* Dr. Internet columnist Steve Blass discusses blocking Microsoft DNS exploit * Help Desk columnist Ron Nutter offers advice on a printing problem
* How to block Microsoft DNS exploit
By Steve Blass
Q: What can be done to minimize exposure to the current Windows DNS server exploit while we wait for an effective patch?
A: Those running Windows DNS Server services should check whether the service is configured to accept Remote Procedure Call requests and disable them if possible. The SANS Institute Internet Storm Center reports that new variants of the Rinbot worm are actively scanning RPC/DNS Port 1025 to identify targets against which to attempt to perform a Windows DnsservQuery to exploit the DNS RPC vulnerability. Microsoft recommends disabling remote management over RPC for the DNS server by modifying the registry, blocking unsolicited inbound traffic on ports 1024-5000 using a firewall, and enabling the advanced TCP/IP filtering options on outward-facing interfaces.
To read Steve’s response in its entirety, please click here.
* When the printer doesn’t print
By Ron Nutter
Q: An HP deskjet color printer is attached to an NT server on LPT1 and share on a network. It has been working well for sometimes but now, we can no longer print documents from the server console to that printer. No error message is generated. Other Windows 98 users on the network can print to this printer. Both the server and printer have been rebooted several times. Re-installation of the driver was attempted and an “unrecognized option” error was generated. The printer’s uninstall program was run and the printer icon remains in the print folder. What is the most probable solution to this printer problem?
A: This sort of problem is the main reason I don’t like to have a network printer attached to a server. It’s nice when it works but can be a real pain to troubleshoot when it doesn’t. As a general rule, I don’t suggest trying to share an inkjet printer unless it has a built-in network jack. I have run into several situations where the bi-directional communication between the printer and the LPT port just doesn’t work well in a network situation. Even with improvements in server hardware over the past several years, putting a printer on LPT1 (or any LPT port for that matter) can slow the server down, based on the IRQ normally associated with the parallel port.
To read Ron’s response in its entirety, please click here.




