Dcom Exploit

Dcom Exploit

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Dcom Exploit =?Utf-8?B?TGVlRw==?= 05-16-2008
---> RE: Dcom Exploit =?Utf-8?B?TGVlR...05-16-2008
  ---> Re: Dcom Exploit PA Bear [MS MVP...05-16-2008
  | |--> Re: Dcom Exploit =?Utf-8?B?TGVlR...05-16-2008
  | `--> Re: Dcom Exploit =?Utf-8?B?TGVlR...05-16-2008
  ---> Re: Dcom Exploit PA Bear [MS MVP...05-16-2008
  | ---> Re: Dcom Exploit =?Utf-8?B?TGVlR...05-17-2008
  |   |--> Re: Dcom Exploit Roger Abell [MV...05-17-2008
  |   |--> Re: Dcom Exploit MowGreen [MVP]05-17-2008
  |   `--> Re: Dcom Exploit PA Bear [MS MVP...05-17-2008
  |--> Re: Dcom Exploit Roger Abell [MV...05-17-2008
  ---> Re: Dcom Exploit =?Utf-8?B?TGVlR...05-17-2008
  | |--> Re: Dcom Exploit PA Bear [MS MVP...05-17-2008
  | `--> Re: Dcom Exploit Roger Abell [MV...05-17-2008
  ---> Re: Dcom Exploit =?Utf-8?B?TGVlR...05-18-2008
    ---> Re: Dcom Exploit Roger Abell [MV...05-18-2008
      ---> Re: Dcom Exploit =?Utf-8?B?TGVlR...05-19-2008
        |--> Re: Dcom Exploit PA Bear [MS MVP...05-19-2008
        `--> Re: Dcom Exploit Roger Abell [MV...05-20-2008
Posted by =?Utf-8?B?TGVlRw==?= on May 16, 2008, 2:14 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
My Avast online scanner keeps flashing up with a Dcom Exploit
88.107.???.???:135 /tcp (the ???.??? keeps changing. 251.156, 115.154 being
two of the combinations.) Am I being targeted by someone.

Posted by =?Utf-8?B?TGVlRw==?= on May 16, 2008, 4:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
In addition could this be being caused due to upgrading to SP3? I know this
type of problem was addressed with sp2 but this seems to coincide with the
upgrade to sp3! I have tried a couple of ways to close down the DCOM port
135 but it is still showing as open. Anyone know any answers/solutions.

"LeeG" wrote:

> My Avast online scanner keeps flashing up with a Dcom Exploit
> 88.107.???.???:135 /tcp (the ???.??? keeps changing. 251.156, 115.154 being
> two of the combinations.) Am I being targeted by someone.

Posted by PA Bear [MS MVP] on May 16, 2008, 4:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
/Where/ is Avast find this?

Have you posted about this in Avast User Forums?
http://forum.avast.com/
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/


LeeG wrote:
> In addition could this be being caused due to upgrading to SP3? I know
> this
> type of problem was addressed with sp2 but this seems to coincide with the
> upgrade to sp3! I have tried a couple of ways to close down the DCOM port
> 135 but it is still showing as open. Anyone know any answers/solutions.
>
> "LeeG" wrote:
>
>> My Avast online scanner keeps flashing up with a Dcom Exploit
>> 88.107.???.???:135 /tcp (the ???.??? keeps changing. 251.156, 115.154
>> being two of the combinations.) Am I being targeted by someone.


Posted by =?Utf-8?B?TGVlRw==?= on May 16, 2008, 5:03 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Not yet. This exploit seems to coincide with the installation of SP3. Up
until now I had never had this exploit happen. I have been running Avast for
quite a while now and this is the first time it has flagged this exploit.


"PA Bear [MS MVP]" wrote:

> /Where/ is Avast find this?
>
> Have you posted about this in Avast User Forums?
> http://forum.avast.com/
> --
> ~Robear Dyer (PA Bear)
> MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
> AumHa VSOP & Admin http://aumha.net
> DTS-L http://dts-l.net/
>
>
> LeeG wrote:
> > In addition could this be being caused due to upgrading to SP3? I know
> > this
> > type of problem was addressed with sp2 but this seems to coincide with the
> > upgrade to sp3! I have tried a couple of ways to close down the DCOM port
> > 135 but it is still showing as open. Anyone know any answers/solutions.
> >
> > "LeeG" wrote:
> >
> >> My Avast online scanner keeps flashing up with a Dcom Exploit
> >> 88.107.???.???:135 /tcp (the ???.??? keeps changing. 251.156, 115.154
> >> being two of the combinations.) Am I being targeted by someone.
>
>

Posted by =?Utf-8?B?TGVlRw==?= on May 16, 2008, 5:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Forgot to mention. I have already looked at the avast forum and i can only
find explanations and possible cures and have also tried one and currently
monitoring the solution. I am curious has to why the change?

"PA Bear [MS MVP]" wrote:

> /Where/ is Avast find this?
>
> Have you posted about this in Avast User Forums?
> http://forum.avast.com/
> --
> ~Robear Dyer (PA Bear)
> MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
> AumHa VSOP & Admin http://aumha.net
> DTS-L http://dts-l.net/
>
>
> LeeG wrote:
> > In addition could this be being caused due to upgrading to SP3? I know
> > this
> > type of problem was addressed with sp2 but this seems to coincide with the
> > upgrade to sp3! I have tried a couple of ways to close down the DCOM port
> > 135 but it is still showing as open. Anyone know any answers/solutions.
> >
> > "LeeG" wrote:
> >
> >> My Avast online scanner keeps flashing up with a Dcom Exploit
> >> 88.107.???.???:135 /tcp (the ???.??? keeps changing. 251.156, 115.154
> >> being two of the combinations.) Am I being targeted by someone.
>
>

Similar ThreadsPosted
DCOM February 20, 2006, 10:33 am
Disable DCOM? January 11, 2008, 1:07 pm
Re: Zero-day IE exploit... November 23, 2005, 7:13 am
Zero-day IE exploit... November 22, 2005, 7:46 pm
Possible new exploit... Have you seen these? April 26, 2006, 2:03 pm
Windows 2003 DCOM October 17, 2005, 11:00 pm
WMI / DCOM 'ACCESS DENIED' February 28, 2007, 7:29 am
Mapping IPC$ doesn't work for DCOM June 18, 2008, 6:15 pm
Re: Where is the IE zero day exploit in the news... November 27, 2005, 2:12 pm
Why was IE6 vulnerable to the wmf exploit? January 5, 2006, 7:45 pm

The site map in XML format XML site map

Contact Us | Privacy Policy