Get a Pentest and security assessment of your IT network.

News

Microsoft IIS FTP Vulnerability – bad detection

The SITE command in the released exploit is used to store shellcode into memory. There are plenty of other ways to store your shellcode in memory before triggering this vulnerability. If you have rules that don’t conform to this, you need to look for ways to “fail” your rule as quickly as possible. Use something like isdataat to determine if the packet is actually that big before doing the check. If you don’t do this, the effect is cumulative and performance can then become an issue.”]

Source: https://blog.talosintelligence.com/2009/09/microsoft-iis-ftp-vulnerability-bad.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

RasGas, The Second Victim!

News

Technical analysis of the Locker virus on mobile phones