Full Disclosure mailing list archives

Re: MS RPC remote exploit. What about DCOMbobulator?


From: "Rob" <rbaer () innernet net>
Date: Thu, 9 Oct 2003 20:45:18 -0400

-------- original msg -------------
Quoting opticfiber (opticfiber () topsight net):

It's come to my attetion that disablinf DCOM in windows is near 
impossible without a regedit.

I am no m$win expert, but I think that runing 'dcomcfng' from a DOS
shell and clicking on 'Default Properties' and clearing 'Enable Dcom on this
Computer' window is enough. No regedits, no 'tiney little applications' required.

You still need to patch the PC or install *nix on it though....
----------- end --------------

I'm not a professional or anything, but the last few Windows systems I have installed for people I have applied the 
following small registry 'patch' to them before going online to download the countless amounts of updates:

--- begin nodcom.reg ---

Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"EnableDCOM"="N"

--- end nodcom.reg ---

I do agree that you still should patch it, but after the first time of going through an install only to be infected 
with the worm while downloading the updates was enough to drive a person mad.  This is a very simple workaround for 
something that IMHO isn't very severe any more.


Rob

Current thread: