Security Basics mailing list archives

Re: Cracking FTP password so that I can convince people not to use FTP, and to instead use SFTP? How do I crack the pwd?


From: Adriel Desautels <adriel () netragard com>
Date: Fri, 10 Oct 2008 13:23:18 -0400

Chip,
        You are missing the point. SFTP and FTP are only different because one
uses encrypted channels to communicate and the other is clear text. That
has nothing to do with the actual security or lack there of, of the FTP
service. In fact, FTP can be very secure from a service perspective.
That said, I'd not recommend to anyone that they transfer data over FTP
if its sensitive.

        The simple answer, sniff his connection and show him that his passwords
are sent clear text. Why are you on this mission?

Regards,
        Adriel T. Desautels
        Chief Technology Officer
        Netragard, LLC.
        Office : 617-934-0269
        Mobile : 617-633-3821
        http://www.linkedin.com/pub/1/118/a45

        Join the Netragard, LLC. Linked In Group:
        http://www.linkedin.com/e/gis/48683/0B98E1705142

------------------------------------------------
Netragard, LLC - "The Specialist in Anti-Hacking"

Netragard Whitepaper Downloads:
-------------------------------
Choosing the right provider : http://tinyurl.com/2ahk3j
Three Things you must know  : http://tinyurl.com/26pjsn


Chip Panarchy wrote:
Hello

I was wondering if I could have some help in 'hacking'/'cracking' an FTP site.

I know that FTP is a very old protocol... so I'm certain that there
are many holes in it. Especially in one that hasn't been maintained
for a few years.

How do I crack the password on the FTP site so that I can use that to
convince the owner of the site (a friend of mine) to switch to SFTP?

I really want to know, because no matter how hard I argue with him,
there still is no comparison to cold hard evidence. I've been trying
to convince him for the last month, but he won't budge. Finally I got
him to give me permission to attempt to hack his FTP site.

So please tell me what method I can use to hack the FTP site.

Thanks in advance,

Chip Panarchy

Current thread: