Files
metasploit-gs/documentation/modules/auxiliary/scanner/ftp/easy_file_sharing_ftp.md
T
2020-01-20 21:26:59 -05:00

797 B

Vulnerable Application

This module exploits a directory traversal vulnerability in Easy File Sharing FTP Server 3.6, or prior. It abuses the RETR command in FTP in order to retrieve a file outside the shared directory.

By default, anonymous access is allowed by the FTP server.

Easy File Sharing FTP Server version 3.6 or prior should be affected. You can download the vulnerable application from the official website:

http://www.efssoft.com/efsfs.exe

Options

Since the FTP server allows anonymous access, by default, you only need to configure:

RHOSTS

The FTP server IP address.

PATH

The file you wish to download. Assume this path starts from C:\

Scenarios

ftp