FTP servers are nothing but server-application running on port 21 of the server. Check out what is the version and name of the ftp-server. After that search for a vulnerability on net for that particular server. If you find a vulnerability, consider yourself lucky. Go ahead, download it and use it to exploit it. Be sure what the exploit does - some can DoS which I am sure you wouldn't want to.