On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

September 4th, 2009

Microsoft FTP in IIS vulnerability now under attack

Posted by Ryan Naraine @ 9:49 am

Categories: Arbitrary Code Execution, Browsers, Complex Attacks, Denial of Service (DoS), Exploit code, Hackers, Locally Running Web Servers, Microsoft, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Windows Vista, Zero-day attacks

Tags: Microsoft Windows Server, Vulnerability, Microsoft Corp., FTP, Microsoft IIS Server, Attack, File Transfer Protocol 7.5, Microsoft Windows, Operating Systems, Servers

Less than a week after the publication of exploit code for a critical vulnerability in the FTP Service in Microsoft Internet Information Services (IIS), attackers are now launching in-the-wild attacks against Windows users.

The attacks, described as “limited,” target businesses running IIS 5.0, 5.1, and 6.0.   Microsoft has updated its security advisory to warn of the new attacks and availability of proof-of-concept code targeting Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.

[ SEE: Microsoft confirms IIS zero-day flaw; Exploit code published ]

From the MSRC blog:

Additionally, a new proof of concept published allowing for Denial of Service (DoS) attacks on Windows XP and Windows Server 2003 with read access to the File Transfer Protocol (FTP) service. This does not require Write access.  Also, a new POC allowing DoS was disclosed this afternoon that affects the version of FTP 6 which shipped with Windows Vista and Windows Server 2008.  Customers should be aware that the Download Center has FTP 7.5 available for Windows Vista and Windows Server 2008. FTP 7.5 is not vulnerable to any of these exploits.

Earlier this week, Microsoft issued an advisory to confirm the severity of this vulnerability, which allows remote code execution on affected systems running the FTP service and connected to the Internet.

[ SEE: Patch Tuesday heads-up: Five 'critical' bulletins on tap ]

The vulnerability, disclosed as zero-day by a hacker named “Kingcope,” is a stack overflow in the FTP service when listing a long, specially-crafted directory name. To be vulnerable, an FTP server would need to grant untrusted users access to log into and create that long, specially-drafted directory. If an attacker were able to successfully exploit this vulnerability, they could execute code in the context of LocalSystem, the service under which the FTP service runs.

Microsoft confirmed the vulnerable code is in IIS 5.0 (Windows 2000), IIS 5.1 (Windows XP) and IIS 6.0 (Windows Server 2003).  IIS 7.0 (Windows Vista, Windows Server 2008) is not vulnerable.

In the absence of a patch, Microsoft recommends that administrators prevent untrusted users from having write access to the FTP service. The advisory contains instructions to:

  • Turn off the FTP service if you do not need it.
  • Prevent creation of new directories using NTFS ACLs.
  • Prevent anonymous users from writing via IIS service.

Next Tuesday, Microsoft plans to ship five “critical” bulletins with fixes for code execution holes affecting the Windows operating system.  It is not yet clear if a fix for this FTP in IIS vulnerability will be included in this patch batch.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 23 Talkback(s)
RE: Microsoft FTP in IIS vulnerability now under attack
Use TrustLeap G-WAN instead of IIS:

- G-WAN is faster (in user-mode) than IIS 7.0 (in the kernel),
- G-WAN ANSI C scripts are 5x faster than IIS 7.0 ASP.Net C#,
- G-WAN is light (108 KB) ... (Read the rest)
Posted by: BugHappy Posted on: 09/17/09 You are currently: a Guest | | Terms of Use
They're attacking the space station?  James T. Kirk | 09/04/09
I fail to see the logic  GuidingLight | 09/04/09
That's easy  Loverock Davidson | 09/04/09
They're Borg  NStalnecker | 09/04/09
Security Holes & MS go hand & hand...  Christian_<>< | 09/04/09
"Security Holes & MS go hand & hand..."  mgp3 | 09/04/09
Could you be specific...  msalzberg | 09/06/09
Just a guess...  zkiwi | 09/06/09
Not a good comparison..  JCitizen | 09/06/09
Really?  zkiwi | 09/07/09
Hey, don't I know you?  Snarfiorix | 09/08/09
Some of us have to  UAC nanny screen | 09/08/09
Um  jdbukis@... | 09/07/09
Just using FTP is the vulnerability  georgeou | 09/04/09
Why is it even enabled, then?  Zogg | 09/04/09
It's not  LiquidLearner | 09/04/09
Why not do away with that FTP option alltogether...  UAC nanny screen | 09/08/09
unless it's a public FTP site  TedKraan | 09/07/09
Thank goodness to IIS 7.0 and I'm not running FTP server.  Grayson Peddie | 09/08/09
RE: Microsoft FTP in IIS vulnerability now under attack  slashdotaccount | 09/08/09
Now this is interesting....  storm14k | 09/09/09
You thought wrong.  ye | 09/09/09
RE: Microsoft FTP in IIS vulnerability now under attack  BugHappy | 09/17/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.
Learn more about the free, six-month trial offer>>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
The best support in the Linux business
If Linux is going to power your mission-critical applications, you'd better have the best support known to business. Novell was rated the top provider of Linux technical support.
Learn more >>
Learn more about tools to grow your business
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
Save time with the UPS Business Essentials Guide
Keep Up With The Latest In Document Management with The DocuMentor.
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
Learn more >>
Reduce risk. Reduce complexity. Increase reliability.
A simplified IT environment isn't just less complex. It's also more reliable. Standardize on a single Linux platform with SUSE Linux Enterprise from Novell, and get the world's most interoperable Linux
Learn more >>
advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc