Ever wondered how many open FTP servers there are?
github.com
github.com
cat: README: No such file or directory
I'd occasionally get email from frustrated people who had trouble trying to read the README file, so I'd tell them to simply run "emacs README", and emacs would solve all of their problems. I don't know if my passive aggressive emacs evangelism ever worked, because I never heard back from them.
At some point I got hold of Scott Yanoff's list of interesting Internet services (capitalizing Internet was still justifiable at the time) and learned about the Weather Underground, Archie, HPCWire, and this new thing called the "World Wide Web" — I started telnetting to a server at the University of Kansas where I could use Lynx, and it seemed pretty clear that this was going to be a big deal, because of how enormously much easier it was than downloading text files over FTP.
So not only have I wondered how many open FTP servers there are, my exploration of the internet pretty much started with a list of them.
Nowadays I occasionally look for FTP servers because they tend to be less of a pain in the ass for downloading stuff than HTTP servers — you can usually get a full list of what they have, and they never interrupt you with CAPTCHAs. It's kind of like a real-world "shibboleet" — I guess sometimes assholes push mandates for CAPTCHAs and whatnot on a company's technical folk, but they leave FTP open because the assholes don't know about it.
If you're wondering how many open HTTP servers there are, Netcraft does a pretty good monthly survey.
Before I had local Internet access (i.e., long distance calls), I used the various "FTP by e-mail" services with my free "Juno" e-mail account (they had toll-free numbers for access!).
Given the Internet is a particular thing, shouldn't it still be used as a proper noun?
What would you think if someone asked you to call them "on the Telephone"?
When we were undergrad students, a friend and I wondered exactly that same question about FTP servers. So we wrote a script that tested random IPv4 for FTP servers using nmap and then attempted to connect.
To our surprise we found quite a few. Most of them were small or not writable, but at least one of them was writable, and it had hundreds of GB of free space. So we connected to it, and then saw that it had huge data files containing what seemed like random junk.
Then, we tried to ssh to the box, but no ssh server was listening. So we tried to telnet in. That worked but we were prompted:
Enter password:
Ah, too bad, we will never guess what the password is… Mh, let's try "123456" just in case… But then, instead of logging us in or telling us that we entered the wrong password, it simply said: Re-enter password:
Mh? So we re-entered "123456". The password has been set.
Haha! The owner must never have set this up. And then we were in. It was a very strange system with a few commands with standard names but non-standard behaviors, and a very minimalistic shell. By poking around and searching the web, we understood that we were actually connected to a surveillance camera and that the big files were probably parts of video.Poking around more gave us access to other such cameras in the same network and more importantly to a web interface from which we could see the videos streaming live. We saw offices and people doing stuff like taking the garbage out (I don't know why but that is one of the more precise image I can recall ^^). The only distincive thing I remember was a big sign saying "Miami Fitness Club".
After that we never did anything about it as we had other things to do, but I kind of cherish this story as a nice souvenir of my first year at the ENS.
Since all clients would basically be connected to a LAN, as soon as I found I could port scan random users I started doing it.
Of course there were a lot of businesses on the network that apparently used FTP to move files around but were unsecured.
I spent the better part of a couple of weeks just going through the data (never actually downloaded anything since I knew it could land me in trouble with my parents).
Like you said, I also cherish this story since it was a rare peak at other peoples lives... without even knowing a 12 year old had access to all their business files.
$ lz5
-bash: lz5: command not found
$ brew install lz5
==> Auto-updated Homebrew!
Updated Homebrew from b5a6b4e to 7926114.
Error: No available formula with the name "lz5"
==> Searching for similarly named formulae...
Error: No similarly named formulae found.
==> Searching taps...
Error: No formulae found in taps.
So, rather than complain about this, how do I do something to fix it? Can I add lz5 as a tap to Homebrew?EDIT: Let me try this again, in a more productive way.
lz5 does not currently exist in Homebrew. I'd like to fix this. I've never done this before. Does anyone have advice? Is it as simple as forking lz5, then adding a tap to Homebrew?
Thanks. And as a note, this edit occurred after specialp's replies. They were right: this originally wasn't a productive comment.
Mine are, at least.
