More IIS Updates....

From: Marc (Marcat_private)
Date: Mon Jan 25 1999 - 13:03:01 PST

  • Next message: Lamont Granquist: "Digital Unix 4.0 exploitable buffer overflows"

    Ok there have been a few posts about it. So rather then respond to each I
    will just do it once for all.
    
    1. I have stopped getting a lot of eMails from people using NT4.0's ftp.exe
    and saying it didnt work. I have however now started to get many eMails from
    people saying they telneted to the server, sent user, pass, NLST (lots of
    a's) and saying it is not working. Well they are forgetting to send the PORT
    command and listening to whatever port they pass via the PORT command.
    Basically you need to do correct FTP syntax. For the people who have done it
    right on NT4.0 IIS4 sp4 machines, they have eMailed me and told me they have
    gotten it to work.
    
    2. It doesnt seem to effect IIS3.0/4.0 and sp3. Why? I am not sure but maybe
    someone who knows or someone at Microsoft can explain. The eMails that i got
    from people with sp3 were tested correctly. I do not have a sp3 machine
    laying around so I cannot verify. Microsoft should be posting something
    later today.
    
    Some people I want to thank for their input:
    Seth M. McGann
    Jordan Ritter
    Mnemonix
    and whom ever else I forgot
    
    Thanks for making my sorting through eMails such as "I am using CuteFTP and
    cant get it to work." worth my time. You were some of the people that had
    good information to pass along. I thank you for that.
    
    Signed,
    Marc
    eEye Digital Security Team
    www.eEye.com
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:30:55 PDT