• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • HomePage
  • Instructor
  • Syllabus
  • Schedule
    • First Half of the Semester
      • Week 1: Course Introduction
      • Week 2: Meterpreter, Avoiding Detection, Client Side Attacks, and Auxiliary Modules
      • Week 3: Social Engineering Toolkit, SQL Injection, Karmetasploit, Building Modules in Metasploit, and Creating Exploits
      • Week 4: Porting Exploits, Scripting, and Simulating Penetration Testing
      • Week 5: Independent Study – Perform Metasploit Attack and Create Presentation
      • Week 6: Ettercap
      • Week 7: Introduction to OWASP’s WebGoat application
    • Second Half of the Semester
      • Week 8: Independent Study
      • Week 9: Introduction to Wireless Security
      • Week 10: Wireless Recon, WEP, and WPA2
      • Week 11: WPA2 Enterprise, Wireless beyond WiFi
      • Week 12: Jack the Ripper, Cain and Able, Delivery of Sample Operating Systems
      • Week 13: Independent Study – Analyze provided Operating System Samples and Create Assessment Report
      • Week 14: Deliver Assessment to Operating System Class either in person or via teleconferenc
  • Assignments
    • Analysis Reports
    • Group Project Report and Presentation
  • Webex
  • Harvard Coursepack
  • Gradebook

MIS 5212-Advanced Penetration Testing

MIS 5212 - Section 001 - Wade Mackey

Fox School of Business

FBI Alert Urges Companies to Secure FTP Servers

March 28, 2017 by Wayne Wilson 2 Comments

The original cloud service “FTP” is on the radar of many hackers. The FBI sent out an alert to medical and dental entities warning them to secure their FTP servers. Hackers are trying to access protected health information (PHI) and personal identifiable information (PII) through FTP. Research has shown that there are over 700K exposed FTP servers on the internet. Before the days of Dropbox, Google drive and Onedrive people would use the File transfer protocol (FTP) to move or copy data from pc’s to servers or vice versa. Now with cybercrimes at an all-time high this once useful feature is a backdoor to store malware and launch DDoS attacks.

https://www.bleepingcomputer.com/news/security/fbi-alert-urges-companies-to-secure-ftp-servers/

Filed Under: Week 10 Tagged With:

Reader Interactions

Comments

  1. Mauchel Barthelemy says

    April 1, 2017 at 10:00 am

    This was a concern raised at my job this week due to the nature of information we deal with daily. Cyber criminals are trying to make connections to FTP servers in anonymous mode to allow write access to inject malicious tools. Preventive measures include checking FTP servers running in anonymous mode.

    Log in to Reply
  2. Vaibhav Shukla says

    April 5, 2017 at 9:20 pm

    FTP, by itself, is itself has been always been concern due to lot of security vulnerabilities.When there’s a slow network connection, people often resort to using a proxy FTP which makes the client instructs the data transmission directly between two FTP servers. A hacker can take advantage of this type of file transfer and use a PORT command to request access to ports by posing as a middle man for the file transfer request.

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (35)
  • Week 01 (2)
  • Week 02 (14)
  • Week 03 (13)
  • Week 04 (10)
  • Week 05 (7)
  • Week 06 (29)
  • Week 07 (8)
  • Week 08 (1)
  • Week 09 (6)
  • Week 10 (12)
  • Week 11 (7)
  • Week 12 (4)
  • Week 13 (6)
  • Week 14 (18)

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in