Security Basics mailing list archives

Re: DCOM Hotfix breaks our software


From: "David Nichols" <dnichols () amci com>
Date: Wed, 20 Aug 2003 09:43:11 -0400

Cheap and dirty way that should work. (For MSBLAST.EXE only! Future variants
with a different name will be able to get through.)

MSBlast must copy its exe file to the %systemroot%,  %systemroot%\system, or
%systemroot%\system32 directories.  (Probably just \system32 but lets use a
little overkill. %systemroot% is typically c:\WINNT.)   Create a folder in
each of these folders call "msblast.exe".  If MSBLAST attempts to infect the
system, the system will not allow the file to be copied into the directory
because a directory with the same name already exists.

Note:  This must be a directory.  A file will just be overwritten by
MSBLAST.

David Nichols
System Admin

----- Original Message -----
From: "alex mole" <alex.mole () realtimeworlds com>
To: <security-basics () securityfocus com>
Sent: Tuesday, August 19, 2003 3:37 PM
Subject: Re: DCOM Hotfix breaks our software


The software is NXN AlienBrain 6 (www.nxn-software.com)

It's a client-server app for version control (sort of like an uber-CVS).
My guess is that it uses DCOM for some of it's functionality.

The problems were on a client machine, and once the hotfix had been
uninstalled from this machine the problems went away. Obviously, this
machine is now still susceptible to the exploit (and W32.Blaster as well).

Is there any other way (without breaking things like DCOM and NetBIOS)
to patch this hole?


Alex



---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: