grep -l "SOAP" ./machines (1)

DevArea [Linux]
Medium
Anonymous FTP exposed a Java SOAP service JAR; an MTOM XXE attack against the CXF endpoint leaked the Hoverfly admin password from a systemd unit file, then authenticated RCE via Hoverfly middleware yielded a shell as dev_ryan; privilege escalation exploited a world-writable /bin/bash by writing a SUID-creating wrapper triggered by a root-owned systemd timer.
FTPXXESOAPMTOMApache CXFHoverfly +4
● pwned