I remember a few threads over time about some peeps using MS FTP. FYI from 
ISC/Sans. . .

Microsoft IIS 5/6 FTP 0Day released
Published: 2009-08-31,
Last Updated: 2009-08-31 19:55:53 UTC
by Pedro Bueno (Version: 1)


We are aware of an new 0-day exploit that was posted on Milw0rm today.

According the exploit, it was suppose to work on both IIS 5.0 and 6.0, on the 
FTP module.

Also according it, it affects IIS 6.0 with stack cookie protection.

The latest on this is that HDMoore is porting it to the MetaSploit framework.

We will update this diary with more info as we get it.


Joe



~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to