Pentester News: StatefulFTP on Windows 7 and Windows 8 breaks payloads
ID: a9e9605b-732f-5f58-8974-f411154ced05
STIX ID: report--a9e9605b-732f-5f58-8974-f411154ced05
Feed Name: TrustedSec blog
Threat Score
This report describes a penetration-testing observation where Windows 7/8's StatefulFTP firewall inspection disrupts staged reverse Meterpreter payloads over FTP (port 21). It documents the failure mode, demonstrates that windows/shell/reverse_tcp is not affected, and provides workarounds including running an administrative netsh command to disable StatefulFTP or using payloads that do not trigger the inspection; the technique has been integrated into SET v4.4.1.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
