SFTP authenticates through SSH, so brute force targets the SSH service. SFTP-only accounts are frequently service identities (application file drops, partner exchanges) with weak, rarely-rotated passwords, which makes spraying productive. SSH may rate-limit or lock, so pace the attempts.
hydra -L users.txt -P passwords.txt sftp://<target>
nxc ssh <target> -u users.txt -p passwords.txt # also validates SFTP access
Exploitation notes#
- Prefer spraying one password across many users over hammering one account, to avoid lockout and detection.
- SFTP service accounts for B2B file exchange often have guessable names and vendor-default passwords.
- A valid SFTP login may be SFTP-only; turning it into a shell is Restricted shell and chroot escape.