A recent brute-force scan of FTP servers available online via an IPv4 address revealed that 796,578 servers were granting access without credentials.
Security researcher Minxomat, owner of a cybersecurity firm that performs targeted scans of the internet on a regular basis, to detect malicious traffic and its sources.
Minxomat details the process on his blog, explaining how he wrote a simple script to scan all IPv4 addresses. The script attempted to connect via port 21 to the “anonymous” FTP user and without a password.
Minxomat, as mentioned above, has previously scanned for other types of open ports, such as MongoDB, CouchDB, and Redis
“We mostly do commercial reverse-DNS crawling. This is a better approach than our implementation for the brute-force scanning we were after.”
His research shows how simple it is and how few resources a determined attacker needs to scan and compile a list of potential targets.
Minxomat released the full list of IP addresses on GitHub.
“FTP Servers that allow anonymous access with write permissions are quite rare, and are extreme cases.”
More information
https://255.wf/2016-09-18-mass-analyzing-a-chunk-of-the-internet/
