Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

MSRPC error in one sep client pc!

Created: 30 Nov 2010 | 6 comments
techshan's picture
0 0 Votes
Login to vote

Hi

 

I am getting the MSRPC error in one of the symantec endpoint protection client pc mentioning some ip address .But before noting down the ip address I closed the warning message.How to get that log of the warning?

 

 

Thanks & Regards

 

S.Swaminathan

Comments

Pawel Lakomski's picture
30
Nov
2010
0 Votes 0
Login to vote

It is comming from IPS or

It is comming from IPS or firewall. Check the logs on the client:

- open SEP window,

- on the left select View logs,

- check NTP package loga and Client management-Security log.

Any questions, paste the logs here and we will have a look :)

--

Cheers,

Symantec Technical Specialist
Symantec Certified Specialist
MCP & MCITP
Cisco Certified Network Associate
Citrix Certified Administrator

 

pete_4u2002's picture
30
Nov
2010
0 Votes 0
Login to vote

it will be on client logs. on

it will be on client logs. on the client side open the client gui, click on the view logs.

VeeKee's picture
30
Nov
2010
0 Votes 0
Login to vote

Vulnerability.

Please upload logs and a screen shot of MSRPC message.

---------------------------------
Vikas
--
Don't forget to mark your thread as 'solved' with the answer that best helped you!

techshan's picture
30
Nov
2010
0 Votes 0
Login to vote

No logs

Hi

 

I found no logs in client but found in the sepm cosole and attached the same and the screenshot also

 

Thanks & Regards

 

S.Swaminathan

MSRPC ATTACK30112010.JPG
AttachmentSize
firewall_report.txt 42.26 KB

Thanks & Regards

 

S.Swaminathan

Pawel Lakomski's picture
30
Nov
2010
0 Votes 0
Login to vote

Is the address the attack is

Is the address the attack is comming from your internal machine? If not, block the address on your external firewall.

--

Cheers,

Symantec Technical Specialist
Symantec Certified Specialist
MCP & MCITP
Cisco Certified Network Associate
Citrix Certified Administrator

 

Pawel Lakomski's picture
30
Nov
2010
0 Votes 0
Login to vote

Severity: High This attack

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This signature detects an attack that is being conducted against the Microsoft RPC DCOM service.

Additional Information

There are numerous vulnerabilities associated with Microsoft's RPC DCOM service. This signature represents patterns associated with various publicly available RPC DCOM attacks. Events associated with this attack warrant immediate attention, and users are encouraged to audit the status of all machines with the RPC service enabled.

Microsoft Windows supports a Remote Procedure Call (RPC) application programmer's interface (API) that allows applications to share publicly available objects in a distributed computing environment (DCE). RPCSS is the service that carries out the communication that takes place through the specified API.

One of the more notable vulnerabilities associated with this service is a denial-of-service condition that exists in the RPCSS service. This issue is due to a failure of the application to properly handle malformed network messages.

The problem presents itself when the malformed messages are handled by the affected service. Exceptional conditions triggered by the malformed messages cause a failure of the application to free previously acquired heap memory. After processing a number of offending messages, the process will be unable to allocate more memory for incoming network data and a denial-of-service condition will be triggered.

The issue specifically deals with the processing of packets reporting extremely large length. After DCOM processes the request, it is passed to the Activation class of functions residing in 'rpcss.dll'. Here memory is allocated to store the information; the size of memory allocated is derived from the 'length' field of the message. If the specified length is larger than the memory pool of the source buffer, an exception will be triggered. In this case the memory that was allocated will not be freed, causing a memory leak that will trigger a denial-of-service condition.

Successful exploitation of this issue may allow a remote attacker to cause the affected server to crash or stop responding. On Microsoft Windows 2000, XP, and Server 2003 this will cause the affected system to reboot; on all other Windows platforms the system will have to be manually rebooted. It is currently not known whether this issue could be leveraged to execute arbitrary code on the affected system.

It has been observed that W32.Gaobot and W32.RXBot worms exploit this issue to propagate.

--

Cheers,

Symantec Technical Specialist
Symantec Certified Specialist
MCP & MCITP
Cisco Certified Network Associate
Citrix Certified Administrator