Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> exploiting one of the hundreds of RPC/DCOM/LSASS vulnerabilities in Windows

And then Microsoft got tired of it, and (IIRC starting with Windows XP SP2) locked it down. Now if you have a legitimate need to use DCOM (for instance, OPC-DA), you have to jump through a series of hoops.



OPC-DA is the worst. Fortunately at least a few vendors are pushing OPC-UA (no DCOM!), but the whole industry moves like molasses.


I recently discovered the wild world of OPC and its variants and the huge community of paid middleware around it. Sure goes deep. Wrote something to pull OPC stuff into InfluxDB and then moved on with my life not having to worry about... or remember how DCOM works again. Hopefully...!


I'd forgotten all about interop with DCOM until just now! Several years ago (when I last had to do it) I recall having to horribly mess with services on my local machine just to get anything to appear to work...let alone actually knowing if it did what I wanted (consistently) and then how to get that to work at a customer site (we were told to document it and throw it over the wall to support...)


See chapter 4 of this PDF for an idea of the amount of settings you need to change to make it work: https://www.kepware.com/getattachment/04042e47-c690-467c-a93...




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: