FTP Bounce Attack

FTP bounce attack is an exploit of the FTP protocol whereby an attacker is able to use the PORT command to request access to ports indirectly through the use of the victim machine as a middle man for the request.

This technique can be used to port scan hosts discreetly, and to access specific ports that the attacker cannot access through a direct connection.

nmap is a port scanner that can utilize an FTP bounce attack to scan other servers.

Nearly all modern FTP server programs are configured by default to refuse PORT commands that would connect to any host but the originating host, thwarting FTP bounce attacks.

Famous quotes containing the words bounce and/or attack:

    You are the food,
    you are the tooth, you are the husband,
    light, light, sieving through the screen
    whereon I bounce my big body at you
    like shoes after a wedding car.
    Anne Sexton (1928–1974)

    ... possibly there is no needful occupation which is wholly unbeautiful. The beauty of work depends upon the way we meet it—whether we arm ourselves each morning to attack it as an enemy that must be vanquished before night comes, or whether we open our eyes with the sunrise to welcome it as an approaching friend who will keep us delightful company all day, and who will make us feel, at evening, that the day was well worth its fatigues.
    Lucy Larcom (1824–1893)