<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msinfluentials.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx</link><description>By now you have probably seen: http://www.microsoft.com/technet/security/advisory/935964.mspx Microsoft recommends you mitigate the problem by disabling RPC management on DNS. They give the switch to do that, but no script to do it on a large number of</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#12264</link><pubDate>Wed, 26 Nov 2008 19:13:42 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:12264</guid><dc:creator>Matt</dc:creator><description>&lt;p&gt;Once you&amp;#39;ve installed the hotfix from MS07-029 (&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/935966"&gt;support.microsoft.com/.../935966&lt;/a&gt;,) you should be able to remove the reg key and get remote management working again.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=12264" width="1" height="1"&gt;</description></item><item><title>Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#9904</link><pubDate>Sat, 15 Nov 2008 05:52:54 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:9904</guid><dc:creator>Press Digital</dc:creator><description>&lt;p&gt;Is there any other way to get MMC to work when this workaround is put in place?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=9904" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5840</link><pubDate>Sat, 28 Apr 2007 15:59:02 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5840</guid><dc:creator>jesper</dc:creator><description>&lt;p&gt;Gene, not remotely. That's what the workaround prevents. You can use RDP though.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5840" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5831</link><pubDate>Fri, 27 Apr 2007 20:38:06 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5831</guid><dc:creator>Gene</dc:creator><description>&lt;p&gt;Is there any other way to get MMC to work when this workaround is put in place? &amp;nbsp;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5831" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5803</link><pubDate>Fri, 27 Apr 2007 01:27:04 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5803</guid><dc:creator>Susan</dc:creator><description>Herman?  Call 1-866-pcsafety and ask for PSS Security.  If you have been hit with this worm, Microsoft needs to know this.  They can help you, and it helps to let them know if folks are getting impacted.  This in turn impacts their actions.&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5803" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5786</link><pubDate>Wed, 25 Apr 2007 17:24:42 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5786</guid><dc:creator>jesper</dc:creator><description>&lt;p&gt;Herman, here is what I had to say on your question a few years back:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/technet/community/columns/secmgmt/sm0704.mspx"&gt;www.microsoft.com/.../sm0704.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If you truly have been hit, the advice still stands.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5786" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5785</link><pubDate>Wed, 25 Apr 2007 16:09:20 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5785</guid><dc:creator>herman</dc:creator><description>What do you do if you suspect your server has been hit with the worm that is taking advantage of this flaw?

I am getting a lot of cannot contact  dns server in the mmc since yesterday. I   &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5785" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5729</link><pubDate>Mon, 23 Apr 2007 16:50:15 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5729</guid><dc:creator>jesper</dc:creator><description>&lt;p&gt;Microsoft has published an official KB article with this workaround. Here is what they have to say about it:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/msrc/archive/2007/04/20/new-kb-article-to-help-deploy-dns-remote-rpc-block-workaround-throughout-enterprise.aspx"&gt;blogs.technet.com/.../new-kb-article-to-help-deploy-dns-remote-rpc-block-workaround-throughout-enterprise.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5729" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5666</link><pubDate>Sat, 21 Apr 2007 21:18:51 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5666</guid><dc:creator>Jay Andrews</dc:creator><description>We implemented the workaround above on two of our AD domain controllers (i.e. DNS), and found that in doing so we lost connectivity to a secondary zone replicating from another division (a seperate trusted AD domain - therefore dynamic dns). After removing the patch on one of the servers, the zone connectivity was restored (for that DC).

I&amp;#39;d appreciate any thoughts on this - we were told (by msft) that this shouldn&amp;#39;t be affected by the patch, but it clearly is. 

(I don&amp;#39;t have the exact error, but it&amp;#39;s something like &amp;quot;secondary Zone could not connect to master&amp;quot; or the like)

on the site:
http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx
It suggests that dynamic dns updates are dependent on RPC. could this be the link?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5666" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5264</link><pubDate>Mon, 16 Apr 2007 15:24:33 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5264</guid><dc:creator>DrewNamingServer</dc:creator><description>&lt;p&gt;Hysteria!! If an internal user is an accomplished coder who can manipulate RPC then why is shutting off the DNS remote mgmt server going to keep them from doing harm. Have you enumerated the RPC servers available on a domain controller? There is a large surface for attack.&lt;/p&gt;
&lt;p&gt;If you have external DNS servers that dont have port 135 protected then you get whats coming to ya! &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5264" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5246</link><pubDate>Mon, 16 Apr 2007 08:28:01 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5246</guid><dc:creator>criticaljoe</dc:creator><description>&lt;p&gt;List of all DNS servers in the forest (handy if you're an Enterprise admin):&lt;/p&gt;
&lt;p&gt;dsquery * forestroot -filter &amp;quot;(servicePrincipalName=DNS*)&amp;quot; -attr DNSHostName -l &amp;nbsp;-scope subtree &amp;gt; dnslist.txt&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5246" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5163</link><pubDate>Sun, 15 Apr 2007 12:48:08 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5163</guid><dc:creator>Dennis Lundtoft Thomsen</dc:creator><description>&lt;p&gt;Sorry there&amp;#248;s a typo - it's of course &amp;quot;dnscmd ServerName /config /RPCProtocol 4&amp;quot; &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5163" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5161</link><pubDate>Sun, 15 Apr 2007 12:12:10 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5161</guid><dc:creator>Angeldmx</dc:creator><description>&lt;p&gt;Good tip! ... Thanks very much! &amp;nbsp;&lt;/p&gt;
&lt;p&gt;But, I Would like your opinion on the &amp;quot;Symantec Rapid Release&amp;quot; features ... &amp;nbsp; &lt;/p&gt;
&lt;p&gt;Do you think that it could help protecting efficiently against this vulnerability ?&lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;gt;How to: &lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://entkb.symantec.com/security/output/n2002103012571948.html"&gt;http://entkb.symantec.com/security/output/n2002103012571948.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;gt;Self-extracting EXE file or VDB/XDB files:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new"&gt;ftp://ftp.symantec.com/AVDEFS/norton_antivirus/rapidrelease&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5161" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5160</link><pubDate>Sun, 15 Apr 2007 12:05:04 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5160</guid><dc:creator>Dennis Lundtoft Thomsen</dc:creator><description>&lt;p&gt;You could also use &amp;quot;dnscmd ServerName /config /RPCProtocol 0&amp;quot; to disable RPC on DNS Servers (And combine it with the output from the dsquery command showed earlier)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5160" width="1" height="1"&gt;</description></item><item><title>re: Turn off RPC management of DNS on all DCs</title><link>http://msinfluentials.com/blogs/jesper/archive/2007/04/13/turn-off-rpc-management-of-dns-on-all-dcs.aspx#5134</link><pubDate>Sun, 15 Apr 2007 05:09:36 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:5134</guid><dc:creator>Michael Knightley</dc:creator><description>&lt;p&gt;Jesper:&lt;/p&gt;
&lt;p&gt;I thought so. Thank you for the confirmation, and for the great tip provided above.&lt;/p&gt;
&lt;p&gt;Kind regards&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=5134" width="1" height="1"&gt;</description></item></channel></rss>