FTP serves files over a cleartext control channel on port 21, with a separate data channel. It is attacked through anonymous access (a common default), brute force against its unencrypted login, and the FTP bounce quirk that abuses the PORT command to make the server open connections on the attacker's behalf.
Subtopics#
- Anonymous access: reading files with no credentials.
- Credential brute force: guessing the cleartext login.
- FTP bounce scan: proxying connections through the server.