Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of 'data' or 'tar'..."

This vulnerability would allow writing files outside the intended restore directory — for example, into /etc/cron.d. Checking the Python version on the target confirms it falls within the affected range:

48758cd0ce20424cdb3ccb1e33ab644e.png

A public proof-of-concept exploit (CVE-2025-4138-poc) is located, capable of bypassing the extraction filter by generating a chain of symlinks:

9. Root Access

The exploit is used to generate a malicious tarball that, once processed by the vulnerable restore_backup_clients.py script running as root, writes an entry directly into /etc/sudoers.d/, granting the wacky user full, passwordless sudo privileges:

83f2a842de5a0b0291a84dc7a40609ce.png

10. Summary

Stage Technique
Recon Nmap identifies only SSH (22) and HTTP (80)
Enumeration ftp subdomain discovered, hosting Wing FTP Server 7.4.3
Initial foothold Unauthenticated RCE (CVE-2025-47812) against Wing FTP Server yields command execution
Credential access admins.xml and hashes.txt disclose salted password hashes for multiple users, including wacky
Weakness identified Salting is enabled but uses a static, disclosed salt (WingFTP) found in the application config
Credential cracking hashcat (mode 1410) recovers the wacky password using the known fixed salt
Lateral movement Recovered credentials used to authenticate via SSH as wacky
Privilege escalation sudo NOPASSWD rule on restore_backup_clients.py combined with a Python tarfile.extractall() symlink-escape vulnerability (CVE-2025-4138 / CVE-2025-4517) allows writing an arbitrary sudoers.d entry
Root sudo su after the malicious sudoers entry is written