Have not tried to exploit it,
 
But MS have fixed in IIS 6 (Win2003 Server) at least the port is only open to localhost.
 
So  I would argue they have learnt, but they haven't fixed it!  
----- Original Message -----
Sent: Tuesday, November 11, 2003 1:51 AM
Subject: Re: [Full-Disclosure] IIS 5.0 random/fixed TCP/UDP ports
 
If that port is used INTERNALLY, shouldn't it be listening INTERNALLY,
as in LOCALHOST? When will MS ever learn...
 

(And the first one who replies with "Microsoft is adding host based
firewalls to 'fix' this architectural oversight" is gonna get added to a
filter list... :)

Reply via email to