FTP Exposure Brief: Examining the 55-Year-Old Protocol Used by Millions
ID: 284888e6-1178-5da9-bb4a-66bda4e3162d
STIX ID: report--284888e6-1178-5da9-bb4a-66bda4e3162d
Feed Name: Censys Blog
This Censys research brief analyzes roughly 5.94 million Internet-facing FTP hosts (down ~40% since 2024), finding that ~58.9% show at least one completed TLS handshake while ~2.45 million hosts have no observed TLS negotiation; major issues include platform-default configurations (notably IIS FTP's 534 response due to unbound certificates) and concentration in large hosting/broadband ASNs. The report breaks down daemon prevalence (Pure-FTPd, ProFTPD, vsftpd, IIS, FileZilla), regional differences in TLS adoption (very low in mainland China and South Korea, legacy TLS concentrated in Japan), nonstandard port usage, and provides remediation guidance (prefer SFTP, enable/enforce explicit TLS, check IIS serverCertHash) plus Censys queries to monitor exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
