logo

A journey into forgotten Null Session and MS-RPC interfaces

ID: 31ccd895-74f9-5ffe-8fa8-2ff0ded4d15e

STIX ID: report--31ccd895-74f9-5ffe-8fa8-2ff0ded4d15e

Feed Name: Securelist by Kaspersky

Date Published: 2024-05-23

Date Updated: 2026-04-29

Author: Haidar Kabibo

...
...

This research examines how legacy null session concepts can be resurfaced by leveraging MS-RPC/DCOM interfaces—specifically IObjectExporter’s ServerAlive2 on TCP 135—to enumerate a domain controller’s network interfaces and potentially domain information without authentication. It reviews historical controls (e.g., named pipe policies), shows that certain DCOM calls operate at no-auth levels, and proposes a methodology to identify additional interfaces enabling anonymous enumeration, offering guidance and tooling for security researchers and penetration testers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.