WingData from HackTheBox features a null-byte Lua injection in Wing FTP Server for RCE, cracked password hashes for a pivot, and a Python tarfile extraction-filter bypass for arbitrary write to root.
0xdf.gitlab.io
HTB: WingData
WingData runs a Wing FTP Server instance with anonymous access enabled. I’ll abuse a null-byte injection flaw in the web interface that smuggles Lua code into the session file, giving remote code execution and a shell. From there, I’ll find Wing FTP’s account files holding salted password hashes, crack one, and reuse it to move to the next user. That user can run a Python backup-restore script as root that unpacks tar archives using the tarfile module’s “data” extraction filter. I’ll exploit a path-validation bypass in that filter to write outside the extraction directory and drop a key into the root account for full access.