Anonymous access

Many FTP servers allow the anonymous (or ftp) account with any or no password, a default meant for public downloads but frequently left on sensitive servers. Anonymous login lists directories and downloads files, and where anonymous upload is also enabled, it becomes a drop point.

bash
ftp <target>                                 # user: anonymous, pass: anything
# or non-interactively
curl ftp://<target>/ --user anonymous:anon   # list
wget -r ftp://anonymous:anon@<target>/       # mirror everything
nmap -p 21 --script ftp-anon <target>        # detect anonymous access

Exploitation notes#

  • ftp-anon flags anonymous access and whether upload is allowed; anonymous read is loot, anonymous write is a foothold.
  • Anonymous-writable directories that are also web-served turn into web-shell upload; check whether the FTP root maps to a web root.
  • Recursively mirror the server; config, backup, and source files are common on anonymous FTP.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more