Add Docker testbed for WingFTP CVE-2025-47812. #173
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
WingFTP Testbed for CVE-2025-47812
A comprehensive Docker testbed for WingFTP server that automates deployment, configuration, and provisioning for testing tsunami scanner plugin.
Overview
This testbed creates a fully containerized WingFTP environment with automated setup, pre-configured admin access, and a demo domain with anonymous user access. The setup is optimized for rapid deployment and testing scenarios.
Architecture
Docker Image Components
Application Layer
/opt/wftpserver/Port Configuration
54665467Setup Process
Phase 1: Infrastructure Setup
Phase 2: Administrative Configuration
administratorwingftp(MD5 hashed in configuration)5466Phase 3: Domain Provisioning
UIDADMINcookiepoc5467(FTP/FTPS disabled)Phase 4: User Provisioning
Quick Start
Prerequisites
wftpserver-linux-64bit.tar.gzsetup-target.shDeployment Commands
Access Points
Administrative Interface
http://localhost:5466administratorwingftpDomain Web Interface
http://localhost:5467Testing
CVE-2025-47812 Exploitation
Execute the provided exploit script against the running testbed: