FTP Bounce Attack

FTP bounce attack is an exploit of the FTP protocol whereby an attacker is able to use the PORT command to request access to ports indirectly through the use of the victim machine as a middle man for the request.

This technique can be used to port scan hosts discreetly, and to access specific ports that the attacker cannot access through a direct connection.

nmap is a port scanner that can utilize an FTP bounce attack to scan other servers.

Nearly all modern FTP server programs are configured by default to refuse PORT commands that would connect to any host but the originating host, thwarting FTP bounce attacks.

Famous quotes containing the words bounce and/or attack:

    Part of the responsibility of being a parent is to arrange situations in children’s lives so they are able to meet crises with a reasonable chance of coping successfully with them.... Parents who believe children are unharmed by crises and will simply bounce back in time seriously misunderstand children.
    Donald C. Medeiros (20th century)

    The small perplexities of small minds eddy and boil about you. Confident from the experience that has led you out of these same dangers, you attack each problem as it appears, unafraid.
    Alice Foote MacDougall (1867–1945)