Many FTP servers allow the anonymous (or ftp) account with any or no password, a default meant for public downloads but frequently left on sensitive servers. Anonymous login lists directories and downloads files, and where anonymous upload is also enabled, it becomes a drop point.
ftp <target> # user: anonymous, pass: anything
# or non-interactively
curl ftp://<target>/ --user anonymous:anon # list
wget -r ftp://anonymous:anon@<target>/ # mirror everything
nmap -p 21 --script ftp-anon <target> # detect anonymous access
Exploitation notes#
ftp-anonflags anonymous access and whether upload is allowed; anonymous read is loot, anonymous write is a foothold.- Anonymous-writable directories that are also web-served turn into web-shell upload; check whether the FTP root maps to a web root.
- Recursively mirror the server; config, backup, and source files are common on anonymous FTP.