RE: RPC Scan Issues

From: Laura A. Robinson (larobins_at_bellatlantic.net)
Date: 10/14/03

  • Next message: Jerry Heidtke: "RE: RPC Scan Issues"
    To: "'Thaddeus McNamara'" <tk@coast-radio.com>, <focus-ms@securityfocus.com>
    Date: Tue, 14 Oct 2003 14:48:24 -0400
    
    

    > After reading there's yet another RPC exploit code in the
    > wild, I double checked my LANs with both the MS DCOM scanner
    > (KB824146Scan) and the Retina RPC DCOM scanner and got very
    > different results. A few of the machines I know are NOT
    > patched and others are Fully patched.
    >
    > 1. Is it possible they aren't patched properly?

    Yes. It's also possible that you are getting false positives.

    > 2. Should I be getting such different results?

    Ideally, no. Realistically, it happens.

    > 3. Should I or can I turn off RPC?

    No.

    > 4. Will the firewall be enough?

    No, but that doesn't mean you shouldn't configure it to block incoming
    traffic on appropriate ports.

    Laura

    ---------------------------------------------------------------------------
    Visual & Easy-to-use are not words that you think of when talking about
    network analyzers. Need to share problem information with colleagues that
    do not read packets?

    Download ClearSight Networks Analyzer and see a new network analysis tool
    that makes the complex - easy
    http://www.securityfocus.com/sponsor/ClearSightNetworks_focus-ms_031006
    ---------------------------------------------------------------------------


  • Next message: Jerry Heidtke: "RE: RPC Scan Issues"

    Relevant Pages

    • RPC Scan Issues
      ... checked my LANs with both the MS DCOM scanner and the Retina ... RPC DCOM scanner and got very different results. ... network analyzers. ...
      (Focus-Microsoft)
    • RE: RPC Scan Issues
      ... Not many sites hit with one of the many RPC related worms were hit thru the ... Subject: RPC Scan Issues ... RPC DCOM scanner and got very different results. ... network analyzers. ...
      (Focus-Microsoft)