Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: STFrancis
here's the fix for it
Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability


A buffer overrun vulnerability has been reported in Microsoft Windows that can be exploited remotely via a DCOM RPC interface that listens on TCP/UDP port 135. The issue is due to insufficient bounds checking of client DCOM object activation requests. Exploitation of this issue could result in execution of malicious instructions with Local System privileges on an affected system.
This issue may be exposed on other ports that the RPC Endpoint Mapper listens on, such as TCP ports 139, 135, 445 and 593.



Resolution for Windows XP
Shut down PC
Unplug Cable Modem.
Start up PC
Click Start -> Settings -> Control Panel
Double Click Network Connections
Right Click the Local Area Connection used to access Internet. Example: Local Area Connection 1
Select Properties
Click the Advanced Tab
Enable the Windows XP Firewall
Click OK, Close out of open windows.
Plug in the Cable Modem.
Ensure Block Sync is established.
Open Internet Explorer
Go to the following URL: http://www.microsoft.com/technet/default.asp
Click the Link toward the middle of the page titled: Action: Read Security Bulletin MS03-026 and Install the Security Patch Immediately
Scroll Down Page about half way to Patch Availability
Click Windows XP 32 bit Edition
Click Download in the upper right of the screen.
Save the file to the desktop
Run the downloaded file.
The patch will install and prompt the customer to reboot.
Once the patch is installed and the computer rebooted, the Windows XP firewall can be disabled and the customer can surf normally.
Temporary Resolution for Windows 2000 Users
Have them go to http://download.microsoft.com/download/0/1/f/01fdd40f-efc5-433d-8ad2-b4b9d42049d5/Windows2000-KB823980-x86-ENU.exe and install the file from there. URL is not case sensitive.
17 posted on 08/11/2003 3:20:21 PM PDT by LynnHam
[ Post Reply | Private Reply | To 1 | View Replies ]


To: LynnHam
If I do the normal go to the Windows Updatepage, let it scan my computer and download &install all the patches, would it install this one too, or do I still have to go and install it manually. (at the Window update it says there are no updates to install, recently I downloaded and installed a bunch of critical patches, which seem to be as numerous as multiplying rabbits).
118 posted on 08/11/2003 7:27:52 PM PDT by FairOpinion
[ Post Reply | Private Reply | To 17 | View Replies ]

To: LynnHam
Thank you.
I owe you one.
123 posted on 08/11/2003 7:39:17 PM PDT by dtel (Texas Longhorn cattle for sale at all times. We don't rent pigs)
[ Post Reply | Private Reply | To 17 | View Replies ]

To: LynnHam
I just went to the Microsoft Windows XP forum and downloaded what they told me to down load and they did everything for me. I shut down my computer and re-started and haven't had a problem since. Are you saying that I need to do more?
140 posted on 08/11/2003 8:18:32 PM PDT by Eva
[ Post Reply | Private Reply | To 17 | View Replies ]

To: LynnHam
I followed your instructions in post #17, and it worked perfectly. I started having this problem about 6:00 pm yesterday. I could do anything I wanted on my computer, except stay online. It would shutdown within about 5 minutes, everytime. My virus software detected nothing. Thank you so much!
200 posted on 08/12/2003 6:56:29 AM PDT by reaganite
[ Post Reply | Private Reply | To 17 | View Replies ]

To: LynnHam
Well IF you didn't do a RUN -> Regedit...and do a Find on HKEY_LOCAL_MACHINE for Msblast.exe you are still a carrier...
204 posted on 08/12/2003 7:12:23 AM PDT by antivenom (BEING OFFENDED means never having to answer an argument)
[ Post Reply | Private Reply | To 17 | View Replies ]

To: LynnHam
Home use, thanks.
236 posted on 08/12/2003 10:10:56 AM PDT by FourtySeven
[ Post Reply | Private Reply | To 17 | View Replies ]

To: LynnHam
Just found MSBlast.exe in my registry. And what point in this process do you delete the file itself? And yes, I know to turn off system restore. Thank you.
262 posted on 08/12/2003 12:26:39 PM PDT by A Navy Vet (Government is the problem, not the solution.)
[ Post Reply | Private Reply | To 17 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson