DCOM/RPC issues FAQ now available

From: Russ (Russ.Cooper_at_RC.ON.CA)
Date: 09/11/03

  • Next message: Marc Maiffret: "Re: EEye RPC Scanning Tool"
    Date:         Thu, 11 Sep 2003 13:58:04 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    I've tried to put together all that I could think relevant to the DCOM/RPC discussions into a single FAQ so we can avoid discussing things again this time.

    http://www.ntbugtraq.com/dcomrpc.asp

    It includes;

    Disabling DCOM
     - Disabling DCOM on Windows 2000 pre-SP3
     - Additional steps for disabling DCOM on Windows Server 2003
     - Microsoft's warning about disabling DCOM
     - List of known applications requiring DCOM or problematic with DCOM disabled
    Windows 95/98/ME and DCOM
    Problems with Clusters
    Windows 2000 SP4 not listed as a "Supported Operating System"
    Machines with MS03-039 applied appear to require MS03-026
    Reports of vulnerabilities over port 80, 443, or 593
     - Use of Port 593 - RPC over HTTP End Point Mapper
     - Use of Port 80/443 - RPC over HTTP or the DCOM "Tunneling TCP/IP" protocol

    Comments and/or suggestions are solicited on the page, please use the email link there.

    Cheers,
    Russ - Surgeon General of TruSecure Corporation/NTBugtraq Editor

    ----
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!
    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available.  And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to
    http://www.trusecure.com/offer/s0100/
    ----
    

  • Next message: Marc Maiffret: "Re: EEye RPC Scanning Tool"

    Relevant Pages

    • Re: MS03-026 - are you patched? Windows Update isnt sure!
      ... Hoping to shed a little light on the file version checking in Windows ... querying the Windows Installer service (which amounts to a metabase or ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Re: Microsoft Numbering System
      ... Do me a favor and load up a new Windows XP box, ... on each and every patch. ... Summer's Hottest Certification Just Got HOTTER! ... To learn more about the TICSA certification, and to register as a TICSA ...
      (NT-Bugtraq)
    • Re: clients contacting WU directly
      ... set Cryptographic Services to Automatic for Startup ... Install Windows XP SP1 again. ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Re: clients contacting WU directly
      ... When I deployed the Windows Automatic Update feature across our domain (to ... force clients to accept updates from our local SUS machine) I also ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • RPC DCOM still vulnerable even after applying patches
      ... windows 200 SP4 machines that "even if you apply the ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)