SFTP runs over SSH, so it shares SSH's authentication surface: credential brute force, username enumeration, and key-based access. Its file-share-specific attack is escaping a restricted SFTP-only account, one confined by an OpenSSH chroot or a forced command, out to a real shell or the host filesystem. The broader SSH attack surface is covered under Remote Access.
Subtopics#
- Credential brute force: guessing SFTP logins.
- Username enumeration: discovering valid users.
- Weak and stolen SSH keys: key-based access.
- Restricted shell and chroot escape: breaking out of an SFTP jail.