HACK A SITE THROUGH FTP [CRYPTING]

HELLO THERE , TODAY I AM  POSTING A TUTORIAL ON WEB-PENETRATION. I WILL BE EXPLAINING HOW TO CRACK AND HACK AN FTP SERVER.

WHAT IS “FTP” ?

FTP STANDS FOR FILE TRANSFER PROTOCOL. AS YOU CAN SEE BY THE NAME, YOU CAN MANAGE FILES THROUGH THE FTP. THE FTP PORT, IS VERY-WELL KNOWN, BUT IS RARELY OPEN ON BIG WEBSITES. THE FTP PORT IS PORT 21. THERE ARE MULTIPLE WAYS TO CONNECT TO AN FTP SERVER/PORT, ESPECIALLY THANKS TO TECHNOLOGY, SUCH AS FILEZILLA.

THERE ARE OF COURSE OTHER WAYS, WHICH ARE THE MANUAL WAYS. WHICH IS CONNECTING TO THE FTP THROUGH A DOS COMMAND LINE. YOU CAN DO THIS FROM UBUNTU, BACKTRACK, (ALL LINUX), AND ALSO WINDOWS. I’VE NEVER TRIED IT ON MAC, BUT I’M SURE IT’S POSSIBLE.

WHEN YOU HAVE ACCESS TO THE FTP, YOU’RE THE KING OF THE WEBSITE. MOSTLY BECAUSE YOU CAN MANAGE ALL OF THE FILES AND DIRECTORIES ON THE SITE. SO YOU CAN UPLOAD AND DELETE. IF YOU UPLOAD YOUR PHP OR ASP SHELL, YOU COULD ROOT THE SERVER, AND POSSIBLY HACK OTHER SITES.
HOW DO I KNOW IF THE FTP PORT IS OPEN?

WELL, YOU DON’T KNOW UNTIL YOU SCAN. THE MOST POPULAR PORT SCANNER WOULD BE NMAP. YOU CAN DOWNLOAD NMAP AT  WWW.NMAP.ORG

HOW DO I CONNECT TO FTP ?

LIKE I SAID, THERE ARE A COUPLE OPTIONS. PERSONALLY, I WOULD CHOOSE THE COMMAND LINE FIRST, BECAUSE YOU LEARN FROM IT. IN A PROGRAM LIKE FILEZILLA, WITH ALL THE FANCY SHIT, IT’S GOT IT ALL. EASY TO WORK WITH, ETC. BUT THE METHOD WE WILL BE USING TO CONNECT, IS WITH “TELNET”.

TELNET IS A NETWORK PROTOCOL THAT YOU CAN USE TO CONNECT TO CERTAIN PORTS ON HOSTS. YOU WOULD EITHER NEED THE WEBSITE NAME, OR IP TO CONNECT. YOU WOULD ALSO HAVE TO MAKE SURE THE PORT THAT YOU WANT TO CONNECT TO, IS OPEN. TO DO THAT, WE NEED A PROGRAM CALLED “NMAP”. NMAP IS A FREE PORT-SCANNER TOOL, IT IS VERY USEFUL TO MANY HACKERS FOR MULTIPLE REASONS.
TO CONNECT TO FTP ON A SITE, AN IP, OR A COMPUTER, YOU NEED TO HAVE TELNET INSTALLED. TELNET IS ALREADY INSTALLED ON ALL WINDOWS AND LINUX OPERATING SYSTEMS. BUT IN WINDOWS 7 & VISTA, YOU HAVE TO CHANGE SOME SETTINGS.

THIS CAN BE DONE VERY EASILY, SIMPLY GO TO CONTROL PANEL ==> PROGRAMS AND FEATURES ==> TURN WINDOWS FEATURES ON OR OFF ==> CHECK OFF THE TELNET CLIENT.

NOW WE CAN SUCCESSFULLY CONNECT TO A PORT THROUGH TELNET.

SO OPEN CMD (COMMAND PROMPT(START => RUN => CMD)). NOW IN THE COMMAND PROMPT, TYPE:
 
CODE:
TELNET

AND HIT ENTER. NOW WE’RE ON TELNET, SO WE CAN CONNECT TO A PORT. IF YOU WOULD LIKE TO GET FAMILIAR WITH THE COMMANDS, SIMPLY TYPE IN “HELP” IN THE COMMAND PROMPT.

NOW, LET’S CONNECT TO OUR SITE (FIRST MAKE SURE THE FTP PORT IS OPEN (PORT 21). NOW, LET’S TYPE IN:
NOW IT SHOULD DISPLAY SOME INFORMATION ON THE FTP, WE CAN USE THAT INFORMATION AGAINST THE SITE, BY SIMPLY GOOGLING SOME EXPLOITS FOR IT.
EXAMPLE: “PROFTPD 1.3.3C EXPLOIT”.

