
WingData - HTB
Summary WingData was compromised through CVE-2025-47812, an unauthenticated RCE in Wing FTP Server (v7.4.3) exposed at ftp.wingdata.htb, yielding a shell as wingftp. Credential hashes exposed in t...

Summary WingData was compromised through CVE-2025-47812, an unauthenticated RCE in Wing FTP Server (v7.4.3) exposed at ftp.wingdata.htb, yielding a shell as wingftp. Credential hashes exposed in t...

Lab Description Lab: Reflected XSS into a JavaScript string with angle brackets HTML encoded This lab contains a reflected cross-site scripting vulnerability in the search query tracking function...

Lab Description Lab: DOM XSS in document.write sink using source location.search inside a select element This lab contains a DOM-based cross-site scripting vulnerability in the stock checker func...

Challenge Overview Category: Web Security / API Exploitation Target: http://154.57.164.76:31023/ A whimsical, interactive text-based game where you wake up in a mysterious alien forest. Navigate ...

About Bucket “A port scan conducted with nmap reveals port 80 running an Apache server, with stored files pointing to an open S3 bucket. It’s possible to upload a PHP shell to the bucket to establ...

About SteamCloud A port scan conducted with nmap reveals specific Kubernetes and Kubelet ports running on the target. It is not possible to enumerate the Kubernetes API because it requires authent...