Rating:

Overflow the buffer and call the system function with a pointer to the username, that contains /bin/sh.

Original writeup (https://0xf4b1.github.io/ctftime/tuctf.com/pwn/ctftp/).