Search for the exploit "iis5hack.exe"
But you won't get much shells with this sploit anymore. Kinda outdated I think

. And if you get a shell, 70% of these boxes only listen on intern ip's like 192.* or 10.*
Anyone got a solution for these boxes? I think they are behind a router or something. If you change the IP in Serv-U (if you wanna make a FTP server of these IIS servers like me

) to the internet IP you get a message in the startuplog "NOT LISTENING ON PORT XXXX ON XXX.XX.XXX.X TRYING TO USE NON-EXISTENT IP-ADRESS?"
Btw. these are always hooked up in some nice LAN's so if you are able to lan-hack maybe you can use this sploit