TCP port 21 attacks include:
The following are FTP Attack
Signatures: 
- 3150—FTP SITE command attempted
(severity 1, reconnaissance): This signature is triggered when
someone tries to execute the FTP SITE command. This may indicate
an attempt to illegally access system resources.
- 3151—FTP SYST command attempted
(severity 1, information): The FTP SYST command returns the type
of operating system that the FTP server is running. Authentication
is not required to execute this command. SYST provides information
that may be used to refine attack methods. FTP from Linux causes
SYST signature to fire. Some proxies, such as the TIS Toolkit,
issue the SYST command as a matter of course. Running an FTP
version with SYST disabled.
- 3152—FTP CWD ~root (severity 5,
access): This signature is triggered when someone tries to execute
the CWD ~root command. This may indicate an attempt to illegally
access system resources.
- 3153—FTP Improper address
specified (severity 5, access): This signature is triggered if a
port command is issued with an address that is not the same as the
requesting host.
- 3154—FTP Improper port specified
(severity 5, access): This signature is triggered if a port
command is issued with a data port specified that is less than
1024 or greater than 65535.
|