PDA

View Full Version : New Free Security Tool


Amie
09-04-2003, 07:37 AM
Steve Gibson, who many of you know as the creator of the
free and excellent "ShieldsUp" security testing service,
wrote this week:

Hi Fred, I wanted to let you know, so that you
could tell your readers if you think it's worthy,
that I have just (early this morning) released my
latest freeware: The DCOMbobulator.

http://grc.com/dcom/

The DCOMbobulator does two things:

* It allows any Windows user to easily test and
verify that their Windows' DCOM system *has* been
correctly patched to eliminate the serious remote
exploit vulnerability which recently brought us
all of the MSBlast Internet worm excitement. We
have confirmed reports that Microsoft's patch
sometimes does not "take", leaving Windows still
vulnerable. The DCOMbobulator let's anyone check
any local Windows system.

* Secondly, and really most importantly, since
virtually NO ONE needs (or has ever needed) to
have DCOM running, the DCOMbobulator allows any
Windows user to safely and easily disable DCOM and
unbind it from port 135. I do a comprehensive job
of this on ALL versions of Windows, so that if the
Windows Task Scheduler and the "Distributed
Transaction Coordinator" (MSDTC) services -- which
both also use port 135 -- are also disabled,
Windows TCP port 135 will finally be closed. )

Like Steve's other offerings, the DCOMbobulator is tiny,
fast, free, and efficient: It downloads in a flash, and does
just what Steve says (above). Plus, it explains what it's
doing, and why; and offers an ultra-easy way to reverse the
changes, if you should ever need or want to. Nice!

I have just used this on my system and here was the result, so I know it works.

linc
09-07-2003, 04:48 AM
Done.

thank you Amie


i'm stealthed.


bye bye worms.

johng
09-07-2003, 06:21 AM
Hello Amie, It says there is no threat to our 98 and Me systems.
But I ran the test and it says DCOM is present and that I could close the port with the programs help. But it said first I must have it running and patched! I don't understand. How can I run it and what is the patch?
Thanks
John

LeRoi
09-07-2003, 12:00 PM
John,

I don't think you or I have anything to worry about (nor anyone else on a 9X system that hasn't installed DCOM as a separate download from M$) if you use a WinME, 98SE or other 9X system.

Run some tests at Grc.com, Sygate, and PCFlank just to make sure your ports are stealthed.

http://www.pcflank.com/

https://grc.com/x/ne.dll?bh0bkyd2

http://scan.sygate.com/prestealthscan.html

johng
09-08-2003, 03:53 AM
Thanks LeRoi for the references, all my ports are shown as BLOCKED.
John

LeRoi
09-08-2003, 08:09 AM
Originally posted by johng@Sep 8 2003, 05:11 AM
Thanks LeRoi for the references, all my ports are shown as BLOCKED.
John
Hi John,

That is the result you want at Sygate, the others will report the proper result as stealthed.