Thank you, guys. You prompted me to learn a bit about the protocol. I want to share what I learned after skimming over the RFC.
A typical session looks like:
$ telnet ftp.kernel.org 21
Trying 149.20.4.69...
Connected to ftp.all.kernel.org.
Escape character is '^]'.
220 Welcome to kernel.org
USER anonymous
331 Please specify the password.
PASS
230 Login successful.
PASV
227 Entering Passive Mode (149,20,4,69,119,142).
Then I was baffled. What does 149,20,4,69,119,142 mean? Okay, 149,20,4,69 looks like an IP address for ftp.kernel.org. But what do they want me to do with 119,142? Turns out it's a port number divided into two octets. Basically they are asking me to connect to port 119 * 256 + 142 = 30606.
So, on the second terminal I run:
$ telnet 149.20.4.69 30606
Trying 149.20.4.69...
Connected to 149.20.4.69.
Escape character is '^]'.
Back to the first one:
LIST
150 Here comes the directory listing.
226 Directory send OK.
And I get the listing I requested, on the second terminal:
drwxr-xr-x 9 ftp ftp 4096 Dec 01 2011 pub
Connection closed by foreign host.
$
Instead of using PASV, you can request the FTP server to connect back to you, with PORT. First, you need to start listening on your WAN interface (if you have one; if you don't, you are out of luck) with `nc -l your.ip.goes.here 2560`. Then, request the server to connect by typing `PORT your,ip,goes,here,10,0` (NB: use commas, not dots). Of course, don't forget to replace your.ip.goes.here with your real WAN IP address.
Cheers.