An FTP Break-In

ftp-crack.pcap

FTP is one of the most commonly used means of transferring large amounts of data. The company we will be looking at now has an internal FTP server that it uses to maintain all of its pre-release software. Lately, the IT technician in charge of maintaining and monitoring this server has noticed a large amount of traffic on the server after hours. Unfortunately, the FTP server software doesn't have logging functionality, so the only way to get a good grasp of what is going on is to get a packet capture. We want to identify the reason for the server's increase in bandwidth and eliminate the source.

What We Know

The FTP server is running very old software with no decent logging functionality. All major developers within ...

Get Practical Packet Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.