That was a let down. Is it really "exfiltration" when you use a protocol designed for mass data transfer and you use it in the exact manner it was intended to be used? The less linkbaity title is "Transferring files with BusyBox's ftp"
The point of the post was to show how easy it is, as people seem to miss these commands or may not be aware of how easy it is to set up a listening service. It's exfiltration by definition, but you are of course free to mangle the data any way you want or use DNS techniques if you really care about hiding what you're doing, but that's a different post.
What is your definition of exfiltration? Or more importantly how do you distinguish between exfil and normal transfer by an authorized user?
There are a lot of embedded devices with fairly trivial vulnerabilities that let you run arbitrary shell commands, but a limited enough set of available commands that getting data out, or doing anything else useful, is nontrivial. (Note that you may not even be able to see the stdout/stderr of the command.) This is showing one way to do that.
Yeah, this is showing one way to copy data from a computer using busybox's ftp client. Where is the surreptitious smuggling? I like my exfil to atleast have a hint of James Bond, MacGuyver, or Rube Goldberg; otherwise it's just copying files off a computer using the default file transfer tools.