logo

Pentester News: StatefulFTP on Windows 7 and Windows 8 breaks payloads

ID: a9e9605b-732f-5f58-8974-f411154ced05

STIX ID: report--a9e9605b-732f-5f58-8974-f411154ced05

Feed Name: TrustedSec blog

Threat Score
25/100

Date Published: 2023-12-20

Date Updated: 2026-05-01

...
...

This report describes a penetration-testing observation where Windows 7/8's StatefulFTP firewall inspection disrupts staged reverse Meterpreter payloads over FTP (port 21). It documents the failure mode, demonstrates that windows/shell/reverse_tcp is not affected, and provides workarounds including running an administrative netsh command to disable StatefulFTP or using payloads that do not trigger the inspection; the technique has been integrated into SET v4.4.1.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.