Credential brute force

FTP authenticates over a cleartext channel with no built-in lockout, so it is a straightforward brute-force and spray target. Vendor defaults and weak user passwords are common, and because the channel is unencrypted, credentials are also recoverable by sniffing an existing session.

bash
hydra -L users.txt -P passwords.txt ftp://<target>
medusa -h <target> -U users.txt -P passwords.txt -M ftp
# Captured FTP traffic reveals USER/PASS in cleartext

Exploitation notes#

  • No default lockout means aggressive brute force is viable, but still rate-limit to avoid tripping monitoring.
  • Try device and application defaults first; appliances and embedded FTP servers ship with known credentials.
  • Sniffing a legitimate FTP session recovers the credentials without guessing, since USER and PASS are plaintext.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more