I agree that if you don't want people to access it, you should secure it. Yet not all these servers are accidentally open: my ftp on 80.100.131.150 (I assume it's in there) hosts a copy of Damn Small Linux because all downloads were extremely slow or broken at the time.
which could then be found by searching for "index of"...
So I got to watch the latest leaked movies without having to directly deal with (spend time on) being 'inner circle' :)
Even "gzip -9" compresses the file to 4,035,858.
So I wonder why lz5 was chosen for compression.
Compressor Duration Size
cat 0.0s 11385584 [*]
gzip -1 0.2s 4918778 [*]
bzip2 -1 0.9s 3334653
bzip2 -9 0.9s 3122347 [*]
xz -1 1.1s 4222016
gzip -9 2.4s 4085818
lz5 -15 6.9s 4643261
xz -9 -e 10.7s 4033589
zpaq -m5 34.2s 2655834 [*]
A [*] indicates that no better compressor was faster. Test methodology was `cat | $compressor > output` run 3-4 times to get an average.I'm surprised by how bzip2 turned out.
$ zcat openftp4_all_20160918.gz | sort | gzip -9 > sorted.gz
$ ls -lha *.gz
-rw-r--r--+ 1 mappu mappu 3.9M Sep 18 18:17 openftp4_all_20160918.gz
-rw-r--r--+ 1 mappu mappu 2.2M Sep 18 18:19 sorted.gz
`zpaq` should out-compress xz on the unsorted file, too, but i haven't tried it.Anyway. nmap can probably do this and is a great tool
If you don't mind all the flak you'll get, just send a SYN on the port you care about to each IP (maybe skip rfc1918, multicast and reserved addresses; or only send to addresses included in bgp announcements). If you send one packet to each addresses, including the addresses you should probably skip that's 4 Billion packets; if you do it at 1M pps (should fit on a 1Gbps ethernet connection), that's less than two hours.
Pulling data from research servers (such as Censys), reducing and then scanning is always a good idea.
> For this little experiment, I’ve setup a single KVM instance, running a single 2GHz vCore with 2GIB of RAM and 10GiB of HDD space. This is sufficient. Probing for ftp access is an extremely CPU-intensive task. You are going to hit bottlenecks in this order: > > CPU > Memory > a whole lot of nothing > network > > While the rescan was running, only about 1 to 2kpps were exchanged, while the CPU was pinned at 100%.
So this means his setup spent about 1-2 million clock cycles per probe. That's a lot!
I suppose this is because he runs the probe script once per IP address? I suspect that an implementation which would stay in-process would be at least an order of magnitued faster.
Google has an advantage in terms of index size, but definitely lose in terms of precision. The way it munges queries is a bit unsettling at times, and even the "exact" option doesn't seem to always work the way it should.
I recall there used to be a veronica too (Very Easy Rodent Oriented Network something or the other....), then a jughead too ...
This is not the same for something like redis or mongo. You could try and prove otherwise one day to a judge but that would be your battle and I don't suggest it.
https://blog.shodan.io/its-still-the-data-stupid/
Shodan crawls for most nosql/ queueing software including mongodb and redistribution.
And related to OP: we also crawl for FTP and attempt anonymous as well as a few other things to better understand FTP deployments on the Internet.
Of course this doesn't mean that some court somewhere may think this is illegal. But it's a common and widespread practice.
Connecting to an FTP service (i.e. logging in), even just for 5 or so seconds....I'm not so sure.
Especially when big companies with lax security and aggressive lawyers might see this is as a "hacking attempt"
No, I don't know why. Can someone explain? (without being condescending, preferably)
Would be better if they simply stated that instead of playing insinuation based guessing games.
And how do they protect against spam?
Not sure how to fingerprint Paradise FTP (searching for "Welcome to Paradise" also returned some non-relevant results) but there aren't many that contain "paradise" in their welcome banner.
Shodan also fingerprints lots of other FTP software (check out the "Top Products" section):
https://www.shodan.io/report/WHJBsZqV
ProFTPD is by far the most popular choice at the moment.
Note: Doing a search that uses a filter (ex: "product") requires a free Shodan account. None of the above require paid access, you just need a free account.
Or even a write-only one so people could deposit data.
The only real problem is a read-write one where people can use it to exchange information.