MSRPC Fault for IRemoteSCMActivator

G

Guest

I'm using the WMI Object Browser from the Windows Management Instrumentation
Tools to view the objects in a remote computers CIMv2.

Of course, I ran into the usual Windows Firewall, DCOM and Security problems
that plague us but rather than blindly turning off the firewall, I've been
working on opening a port at a time.

Now, I'm not using the Remote Desktop or Remote Assitance or File and Print
Sharing exceptions. This is a XPSP2 Windows Firewall turned on initially with
no exceptions, and then opening ports as I go along.

Unfortunately, I've hit a stumbling block with my last test. Here is the
capture from MS Network Monitor 3.1 between my PC and the remote PC I wish to
remotely examine CIMv2 on.

62 8.189453 192.168.0.60 192.168.0.204 TCP TCP: Flags=.S......,
SrcPort=2670, DstPort=DCE endpoint resolution(135), Len=0, Seq=317471127,
Ack=0, Win=65535 (scale factor not found)
63 8.189453 192.168.0.204 192.168.0.60 TCP TCP: Flags=.S..A..., SrcPort=DCE
endpoint resolution(135), DstPort=2670, Len=0, Seq=3912905986, Ack=317471128,
Win=65535 (scale factor not found)
64 8.189453 192.168.0.60 192.168.0.204 TCP TCP: Flags=....A...,
SrcPort=2670, DstPort=DCE endpoint resolution(135), Len=0, Seq=317471128,
Ack=3912905987, Win=65535 (scale factor not found)
65 8.190430 192.168.0.60 192.168.0.204 MSRPC MSRPC: c/o Bind:
UUID{99FCFEC4-5260-101B-BBCB-00AA0021347A} DCOM-IObjectExporter Call=0x1
Assoc Grp=0x0 Xmit=0x16D0 Recv=0x16D0
66 8.190430 192.168.0.204 192.168.0.60 MSRPC MSRPC: c/o Bind Ack: Call=0x1
Assoc Grp=0x5592 Xmit=0x16D0 Recv=0x16D0
67 8.190430 192.168.0.60 192.168.0.204 MSRPC MSRPC: c/o Request: unknown
Call=0x1 Opnum=0x5 Context=0x0 Hint=0x0
68 8.190430 192.168.0.204 192.168.0.60 MSRPC MSRPC: c/o Response: unknown
Call=0x1 Context=0x0 Hint=0x74 Cancels=0x0
69 8.191406 192.168.0.60 192.168.0.204 TCP TCP: Flags=.S......,
SrcPort=2671, DstPort=DCE endpoint resolution(135), Len=0, Seq=971372815,
Ack=0, Win=65535 (scale factor not found)
70 8.191406 192.168.0.204 192.168.0.60 TCP TCP: Flags=.S..A..., SrcPort=DCE
endpoint resolution(135), DstPort=2671, Len=0, Seq=1680589981, Ack=971372816,
Win=65535 (scale factor not found)
71 8.191406 192.168.0.60 192.168.0.204 TCP TCP: Flags=....A...,
SrcPort=2671, DstPort=DCE endpoint resolution(135), Len=0, Seq=971372816,
Ack=1680589982, Win=65535 (scale factor not found)
72 8.191406 192.168.0.60 192.168.0.204 MSRPC MSRPC: c/o Bind:
UUID{000001A0-0000-0000-C000-000000000046} DCOM-IRemoteSCMActivator Call=0x2
Assoc Grp=0x5592 Xmit=0x16D0 Recv=0x16D0
73 8.191406 192.168.0.60 192.168.0.204 TCP TCP: Flags=...PA...,
SrcPort=2671, DstPort=DCE endpoint resolution(135), Len=36, Seq=971374276 -
971374312, Ack=1680589982, Win=65535 (scale factor not found)
74 8.192383 192.168.0.204 192.168.0.60 TCP TCP: Flags=....A..., SrcPort=DCE
endpoint resolution(135), DstPort=2671, Len=0, Seq=1680589982, Ack=971374312,
Win=65535 (scale factor not found)
76 8.248047 192.168.0.204 192.168.0.60 MSRPC MSRPC: c/o Bind Ack: Call=0x2
