SFTP

SFTP runs over SSH, so it shares SSH's authentication surface: credential brute force, username enumeration, and key-based access. Its file-share-specific attack is escaping a restricted SFTP-only account, one confined by an OpenSSH chroot or a forced command, out to a real shell or the host filesystem. The broader SSH attack surface is covered under Remote Access.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more