hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

=k3Rn=
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
"EnableDCOM"="N"

can you secure a system by using this reg-key do that dcom service isnt started at all?

thx for any replies!
noam
as far as i know, it works perfectly!
it disables dcom, so both dcom1/2 are "patched" smile.gif
virus
already discussed at the forum .....
but I'll let this one stay as its a separate thread and is helpful for protecting against DCOM exploits wink.gif
thatsmej
QUOTE (noam @ Oct 16 2003, 04:58 AM)
as far as i know, it works perfectly!
it disables dcom, so both dcom1/2 are "patched" smile.gif

i tried it local..
and was still able to get my self a shell on rpc1...

microsoft says it should work...
but on my win2k sp3 it didnt...
hermel
It works first after a restart
=k3Rn=
ok, one restart. but then it should be fixed - right?
0xc0000005
i remember that shit is a little bit old to change the reg key from Y (=YES) to "N" (=NO)

but @ Linux regedit this entry doesn't exist, or?!
hermel
@ =k3Rn=
Yes wink.gif

@ 0xc0000005
No it works only on WIN

dozolax
good post
ST.
if i'll disable it, what i'll lose?
system stability will be ok?
virus
I disabled it on my system and works fine. Basically depends on the applications that you are using. Maybe you have an app that uses DCOM ..... so it depends
Dinos
Greetings,
My first post in the board... There is no problem disabling the key, unless you are one of the following: a) a user working with shared contacts in a ms exchange server enviroment cool.gif a user working with very specific web base programs.

Regards,
Dinos
TaScam
only the restart sad.gif . But is beter then be rehacked. So nice solution smile.gif
thx M8
vnet576
QUOTE (TaScam @ Feb 2 2004, 10:38 AM)
But is beter then be rehacked.

So u are already hacked?

laugh.gif
forza
or just this tool
http://grc.com/dcom/ :-)
esorone
Thx for this post,

Find it very usefull
cecrex
installing the patch is the easiest and the best way..
TwitcH
i agree with cetrex, just keep up to date with the windows updates you should be fine smile.gif
MaNiAx
nice tool forza, helps everyone on my network stay clean and put smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.