<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.eeye.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Vulnerability Assessment</title><link>http://forums.eeye.com/forums/18.aspx</link><description>Post issues related to your Vulnerability Assessment scans in this forum</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 SP1 (Build: 30415.43)</generator><item><title>Re: DCOM  key Retina Audit ID 5328</title><link>http://forums.eeye.com/forums/thread/4778.aspx</link><pubDate>Wed, 02 Sep 2009 05:12:17 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4778</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4778.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4778</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If your concerned about saving your registry settings, I would look at using the free program called ERUNT.&amp;nbsp; This can be found at snapfiles.com and other miscellaneous locations.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: DCOM  key Retina Audit ID 5328</title><link>http://forums.eeye.com/forums/thread/4776.aspx</link><pubDate>Tue, 01 Sep 2009 20:09:58 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4776</guid><dc:creator>jaws</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4776.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4776</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Hi,&lt;/p&gt;
&lt;p&gt;&amp;nbsp; How do you save the current permissions prior to changing them?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;&amp;nbsp; Is exporting the registry enough?&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp; Does making these changes cause problems?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Jim&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: DCOM  key</title><link>http://forums.eeye.com/forums/thread/4475.aspx</link><pubDate>Fri, 03 Jul 2009 18:34:00 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4475</guid><dc:creator>nomuus</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4475.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4475</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;jkembry:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;New to the forum.&lt;/p&gt;
&lt;p&gt;I am having different issues when this particular vulnerability is
remediate.&amp;nbsp; I have a number of machines (Windows XP Professional, SP3)
where functionality has been severly degraded.&amp;nbsp; They take forever to
boot up, the Windows Installer Service ceases to function, there is
major time lag between when the user is doing something and when the
computer responds.&lt;/p&gt;
&lt;p&gt;Once we re-set DCOM permissions back to they way they were before remediation, all returns to normal.&lt;/p&gt;
&lt;p&gt;Any ideas.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Jeff Embry&lt;/p&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I
am wondering as to why this would have caused such a performance
degradation, esp if you ensured SYSTEM and Administrators have full
access to these keys.&amp;nbsp;&amp;nbsp; I believe Windows Installer Service runs as
SYSTEM, so if SYSTEM has full permissions in this particular registry
location...are you propogating all permissions throughout the subkeys? &lt;/p&gt;
&lt;p&gt;The
symptoms you described could be numerous different reasons, like
applications be restricted to what they can access via DCOM, or a user
account or group not having proper access, etc.&amp;nbsp; Verify the permissions have propogated throughout the keys (as described in my last post). Does that resolve any issues?&lt;/p&gt;
&lt;p&gt;Are there any applications that could depend on needing write access to dcom permissions??&amp;nbsp;&amp;nbsp; Users other than those in the Administrators Group or the local SYSTEM account should not need greater than read permissions (e.g. read and write).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: DCOM  key</title><link>http://forums.eeye.com/forums/thread/4474.aspx</link><pubDate>Fri, 03 Jul 2009 18:17:38 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4474</guid><dc:creator>nomuus</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4474.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4474</wfw:commentRss><description>&lt;p&gt;&lt;BLOCKQUOTE&gt;&lt;div&gt;&lt;img src="http://forums.eeye.com/Themes/eeye/images/icon-quote.gif"&gt; &lt;strong&gt;gallaghermj:&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;span style="font-size:x-small;"&gt;This check verifies that a DCOM object doesn&amp;#39;t have access permissions that allow non-administrator users to change the security settings. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The settings requested to have set: &amp;quot;Ensure that only Local Administrators Group and Local System are permitted to have greater than &amp;quot;read&amp;quot; access.&amp;quot; &lt;/p&gt;
&lt;p&gt;When this item is set the propagtion does not complete. There are about 150+ component keys in there. I have this Registry permission issue come up on every machine I have and would&amp;nbsp;love to remediate the finding&amp;nbsp;The instructions are clear in Retina, but the practical application of them&amp;nbsp;are not. Has anyone resolved this ? What were your steps that lead to success?&lt;/p&gt;
&lt;p&gt;Thanks, Michael&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;
&lt;p&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The solution included in the audit should work, but there is typically a caveat...you have to ensure that you choose the option to replace all child object permissions so that the permissions propogate throughout all subkeys and values.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: DCOM  key</title><link>http://forums.eeye.com/forums/thread/4339.aspx</link><pubDate>Fri, 29 May 2009 15:09:52 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4339</guid><dc:creator>jkembry</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4339.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4339</wfw:commentRss><description>&lt;p&gt;New to the forum.&lt;/p&gt;
