FTP probe
The FTP probe opens a control connection and works through it, recording the server’s reply to each command. VirtuProbe speaks FTP directly, written against the protocol specification rather than wrapped around a client library, so the multi-line banner, the reply codes and the data connection the server nominates are all visible rather than hidden inside a helper.
That matters more here than it does for most protocols, because FTP is two connections. The control channel carries the commands and the replies, and the transfer happens on a second connection the server names mid-conversation. The probe shows you both halves.
Two modes
Section titled “Two modes”Switch with the Action / Advanced toggle above the editor.
Action mode picks one thing to do and builds the commands for it. It runs as ordinary FTP commands, so every one of them still appears in the history with its reply.
Advanced mode is the command sequence itself, for the cases Action mode does not cover.
Connection settings
Section titled “Connection settings”| Field | Description |
|---|---|
| Host | Hostname or IP of the FTP server |
| Port | Server port (default: 21) |
| TLS mode | None, or explicit TLS over AUTH TLS |
| Trust self-signed certificates | Skip certificate validation for this probe. Lab use |
| Credential | A Basic credential from the credential store |
| Passive mode | EPSV or PASV, which is how the data connection is negotiated |
| Transfer type | Binary or ASCII |
Passive mode is worth choosing deliberately. EPSV is the modern form and the default; PASV
is the older one, and some servers and middleboxes only answer the one they know. If a transfer
hangs after the control connection looks healthy, this is the first field to change.
Action mode
Section titled “Action mode”| Action | What it does | Fields |
|---|---|---|
| List a directory | Reads a directory listing over a data connection | Remote path |
| Download a file | Retrieves a file and keeps its contents | Remote path |
| Upload a file | Sends content to a path | Remote path, Content |
| File info | Asks the server about one file without transferring it | Remote path |
Advanced mode
Section titled “Advanced mode”Write the control commands yourself, one per line, for example CWD /pub or RETR file.txt. Every
command and every reply is one row in the history.
Extractors
Section titled “Extractors”| Extractor | Pulls out |
|---|---|
FTP_SUCCESS | Whether the probe succeeded |
FTP_REPLY_CODE | A reply code, for example 226 for a completed transfer |
FTP_REPLY_LINES | The reply text, including the lines of a multi-line reply |
FTP_LIST | The directory listing, one entry per line, ready for an ITERATE step |
FTP_FILE_CONTENT | The contents of a downloaded file, as text |
FTP_FILE_HEX | The same bytes as hex, for a file that is not text |
FTP_BYTE_COUNT | How many bytes were transferred |
FTP_LIST is the one that makes a chain worth writing: put it in front of an
ITERATE step and the chain walks whatever the server actually has, rather than a
list of paths you typed in advance and that goes stale.
Chains
Section titled “Chains”An FTP step works like any other. See chain steps and extractors.
The shape that comes up most is a delivery check: list the directory a partner drops files into, iterate over it, download each one and assert on the contents. The file arriving and the file being what you expected are two different claims, and a chain can make both.
A local server to test against
Section titled “A local server to test against”The bundled docker targets include ftp-simple on port 21, with passive ports 30000 to 30009
and a seeded directory.
cd virtuprobe-docker/ftp-simple && docker compose up -d