FTPXerox v1.0 – FTP File Transfer Sniffer


This is an old tool, but still useful. I saw someone asking for a tool to grab FTP files from the wire without using something like Wireshark, which brought me to this tool – FTPXerox.

FTPXerox grabs files that are transferred across the network using the FTP protocol. It was written to demonstrate the fact that any “clear-text” file transfer protocol is susceptible to such attacks. It implements a full end-to-end TCP re-assembly engine that watches for FTP transfers. Once the engine detects an FTP file transfer, it grabs the file off the wire and stores it in a local file. It is quite intelligent in the sense, it can reconstruct exact file names and even grab binary files! Version 1.0, however, does NOT support PASV mode file transfers.


Notes

Due to the way the TCP re-assembly engine is implemented, FTPXerox can also give directory listing commands (NLST), (LIST) etc in a file. These files will be of the form “fnXXXXXX”. This is just extra information. We plan to fix that in the next release. If you do not need directory listings, just delete these files as and when they’re formed.

You can download FTPXerox v1.0 here:

ftpxerox.zip

Or read more here.

Posted in: Hacking Tools, Networking Hacking Tools

, , ,


Latest Posts:


Karkinos - Beginner Friendly Penetration Testing Tool Karkinos – Beginner Friendly Penetration Testing Tool
Karkinos is a light-weight Beginner Friendly Penetration Testing Tool, which is basically a 'Swiss Army Knife' for pen-testing and/or hacking CTF's.
Aclpwn.Py - Exploit ACL Based Privilege Escalation Paths in Active Directory Aclpwn.Py – Exploit ACL Based Privilege Escalation Paths in Active Directory
Aclpwn.py is a tool that interacts with BloodHound< to identify and exploit ACL based privilege escalation paths.
Vulhub - Pre-Built Vulnerable Docker Environments For Learning To Hack Vulhub – Pre-Built Vulnerable Docker Environments For Learning To Hack
Vulhub is an open-source collection of pre-built vulnerable docker environments for learning to hack. No pre-existing knowledge of docker is required, just execute two simple commands.
LibInjection - Detect SQL Injection (SQLi) and Cross-Site Scripting (XSS) LibInjection – Detect SQL Injection (SQLi) and Cross-Site Scripting (XSS)
LibInjection is a C library to Detect SQL Injection (SQLi) and Cross-Site Scripting (XSS) through lexical analysis of real-world Attacks.
Grype - Vulnerability Scanner For Container Images & Filesystems Grype – Vulnerability Scanner For Container Images & Filesystems
Grype is a vulnerability scanner for container images and filesystems with an easy to install binary that supports the packages for most major *nix based OS.
APT-Hunter - Threat Hunting Tool via Windows Event Log APT-Hunter – Threat Hunting Tool via Windows Event Log
APT-Hunter is a threat hunting tool for windows event logs made from the perspective of the purple team mindset to provide detection for APT movements hidden in the sea of windows event logs.


3 Responses to FTPXerox v1.0 – FTP File Transfer Sniffer

  1. David June 10, 2009 at 9:19 am #

    I already know this tool, very effective and do the right job. But thanks for sharing.

  2. Erik June 10, 2009 at 2:45 pm #

    I also noticed this question on the pen-test mailing list at securityfocus.

    In my opinion the best tool for extracting files sent over FTP from a pcap file is NetworkMiner, it supports both normal (PORT) and passive (PASV) FTP transfers. You can also extract files sent with TFTP, HTTP and SMB with this tool.

    But you have to be running Windows to use NetworkMiner, or you could go ahead and install Wine (www.winehq.org)

    NetworkMiner is available here:
    http://networkminer.sourceforge.net/

    I think you

  3. Darknet June 11, 2009 at 9:23 am #

    Yes we’ve covered NetworkMiner before!

    I think Honeysnap is a good option too, will cover that later.