I got an administrator's machine yesterday. When I analyzed the files above, I found the dat file of cuteftp in the Application Data directory and quickly imported it to cuteftp to get the password, the above is an ftp connection with an intranet ip address. The intranet is a large domain and more machines can be obtained through passwords. There is also an ftp connection on the Internet, which is all over ssh and encrypted. At this time, it is very important to get the password, because the Intranet and Internet are all linux machines, and an ssh password can be used freely when it is connected through putty.
In the previous flash XP Connection Tool, the files in the directory are downloaded and opened locally. The plaintext password can be obtained through the asterisk viewer, practice has proved that this trick cannot obtain the plaintext password in cuteftp. It seems that only packet capture is required, and ssh encryption is required to be bypassed. simply change it to the ftp connection mode and ask a colleague to add an intranet ip address on his machine and enable a sniffing, I also added an intranet ip address, connected directly, and caught the password. Cuteftp directly changes the ip address to the Intranet and connects to the Internet.