CrushFTP
Discovery
# VHost enumeration
gobuster vhost --url http://TARGET -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-110000.txt --append-domain
# Common subdomain
ftp.TARGETCVE-2025-31161 - Authentication Bypass (Race Condition)
Exploits
Manual User Enumeration
CVE-2024-4040 - SSTI/LFI
Post-Exploitation (After Login)
File Download
Key Files to Grab
User.XML Password Hash Extraction
Cracking CrushFTP Hashes
Pivoting via CrushFTP
Config Paths
Notes
Last updated