Contributor

Nope it is RPC DCOM 2.0

Opinion
Oct 23, 20081 min

Microsoft just released their “out of band” security bulletin.  There is a gaping hole in the way most Microsoft platforms serve Remote Procedure Calls (RPC).   This is on the order of severity of the original RPC DCOM vulnerability that led to the wide spread of the MSBlaster worm in August or 2003.

I have never understood why anyone does RPC over the Internet but I guess it is needed for OWA and other Microsoft propriatary applications/protocols.  So, while blocking the relevent ports, 135, 443, and 593, might be a good idea, if those ports are open on your firewall it is probably because you need them and you will break something if you block it.  

Get patched now.  

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author