The vulnerability in the mod_copy module of Proftpd was disclosed a couple months back. Most servers using Proftp are still vulnerable to attacks as they're using older versions of the software. If you're using Proftpd version 1.3.5 or before, your server is vulnerable and it's just a matter of time before someone takes advantage of that vulnerability.

Metasploit. Penetration Testing FTP access with anonymous account 07/25/2018. Added. 11/01/2004. Modified. 12/04/2013. Description. Many FTP servers support a default account with the user ID "anonymous" and password "[email protected]". It is best practice to remove default accounts, if possible.

upload shell via ftp using anonymous connection and abt ftp bruteforcer. Posted by Unknown On 04:50. If the ftp server did not allow access to anonymous login,Then we have to brutefore it using a bruteforcer tool.Normally the ftp server is secured,If u got luck then u can upload shell

Konica Minolta FTP Utility 1.00 - (Authenticated) CWD Command Overflow (SEH) (Metasploit). CVE-2015-7768 . remote exploit for Windows platform

use auxiliary/scanner/ftp/ and press Tab key two times in your keyboard it will display all the options available to enumerate the FTP. You can use all of them one by one to know what they do but for this turorial, I am using anonymous option to check FTP allow anonymous login to do that type the following command in your Metasploit workspace

