[ PID: 4312 ]
WingData - CTF
Mar 25, 2026Exploiting unauthenticated RCE in Wing FTP Server for initial access and abusing an insecure tar archive restore script for root privileges.
./view_writeup.shExploiting unauthenticated RCE in Wing FTP Server for initial access and abusing an insecure tar archive restore script for root privileges.
./view_writeup.shChaining RCE in MCPJam with an LFI-to-RCE pivot in PrivateBin to exploit an internal Docker management service for root access.
./view_writeup.shExploiting XSLT injection for arbitrary file write to achieve RCE via cron jobs, followed by priv-esc through a vulnerable needrestart version.
./view_writeup.shExploiting an exposed Git repository, SQL injection, and dynamic rule execution to obtain root access
./view_writeup.shBypassing pac4j-jwt authentication with a forged JWE token and exploiting SSH Certificate Authorities for root access
./view_writeup.sh