TFTP

tftp:// drives a Trivial File Transfer Protocol request over UDP port 69 from a curl-backed client. TFTP needs no authentication, so where an internal TFTP server exists, this scheme reads files straight out of it, which on internal networks frequently means switch, router, and PXE boot configuration.

Reading a file#

The URL names the host, optional port, and the filename to fetch:

code
tftp://10.0.0.5/running-config
tftp://127.0.0.1:69/startup-config
tftp://10.0.0.5/pxelinux.cfg/default

The client sends a read request for the named file in octet mode and returns the contents. Because TFTP is unauthenticated and request-response, a single tftp:// fetch retrieves whatever the server will serve, with device configuration files (which often embed credentials and SNMP strings) the prime target.

Reach and limits#

TFTP has no listing and no authentication, so success depends on naming a file the server exposes; the common config filenames above are the usual guesses. The scheme is UDP, so a non-response is ambiguous (dropped versus absent), making it less reliable as a port oracle than the TCP schemes, but a returned file is unambiguous disclosure. Use it when a Port probe or network context suggests TFTP is present, typically alongside network infrastructure.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more