Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 30 guests and 1 member online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Network Pen Testing
How to hack FTP?
EH-Net
May 24, 2013, 01:30:26 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Network Pen Testing
(Moderator:
don
) >
How to hack FTP?
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: How to hack FTP? (Read 63724 times)
0 Members and 1 Guest are viewing this topic.
scucci
Newbie
Offline
Posts: 29
How to hack FTP?
«
on:
September 19, 2008, 01:01:05 PM »
I posted a recent topic regarding securing FTPand now I'm curious in finding a way to hack my FTP server. I want to see if this is possible and learn how to protect it. Are there any known methods or tools that you recomend? I know that FTP sends all data (credentials/files) in clear text, and I want to show this to management.
Also is there a non-intrusive way to secure FTP from a users point of view? We still want them to loging to FTP via their browser or client without having to install any software on their side?
Thanks,
Scucci
Logged
BillV
Hero Member
Offline
Posts: 1892
Re: How to hack FTP?
«
Reply #1 on:
September 19, 2008, 02:24:14 PM »
Sniffing -
Wireshark
Logon Attack -
THC-Hydra
And you could always exploit the software running the FTP service.
I'm not sure I understand your other question. You would secure your FTP service on the server side....
BillV
Logged
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: How to hack FTP?
«
Reply #2 on:
September 19, 2008, 02:27:59 PM »
A favorite tool if you are using a Windows PC is Cain & Able. Good Windows Swiss Army knife type tool.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
scucci
Newbie
Offline
Posts: 29
Re: How to hack FTP?
«
Reply #3 on:
September 19, 2008, 08:42:53 PM »
I guess I didn't make myself that clear in the last post, its kinda of a 2 part question.
1. I know that FTP is not secure and I want to try and crack our current FTP site. I'm currently researching ways to do this. I was wanted to know how to view data and credentials as they're going on the wire. I've read that it passes data in clear text, so i wanted to try and capture this. Is this only possible internally or can this be done externally from the network.
2. Secondly, since FTP does pass everything in clear text I wanted to know a few solutions to secure FTP that wouldn't require a different experience from the users. Is this possible to do without having them download a different client or accessing in a different way.
thanks again,
matt
Logged
sgt_mjc
Sr. Member
Offline
Posts: 294
Re: How to hack FTP?
«
Reply #4 on:
September 19, 2008, 10:15:47 PM »
If you are running Cain on your box, it can intercept FTP credentials. Wireshark will give you a raw view of the traffic. Try looking into SFTP. Good luck.
Logged
Mike Conway
CISSP
CompTia Security +
C|EH
wishi
Newbie
Offline
Posts: 4
Ninja
Re: How to hack FTP?
«
Reply #5 on:
October 17, 2008, 10:42:29 AM »
Why not reverse the client's source a bit. Most times there's a off-by-one or other option to exploit it.
Hydra - guess it's just not my style. You could try Medusa or John, or even CUDA API in C - and speed this up as long as you know whether the policy isn't harmed, causing logfiles. Therefore footprint that before you start anything.
Have fun,
wishi
Logged
Dave 1
Newbie
Offline
Posts: 2
Re: How to hack FTP?
«
Reply #6 on:
September 02, 2010, 10:19:06 AM »
I need a hacker to gain access to my websites ftp details. a host is with holding them from me. but I need it doing before tommorrow 12 noon.
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: How to hack FTP?
«
Reply #7 on:
September 02, 2010, 10:34:26 AM »
@Dave 1: This is an ETHICAL hacker site. We don't do illegal stuff here.
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
Dave 1
Newbie
Offline
Posts: 2
Re: How to hack FTP?
«
Reply #8 on:
September 02, 2010, 10:55:42 AM »
Is it illegal if its my website?
Logged
H1t M0nk3y
Hero Member
Offline
Posts: 865
Re: How to hack FTP?
«
Reply #9 on:
September 02, 2010, 11:56:47 AM »
Quote
a host is with holding them from me
Why does this host holding your FTP site?
You can hack your own stuff in your own lab with tools you own, but other than that, you would need a written permission to do a pentest. And if someone is holding your web site against you, he would probably not sign anything...
Logged
OSCP, GPEN, GWAPT, GSEC, CEH, CISSP
White ghost
Newbie
Offline
Posts: 36
Im a ghost from paradise
Re: How to hack FTP?
«
Reply #10 on:
October 31, 2011, 03:09:45 AM »
You can hack the ftp server with ncrack
ncrack is a backtrack linux tool (and back track is a linux distribution for pentration test its free) but you can download ncrack for windows
its a command line application and here is the example of it
ncrack -v --user admin 192.168.10.1:21
Logged
MCITP CCENT
millwalll
Guest
Re: How to hack FTP?
«
Reply #11 on:
October 31, 2011, 04:29:41 AM »
All the above methods would work fine. Most people would try brute force the account if there was no lock out using hydra or another tool. Using wireshark would work too as long you had access to the network to sniff the traffic this would be the most effect as FTP is not a secure protocol and transfer everything in plain text.
Logged
3xban
Hero Member
Offline
Posts: 608
Re: How to hack FTP?
«
Reply #12 on:
October 31, 2011, 09:06:59 AM »
Careful WhiteGhost, we had another user come in and look for someone to hack a site for them that wasn't the OP.
But to the OP, what you may want to prove is that the FTP site is seceptible to a Man-in-the-middle attack since FTP uses cleartext credentials. Explain to them that SFTP is the prefered method of transfering files to customers and partners. It is run over a Secure Shell (SSH) session which utilizes an encrypted tunnel. The cost is low for implmenting a SFTP solution.
And yes the best way to show them is the use of a sniffer and a tool lilke Cain. Ha! you can get elaborate and utlize the SET to clone the FTP site and show them how someone can socially engineer users to gain access to their credentials
Logged
Certs: GCWN
(@)Dewser
ev0wpnz
Newbie
Offline
Posts: 5
Re: How to hack FTP?
«
Reply #13 on:
November 08, 2011, 08:42:32 PM »
scucci,
FTP is an inherently insecure protocol due to the fact that it uses plain-text and allows anonymous logins. There are also a lot of the FTP applications that are vulnerable to remote exploitation. An example of one vulnerable application would be wu-ftpd. I think 3xban did a great good of answering your question an I mostly just reiterating what he said. Performing an Man-in-the-middle using ARP poisoning and using something like ettercap/cain&able to grab the credentials as someone logs into them would be the simplest way. You could aslo exploit the service although this does not prove that the protocol itself is insecure just the particular application your using.
Here is a good video on Man-in-the-middle:
http://www.youtube.com/watch?v=-hd7XG-b6uk
Feel free to message me if you have any more questions.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
Tools
: Symbolic Exploit Assistant project is looking for collaborators
(0) by
galapag0
Greetings
: Hi from the UK
(5) by
prats84
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(9) by
prats84
Network Pen Testing
: Want a challenge? Want a GXPN practice exam?
(0) by
ajohnson
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(29) by
ajohnson
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(1) by
prats84
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.