The Big Picture on Big Flaws

Thomas Kristensen · Network Security · 2003

Today we can look back on a month where too many IT managers were caught by surprise by the RPC DCOM vulnerability and the subsequent exploits and worms. If we look at how the vulnerability could be exploited, it is clear that an attacker or a worm needs to be able to establish network connections to ports 135/udp, 135/tcp, 139/tcp, 445/tcp, 593/tcp or another port where a DCOM enabled service is listening. These ports are related to services like RPC (Remote Procedure Call), NetBIOS or CIFS (file sharing). They all provide access to sensitive services and carry sensitive unencrypted data. These ports have been the weakest point in Windows for a long time. For years they have been the target for attacks: • Null sessions. • User enumeration. • Access using default account names, simple passwords or null passwords. • SPAM using Windows Messaging pop-up's. • And many more. In other words these services were never intended to be used on the Internet or other “insecure” networks. These services are intended to be run on internal networks only, any firewall and router in a company should filter this traffic inbound and outbound. It is the first lesson taught at any basic IT security course.

Read the paper · More papers on PaperTik