ftp> help Commands may be abbreviated. Commands are:
! cdup epsv4 hash mdelete mput pdir quote rmdir struct user $ chmod epsv6 help mdir mreget pls rate rstatus sunique verbose account close exit idle mget msend pmlsd rcvbuf runique system xferbuf append cr features image mkdir newer preserve recv send tenex ? ascii debug fget lcd mls nlist progress reget sendport throttle bell delete form less mlsd nmap prompt remopts set trace binary dir ftp lpage mlst ntrans proxy rename site type bye disconnect gate lpwd mode open put reset size umask case edit get ls modtime page pwd restart sndbuf unset cd epsv glob macdef more passive quit rhelp status usage
我们用get和dir命令
1 2 3 4 5 6 7 8
ftp> get allowed.userlist local: allowed.userlist remote: allowed.userlist 229 Entering Extended Passive Mode (|||41292|) 150 Opening BINARY mode data connection for allowed.userlist (33 bytes). 100% |*****************************************************************************************************************************************| 33 0.12 KiB/s 00:00 ETA 226 Transfer complete. 33 bytes received in 00:01 (0.03 KiB/s)
拿到文件
1 2 3 4 5 6 7 8
ftp> get allowed.userlist.passwd local: allowed.userlist.passwd remote: allowed.userlist.passwd 229 Entering Extended Passive Mode (|||45746|) 150 Opening BINARY mode data connection for allowed.userlist.passwd (62 bytes). 100% |*****************************************************************************************************************************************| 62 0.23 KiB/s 00:00 ETA 226 Transfer complete. 62 bytes received in 00:01 (0.05 KiB/s)
拿到所有用户名和密码
我们打开userlist文件查看用户名,然后尝试用用户名登陆
结果尝试失败
1 2 3 4 5 6 7 8
┌──(spencer㉿kali)-[~/桌面] └─$ ftp 10.129.237.84 Connected to 10.129.237.84. 220 (vsFTPd 3.0.3) Name (10.129.237.84:spencer): aron 530 This FTP server is anonymous only. ftp: Login failed ftp>
并且看到530 This FTP server is anonymous only.这个服务器只能用匿名登陆,所以我们只能换个方式