Scrapyd 1.2.1 listening on port 6800 without authentication: addversion.json accepts a Python egg from anyone, and Scrapyd imports it (to list spiders) and runs it, so code in the egg runs on the server.
Not startedDockercommit 00ce03dx86_64 · aarch64Secret
Upload a malicious egg to the open Scrapyd API to run commands on the server and read /ctf/flag.
The brief for this lab lives in its repository.