Skip to content

FTP probe

The FTP probe opens a control connection and works through it, recording the server’s reply to each command. VirtuProbe speaks FTP directly, written against the protocol specification rather than wrapped around a client library, so the multi-line banner, the reply codes and the data connection the server nominates are all visible rather than hidden inside a helper.

That matters more here than it does for most protocols, because FTP is two connections. The control channel carries the commands and the replies, and the transfer happens on a second connection the server names mid-conversation. The probe shows you both halves.

Switch with the Action / Advanced toggle above the editor.

Action mode picks one thing to do and builds the commands for it. It runs as ordinary FTP commands, so every one of them still appears in the history with its reply.

Advanced mode is the command sequence itself, for the cases Action mode does not cover.

FieldDescription
HostHostname or IP of the FTP server
PortServer port (default: 21)
TLS modeNone, or explicit TLS over AUTH TLS
Trust self-signed certificatesSkip certificate validation for this probe. Lab use
CredentialA Basic credential from the credential store
Passive modeEPSV or PASV, which is how the data connection is negotiated
Transfer typeBinary or ASCII

Passive mode is worth choosing deliberately. EPSV is the modern form and the default; PASV is the older one, and some servers and middleboxes only answer the one they know. If a transfer hangs after the control connection looks healthy, this is the first field to change.

ActionWhat it doesFields
List a directoryReads a directory listing over a data connectionRemote path
Download a fileRetrieves a file and keeps its contentsRemote path
Upload a fileSends content to a pathRemote path, Content
File infoAsks the server about one file without transferring itRemote path

Write the control commands yourself, one per line, for example CWD /pub or RETR file.txt. Every command and every reply is one row in the history.

ExtractorPulls out
FTP_SUCCESSWhether the probe succeeded
FTP_REPLY_CODEA reply code, for example 226 for a completed transfer
FTP_REPLY_LINESThe reply text, including the lines of a multi-line reply
FTP_LISTThe directory listing, one entry per line, ready for an ITERATE step
FTP_FILE_CONTENTThe contents of a downloaded file, as text
FTP_FILE_HEXThe same bytes as hex, for a file that is not text
FTP_BYTE_COUNTHow many bytes were transferred

FTP_LIST is the one that makes a chain worth writing: put it in front of an ITERATE step and the chain walks whatever the server actually has, rather than a list of paths you typed in advance and that goes stale.

An FTP step works like any other. See chain steps and extractors.

The shape that comes up most is a delivery check: list the directory a partner drops files into, iterate over it, download each one and assert on the contents. The file arriving and the file being what you expected are two different claims, and a chain can make both.

The bundled docker targets include ftp-simple on port 21, with passive ports 30000 to 30009 and a seeded directory.

Terminal window
cd virtuprobe-docker/ftp-simple && docker compose up -d