Enumeration
Mandatory
- Check anonymous login
- Try to create AND upload a file:
mkdir testput /tmp/test test
- Check login with at least the following credentials:
- admin / admin
- admin / password
Optional
- Download everything with wget and look for .dot files!
- Check login with newly found users
- Brute-force login
- Make sure to check admin / admin and other usual combinations and DON’T relay on a password list like best110.txt only!
- Download the whole content
- Check for FTP server exploits
- Try
../cd /cd C:\cd C:\\get $file_which_should_be_on_the_os
Tools
- Patator (brute force)
Leave a Reply
You must be logged in to post a comment.