Re: Tech Tip: This is how You Disable Dcom & close Down Port 135



Hello Fellas

GRC is a beginning source of security. Yes there are many sources of info on
the net that can give you detailed info on security. Starting at Microsoft
web site.Lots of resources on and making adjustments to you OS.

Does you router have the ability to detect programs that access the net and
also prevent programs access as well ?

....If not or If so

A simplified scenario for your Router

In XP svchost by default accesses the net. DHCP service is just one service
that is launched through the svchost process. Firewalls recognize this to be
a legit process and no blocking is performed unless you specifically block
svchost.

What ever service that is using svhost as a launch point will all ready have
access. A legit process or a naughty program that incorporates its process to
part of the svchost.

Then if a nasty service some how got on your Operating System. Launching it
self through Svchost. Your router has just been compromised by this rogue
svhost service.

Router 99.98% ..why you ask?? 100% perfection to infinity is where we all
fall short including technology.

Allan has the correct approach in how to contructively learn and make
adjustments to propel his learning process further.


An interesting discussion have a good weekend fellas !


"Allan" wrote:


"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:eY0Kwl6iIHA.1184@xxxxxxxxxxxxxxxxxxxxxxx

My last feedback -- don't rely on information on GRC, the scare monger.
Gibson made his money selling a program to change the interleave of
MFM/RLL drives when
there were free alternatives.
Gibson is not an authorative source for INFOSEC related information.

And yes, my BEFSRxx, with ports specifically being blocked, is 100%
reliable.

--
Dave
Dave, I don't know if you are aware of the tweak to disable NetBios without
editing the Registry :
http://security.symantec.com/sscv6/NetBIOS_FAQ.asp?langid=ie&venid=sym&plfid=23&pkj=VRZCCSCEFRQBCBZLSRZ
I checked my services and I already had COM+ Sys App service disabled; I
believe most users with standalone PC's can safely disable this service.
(That is, even without disabling DCOM as per the OP's instructions).
Even after you disable NetBios as per the instructions on the Symantec
website, you cannot disable the NetBios service; it is still needed for
connectivity for some reason. You would still need to block ports 135-138 in
your router after making this tweak.

--
Allan



.



Relevant Pages

  • Re: Tech Tip: This is how You Disable Dcom & close Down Port 135
    ... | the net that can give you detailed info on security. ... | A simplified scenario for your Router ... | that is launched through the svchost process. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: media center extender will not work!!!
    ... I doubt your router is what's causing ... connect your MCX directly to your PC using a cross-over Ethernet cable; ... >>> I first disabled my macafee firewall and was using the windows ... I have tried disabling both firewalls and get ...
    (microsoft.public.windows.mediacenter)
  • Re: Home networking problem.
    ... it does see router in my network places. ... I have a Dlink wireless router hooked to cable modem. ... Pro machine in the workgroup but is unable to access it. ... Windows firewall, tried disabling the computer browser, told it to only use ...
    (microsoft.public.windowsxp.network_web)
  • Re: blocking incoming udp packets
    ... It seems the router is sending udp packets to 255.255.255.255 (both ... UDP 162 is the SNMP trap port. ... The RIP disabling was easy to do, and that has stopped the traffic on ...
    (comp.security.firewalls)
  • Re: Network drops since upgrading to XP
    ... If disabling autoconnection doesn't fix the problem and other ... configure the computer' network cards for half duplex. ... The router DHCP's> addresses, ... > netwrk will just drop, and the ping gets "Request timed out", renew of the> adapter fails, but if I disable and re-enable the adapter the connection> is restored for another random period. ...
    (microsoft.public.windowsxp.network_web)