Cleartext HTTP Username/Password Leakage over FTP

This rule detects potential cleartext leakage of usernames and passwords over FTP (port 21) by identifying HTTP requests containing common credential-related keywords in the URL, while explicitly excluding HTTPS traffic. This could indicate sensitive information being transmitted insecurely.