| 
 The information in this article applies to: 
 SUMMARY
The CERT (http://www.Cert.org) Advisory CA-97.27 warns of an FTP security
attack called the "Bounce" attack. This involves misuse of the Port
command to maliciously open a connection to a port on the File Transfer
Protocol (FTP) server.
 MORE INFORMATION
The FTP server in IIS 4.0 disallows third-party data transfers. This is
done via a modification to the implementation of the Port command. When
the FTP server receives a Port command, the specified IP address must
match the client's source IP address for the control channel.
 
Keywords          :  | 
| Last Reviewed: May 3, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |