DCOM not disabled on Win2k SP0,1,2

From: Marc Maiffret (marc_at_EEYE.COM)
Date: 08/12/03

  • Next message: Russ: "Re: DCOM not disabled on Win2k SP0,1,2 - or maybe it is?"
    Date:         Tue, 12 Aug 2003 12:28:15 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Thanks much for the eMail Tod. It should be noted that I just spoke to
    Microsoft and they can confirm that DCOM does not truly become disabled on
    Windows 2000 SP0, SP1, SP2. Even if you set the registry key and restart or
    use the DCOM config tool and restart, your still vulnerable to the DCOM bug.
    Once again Microsoft confirmed this with me on the phone just a little while
    ago. Most of us have been saying this the past few days, or weeks in Tod's
    case, but a few people still wanted to hear it from MS themselves that this
    information is accurate. It is accurate.

    Signed,
    Marc Maiffret
    Chief Hacking Officer
    eEye Digital Security
    T.949.349.9062
    F.949.349.9538
    http://eEye.com/Retina - Network Security Scanner
    http://eEye.com/Iris - Network Traffic Analyzer
    http://eEye.com/SecureIIS - Stop known and unknown IIS vulnerabilities

    | -----Original Message-----
    | From: Tod Beardsley [mailto:todb@planb-security.net]
    | Sent: Tuesday, August 12, 2003 12:32 PM
    | To: Marc Maiffret
    | Subject: Re: reports of DCOM worm on the loose...Report #4
    |
    |
    | You posted on NTBugTraq:
    |
    | > DCOM is not "really" disabled and you are still vulnerable. We have
    | > seen this with a few customers of ours and also testing in our lab.
    | > Anyone else have the same experience?
    |
    | Yup. Documented on Jul 28:
    |
    | "Oh, and in case you have 1000s of workstations and would prefer to
    | simply disable DCOM over RPC (with, say, dcomcnfg.exe), don't bother. I
    | tested this today on Windows 2000, and even after disabling, removing
    | all permissions, and unbinding all protocols, and reboots in between,
    | the target was still plenty exploitable." - Me
    |
    | Just in case you're still gathering data points.
    |
    | --
    | "It's okay to yell 'fire' in a crowded theater
    | if the theater is actually on fire."
    | Tod Beardsley | www.planb-security.net
    |
    |
    |

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!

    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available. And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to

    http://www.trusecure.com/offer/s0100/

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: Russ: "Re: DCOM not disabled on Win2k SP0,1,2 - or maybe it is?"

    Relevant Pages

    • Re: reports of DCOM worm on the loose...Report #4
      ... "eEye's DCOM Checker incorrectly reports NT 4 machines as being vulnerable, ... and disable DCOM (as a way to protect yourself until you install the ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • So what uses DCOM anyway?
      ... What I'm looking for are things that are either built into the OS, an MS Server, or are very widely deployed. ... Warning, if you disable DCOM, may you may lose operating system functionality. ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • here it is !
      ... the difficulty began when I did not specify the ... Should you be interested in disabling TCP 135 for security ... TCP port 135 will only listen on ... I've disabled Dcom in the ...
      (microsoft.public.security)
    • Re: !!READ-easy way to fix the new worm-XP!!
      ... > your desktop right click my computer goto manage ... Disabling DCOM may or may not secure your system from ... this vulnerability, and it does NOTHING NOTHING NOTHING to secure your ... Disabling DCOM, as has been recommended here and elswhere ...
      (microsoft.public.security)
    • Re: Windows 2003 Terminal Slow booting into Desktop
      ... Just more to add, I have just tried via msconfig, disabling Computer ... Browsing and DCOM, the server booted okay. ...
      (microsoft.public.windows.terminal_services)