HOW DO I HACK A SITE THROUGH FTP ?

THERE ARE A COUPLE WAYS TO DO THIS, MY FAVORITES ARE LOOKING FOR EXPLOITS IN THE FTP CLIENT AND VERSION, AND BRUTEFORCING/DICTIONARY ATTACK. THE FIRST METHOD IS VERY SIMPLE, JUST READ THE ABOVE SECTION TO FIGURE OUT HOW TO DO IT.

BRUTEFORCING IS WHEN YOU ATTACK A TARGET BY USING SOMTIMES MILLIONS OF PASSWORDS. BRUTEFORCE USES RANDOM COMBINATIONS, WHEREAS A DICTIONARY ATTACK USES WORDS. THE DICTIONARY ATTACK GOES MUCH FASTER, BUT WILL NOT ALWAYS WORK. I ONLY BRUTEFORCE WHEN I HAVE NO OTHER CHOICE.

THE SECOND WAY, IS STILL PRETTY EASY, BUT REQUIRES A LITTLE BIT MORE BRAIN :P . IF YOU WANT TO DO IT MORE “ADVANCED-LY” THEN DOWNLOAD “HYDRA”. HYDRA IS A PROGRAM THAT WILL PERFORM A DICTIONARY ATTACK ON ANY OPEN PORT ON YOUR TARGET SITE, OR IP.

THE EASY WAY TO DO IT, IS BY DOWNLOADING “BRUTUS”. IT DOES THE SAME THING, BUT IT’S EASIER TO NAVIGATE AND USE. YOU CAN GET BOTH PROGRAMS BY GOOGLING THEM. IF YOU CAN’T FIND ANY, PM ME AND I’LL SEND YOU A GOOD LINK.

IF YOU ALREADY HAVE THE CREDNTIALS, YOU CAN LOGIN TO THE FTP OVER TELNET, BY DOING THE FOLLOWING:

CODE:
o http://www.site.com 21
-
PASV
-
USER -USERNAMEHERE-
PASS -PASSWORDHERE-
EPILOGUE

THIS IS A TUTORIAL FOR BEGINNERS, BUT IF I MISSED SOMETHING PLEASE NOTIFY ME BY PM OR BY REPLYING IN THE COMMENT SECTION. THIS TUTORIAL DOES SEEM VERY BRIEF TO ME, BUT I CAN’T EXPLAIN EVERY EXPLOIT THERE IS FOR FTP, OTHERWISE THE TUTORIAL WOULD BE TOO LONG AND BORING.

IF YOU REQUIRE ANY ASSISTANCE, BE SURE TO CONTACT ME BY PM. I ALWAYS READ MY PMS, AND I 90% OF THE TIME REPLY TO ALL OF THEM.

I REALLY HOPE THIS TUTORIAL HELPED, BUT IF IT DIDN’T, PLEASE TELL ME WHAT I DID WRONG ON THIS TUTORIAL, SO THAT I CAN FIX IT FOR YOU. :)

CHECK OUT THE FOLLOWING:

KNOW ABOUT VULNERABILITY SCANNERS :

ABOUT EC-COUNCIL CERTIFICATION FROM INFOSEC INSTITUTE :

Comments

  1. when i type "o http://www.sitename.com 21" it did not work then i used "o ftp.sitename.com 21" and it show:
    220------- Welcome to Pure-FTPd [privsep] [TLS]
    200 ------ you are user number 1 of 50 allowed.
    220------- local time is now 16:19 server port:21.
    220------- This is a private system - no anonymous login
    220------ you will be disconnected after 10 minutes of inactivity.

    ReplyDelete
  2. Wow! This can be one particular of the most beneficial blogs We've ever arrive across on this subject. Actually Magnificent. I am also a specialist in this topic so I can understand your hard work. https://freeworkingtoolsandsoftware.wordpress.com

    ReplyDelete
  3. not helpful,just basic things, all body knows that hydra or brutus are used. :D

    ReplyDelete
  4. not helpful,just basic things, all body knows that hydra or brutus are used. :D

    ReplyDelete
  5. Thanks for this awesome information And Guys here is the app by using this you can download paid app from google play store in free download by using this link Download Now

    ReplyDelete
  6. how to inject exploit the taeget website

    ReplyDelete

Post a Comment

Popular posts from this blog

HOW TO HACK VBULLETIN FORUMS

HACKING FACEBOOK ACCOUNTS LATEST TRICK

HOW TO COPY PROTECTED AUDIO CDS