File Transfer Protocol (FTP)
A legacy protocol for transferring files that sends credentials, commands and file contents in cleartext over separate control and data connections; commonly replaced by SFTP or FTPS.
The File Transfer Protocol, specified in RFC 959 (1985), moves files between a client and a server. It uses two connections: a control connection, on well-known port 21, for commands and replies, and a separate data connection for each file transfer or directory listing. In active mode the server opens the data connection back to the client; in passive mode the client opens it to a port the server names. That design complicates firewalls and network address translation, which have to track the negotiated ports.
The security problem is that FTP, as originally specified, protects nothing. Usernames, passwords, commands and file contents all cross the network in cleartext, so anyone able to capture the traffic through packet sniffing can read the credentials and the data. Many servers also allow anonymous login, which can expose files unintentionally. FTP sits with Telnet as a classic example of an insecure legacy protocol. There are two common replacements, and they are easy to confuse. SFTP is a different protocol that runs over SSH on a single connection. FTPS is FTP itself with TLS added, so it keeps FTP’s two-connection design.
Exam relevance: a scenario is likely to describe credentials being captured during file transfers, which points to replacing FTP with an encrypted alternative. Candidates are expected to know which replacement builds on SSH and which on TLS.