It's not all that hard, look people do port scans of addresses...port 21 is usually whats used for FTP. When they get responses on that port, they see how secure the FTP server is. If you have limited or no security...
Then bam, they use it for warez.