Note CERT Advisory CA-1997-27 describes FTP Bounce attacks. For more information, see the "References" section of this article.
By default, the FTP Server service in Microsoft Internet Information Server (IIS), versions 4.0, 5.0, and 6.0, is not vulnerable to this type of attack. However, the FTP Server service may be vulnerable if it has been configured to permit transfers to third-party IP addresses by setting the EnablePortAttack registry key in IIS 4.0 and IIS 5.0, or the EnableDataConnTo3rdIP registry key in IIS 6.0.
For more information about the registry locations of EnablePortAttack and EnableDataConnTo3rdIP, click the following article number to view the article in the Microsoft Knowledge Base:
294679�
How to enable external client computers access to a File Transfer Protocol server