RE: attempt to launch a DCOM server?

From: Mike O'Toole (hoople_ny_at_yahoo.com)
Date: 08/14/03

  • Next message: Shalla: "Re: What the heck is this msblast.exe"
    To: "'Vincent Aikema'" <vaikema@hotmail.com>
    Date: Wed, 13 Aug 2003 18:56:24 -0400
    
    

    I've seen this error (at boot up) when some application is trying to
    launch the 'IISAdmin Service' to enable it's web management interface.
    This was on a server that once had IIS in use but when it was
    decommissioned. The IIS services were set to 'disabled' startup state.

    Mike

    > -----Original Message-----
    > From: Vincent Aikema [mailto:vaikema@hotmail.com]
    > Sent: Wednesday, August 13, 2003 7:02 AM
    > To: geoffreyshorter@hotmail.com
    > Cc: focus-ms@securityfocus.com
    > Subject: RE: attempt to launch a DCOM server?
    >
    >
    > I've seen the same error that Geof reported. It appears on
    > just one of my servers here...about 3 times per day. The
    > error first appeared AFTER I patched the server over a week
    > ago. In my case the "originating user" is in a seperate
    > (country) network linked via a vpn with no firewall in between.
    >
    > My initial obvious conclusion was that the user installed
    > some exploit utility either intentionally or unintentionally
    > and it is being run automatically. However the local admin
    > there hasn't discovered any problem on that user's PC, but
    > is still pursuing it. My main concern now is what
    > did it do on the server BEFORE it was patched last week.
    > I don't see anything abnormal, but...
    >
    > If anyone has any info on this, I'd also like to know :-)
    >
    > Ciao,
    > Vincent
    >
    >
    > -----Original Message-----
    > From: Geoffrey Shorter [mailto:geoffreyshorter@hotmail.com]
    > Sent: Tuesday, August 12, 2003 9:36 PM
    > To: focus-ms@securityfocus.com
    > Subject: attempt to launch a DCOM server?
    >
    > One of our machines, which we know is patched against the RPC DCOM
    > vulnerability, reported this at 12:16:33 this afternoon:
    >
    > System Error 10002
    > Access denied attempting to launch a DCOM Server.The server
    > is:{<bunch of
    > numbers here>}The user is <servicename>/<servername>,
    > SID=S-1-5-21-00000000000-000000000-0000000000-0000.
    >
    > Names and numbers changed/removed to protect the innocent, of
    > course... :)
    >
    > Is the above an indication of someone attempting to exploit
    > the RPC DCOM
    > vulnerability?
    >
    > Anyone know?
    >
    > Thanks.
    > geof
    >

    ---------------------------------------------------------------------------
    Your network firewall and IDS products do not prevent Web application
    attacks - the most common form of online exploitation- resulting in Web
    defacement, data theft, sabotage and fraud.
    KaVaDo is the only company that provides a complete suite of Web
    application security products.
    Download a FREE whitepaper on "Security Policy Automation for Web
    Applications":http://www.securityfocus.com/Kavado-focus-ms
    ---------------------------------------------------------------------------


  • Next message: Shalla: "Re: What the heck is this msblast.exe"

    Relevant Pages

    • Launch a process for each COM object?
      ... COM server instance. ... If COM can't be configured to launch separate processes, ... service and inter-process communicate them to the launched processes? ...
      (microsoft.public.win32.programmer.ole)
    • Re: Launch a process for each COM object?
      ... each COM server instance. ... If COM can't be configured to launch separate processes, ... passed to the COM service and inter-process communicate them to the ...
      (microsoft.public.win32.programmer.ole)
    • Re: My MFC VC++ app is crashing within ProcessShellCommand
      ... Either it is a service, and therefore cannot be double-clicked to launch it, or it is an ... server both when running interactively (by double-clicking on the exe when I, ... under a local account. ... The application works fine both interactivle and as a service under a local ...
      (microsoft.public.vc.mfc)
    • strange behavior....jumping from servers to servers !!!!
      ... I have a strange behavior on servers in an AD environnement. ... icons don’t launch apps, start menu is inoperant and so on. ... The more strange is that this behavior jump from one server to another, ... member server, and other different member in w2K sp4. ...
      (microsoft.public.windows.server.general)
    • Re: Launching an application from ASP.NET
      ... > browser is running on the machine running IIS, they are allowed to launch ... > "server tool" applications from the web pages. ... > From what I have read in the MSDN, web services should not allow a UI. ...
      (microsoft.public.dotnet.framework.aspnet.security)

    Loading