&lt;p&gt;I am having different issues when this particular vulnerability is remediate.&amp;nbsp; I have a number of machines (Windows XP Professional, SP3) where functionality has been severly degraded.&amp;nbsp; They take forever to boot up, the Windows Installer Service ceases to function, there is major time lag between when the user is doing something and when the computer responds.&lt;/p&gt;
&lt;p&gt;Once we re-set DCOM permissions back to they way they were before remediation, all returns to normal.&lt;/p&gt;
&lt;p&gt;Any ideas.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Jeff Embry&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: DCOM  key</title><link>http://forums.eeye.com/forums/thread/4171.aspx</link><pubDate>Thu, 09 Apr 2009 17:04:32 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4171</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4171.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4171</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;So your still having the issue after you completed the steps I was given in that post?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: DCOM  key</title><link>http://forums.eeye.com/forums/thread/4170.aspx</link><pubDate>Thu, 09 Apr 2009 15:40:15 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4170</guid><dc:creator>gallaghermj</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4170.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4170</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;You might have listed a fix here &lt;a href="http://forums.eeye.com/forums/p/484/2101.aspx#2101"&gt;http://forums.eeye.com/forums/p/484/2101.aspx#2101&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;but i was able to replicate the steps. Rescanning of DCOM produced the same result.&lt;/p&gt;
&lt;p&gt;
&lt;table cellpadding="0" cellspacing="0"&gt;

&lt;tr&gt;
&lt;td&gt;&lt;/td&gt;
&lt;td&gt;
&lt;table cellpadding="2" cellspacing="2"&gt;

&lt;tr&gt;
&lt;td colspan="2"&gt;&lt;span style="font-size:x-small;color:#000000;font-family:Arial;"&gt;&lt;strong&gt;Microsoft Windows DCOM Object Registry Permissions&lt;/strong&gt;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Audit ID: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;5328 &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Vul ID: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Risk Level: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;Medium &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Sev Code: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;Category II &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;PCI Severity Level: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;1 (Low) &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;CVSS Score: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Category: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;Windows &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Description: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;This check verifies that a DCOM object doesn&amp;#39;t have access permissions that allow non-administrator users to change the security settings. &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;How To Fix: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;span style="font-size:x-small;font-family:Arial, Helvetica, sans-serif;"&gt;Ensure that only Local Administrators Group and Local System are permitted to have greater than &amp;quot;read&amp;quot; access for any DCOM object:&lt;br /&gt;&lt;ol&gt;
&lt;li&gt;Click Start, Run, type &amp;quot;regedt32&amp;quot;, and click OK. &lt;/li&gt;
&lt;li&gt;Locate HKEY_LOCAL_MACHINE\Software\Classes\AppID &lt;/li&gt;
&lt;li&gt;Select AppID, Right Click, then select Permissions. &lt;/li&gt;
&lt;li&gt;Ensure that only Local Administrators Group and Local System are permitted to have greater than &amp;quot;read&amp;quot; access.&lt;/li&gt;
&lt;/ol&gt;Note: Additional groups must have only &amp;quot;read&amp;quot; access and individual user accounts are not permitted. &lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;b&gt;&lt;span style="font-size:x-small;color:#333333;font-family:Arial, Helvetica, sans-serif;"&gt;&lt;strong&gt;Related Links: &lt;/strong&gt;&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;
&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;
&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: DCOM  key</title><link>http://forums.eeye.com/forums/thread/4160.aspx</link><pubDate>Tue, 07 Apr 2009 17:40:13 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4160</guid><dc:creator>Blue1978</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4160.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4160</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Can you copy and paste the Retina audit that is telling you this here?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>DCOM  key</title><link>http://forums.eeye.com/forums/thread/4155.aspx</link><pubDate>Mon, 06 Apr 2009 14:59:42 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4155</guid><dc:creator>gallaghermj</dc:creator><slash:comments>0</slash:comments><comments>http://forums.eeye.com/forums/thread/4155.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4155</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;span style="font-size:x-small;"&gt;This check verifies that a DCOM object doesn&amp;#39;t have access permissions that allow non-administrator users to change the security settings. &lt;/span&gt;&lt;/p&gt;
&lt;p&gt;The settings requested to have set: &amp;quot;Ensure that only Local Administrators Group and Local System are permitted to have greater than &amp;quot;read&amp;quot; access.&amp;quot; &lt;/p&gt;
&lt;p&gt;When this item is set the propagtion does not complete. There are about 150+ component keys in there. I have this Registry permission issue come up on every machine I have and would&amp;nbsp;love to remediate the finding&amp;nbsp;The instructions are clear in Retina, but the practical application of them&amp;nbsp;are not. Has anyone resolved this ? What were your steps that lead to success?&lt;/p&gt;
&lt;p&gt;Thanks, Michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>