Assoc Grp=0x5592 Xmit=0x16D0 Recv=0x16D0
77 8.248047 192.168.0.60 192.168.0.204 MSRPC MSRPC: c/o Alter Cont:
UUID{000001A0-0000-0000-C000-000000000046} DCOM-IRemoteSCMActivator Call=0x2
80 8.255859 192.168.0.204 192.168.0.60 MSRPC MSRPC: c/o Alter Cont Resp:
Call=0x2 Assoc Grp=0x5592 Xmit=0x16D0 Recv=0x16D0
81 8.255859 192.168.0.60 192.168.0.204 MSRPC MSRPC: c/o Request: unknown
Call=0x2 Opnum=0x4 Context=0x1 Hint=0x310
82 8.329102 192.168.0.60 192.168.0.204 TCP TCP: Flags=....A...,
SrcPort=2670, DstPort=DCE endpoint resolution(135), Len=0, Seq=317471224,
Ack=3912906187, Win=65335 (scale factor not found)
83 8.352539 192.168.0.204 192.168.0.60 MSRPC MSRPC: c/o Response: unknown
Call=0x2 Context=0x1 Hint=0x10 Cancels=0x0
84 8.356445 192.168.0.60 192.168.0.204 TCP TCP: Flags=.S......,
SrcPort=2672, DstPort=DCE endpoint resolution(135), Len=0, Seq=2887003844,
Ack=0, Win=65535 (scale factor not found)
85 8.356445 192.168.0.204 192.168.0.60 TCP TCP: Flags=.S..A..., SrcPort=DCE
endpoint resolution(135), DstPort=2672, Len=0, Seq=3406163168,
Ack=2887003845, Win=65535 (scale factor not found)
86 8.356445 192.168.0.60 192.168.0.204 TCP TCP: Flags=....A...,
SrcPort=2672, DstPort=DCE endpoint resolution(135), Len=0, Seq=2887003845,
Ack=3406163169, Win=65535 (scale factor not found)
87 8.356445 192.168.0.60 192.168.0.204 MSRPC MSRPC: c/o Bind:
UUID{000001A0-0000-0000-C000-000000000046} DCOM-IRemoteSCMActivator Call=0x3
Assoc Grp=0x5592 Xmit=0x16D0 Recv=0x16D0
88 8.356445 192.168.0.204 192.168.0.60 MSRPC MSRPC: c/o Bind Ack: Call=0x3
Assoc Grp=0x5592 Xmit=0x16D0 Recv=0x16D0
89 8.356445 192.168.0.60 192.168.0.204 MSRPC MSRPC: c/o Request: unknown
Call=0x3 Opnum=0x4 Context=0x1 Hint=0x310
90 8.357422 192.168.0.204 192.168.0.60 MSRPC MSRPC: c/o Fault: Call=0x3
Context=0x1 Status=0x5 Cancels=0x0
91 8.357422 192.168.0.204 192.168.0.60 TCP TCP: Flags=F...A..., SrcPort=DCE
endpoint resolution(135), DstPort=2672, Len=0, Seq=3406163261,
Ack=2887004725, Win=64655 (scale factor not found)
92 8.357422 192.168.0.60 192.168.0.204 TCP TCP: Flags=....A...,
SrcPort=2672, DstPort=DCE endpoint resolution(135), Len=0, Seq=2887004725,
Ack=3406163262, Win=65443 (scale factor not found)
93 8.357422 192.168.0.60 192.168.0.204 TCP TCP: Flags=F...A...,
SrcPort=2672, DstPort=DCE endpoint resolution(135), Len=0, Seq=2887004725,
Ack=3406163262, Win=65443 (scale factor not found)
94 8.357422 192.168.0.204 192.168.0.60 TCP TCP: Flags=....A..., SrcPort=DCE
endpoint resolution(135), DstPort=2672, Len=0, Seq=3406163262,
Ack=2887004726, Win=64655 (scale factor not found)
96 8.530274 192.168.0.60 192.168.0.204 TCP TCP: Flags=....A...,
SrcPort=2671, DstPort=DCE endpoint resolution(135), Len=0, Seq=971375309,
Ack=1680590308, Win=65209 (scale factor not found)

The problem seems to be the last MSRPC conversation, which is the Bind to
DCOM-IRemoteSCMActivator using Call 0x3. The remote PC returns a Fault status.

Anyone know what might cause this?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top