shell bypass 403

UnknownSec Shell

C:/Windows/security/msscw/ConfigureFiles/ [ drwxrwxrwx ]

name : IndependentRoles.xml
��<?xml version="1.0" encoding="utf-16"?>

<!--Version 2.2-->

<SCWKnowledgeBase>

  <!-- 

// This file should not be modified.

// You can override the settings in this knowledge base (KB) by creating a "custom" KB.

// You can extend this knowledge base by creating an "extension" KB.

// See KBReg.xml for information on Customizing or Extending the Knowledge Base.

// Notes about editing KBs:

// 1. XML is case and whitespace sensitive - make sure your key fields match.

// 2. Do not use hyphens in key fields.

-->

  <Roles>

    <Role Status="Enabled"

          Type="Independent"

          Name="Core">

      <Selected Value="TRUE"/>

      <Services>

        <Service Name="DcomLaunch"/>

        <Service Name="RpcEptMapper" />

        <Service Name="Eventlog"/>

        <Service Name="EventSystem"/>

        <Service Name="PlugPlay"/>

        <Service Name="RpcSs"/>

        <Service Name="SamSs"/>

        <Service Name="ShellHWDetection"/>

        <Service Name="sppsvc"/>

        <Service Name="TrustedInstaller"/>

        <Service Name="vds"/>

        <Service Name="Winmgmt"/>

        <Service Name="Appinfo"/>

        <Service Name="Schedule"/>

      </Services>

    </Role>

    <Role Status="Enabled"

          Type="Independent"

          Name="SecurityandNetwork">

      <Selected Value="TRUE"/>

      <Services>

        <Service Name="CryptSvc"/>

        <Service Name="gpsvc"/>

        <Service Name="iphlpsvc"/>

        <Service Name="MpsSvc"/>

        <Service Name="ProfSvc"/>

        <Service Name="nsi"/>

        <Service Name="Netman"/>

        <Service Name="BFE"/>

        <Service Name="NlaSvc"/>

        <Service Name="netprofm"/>

        <Service Name="KeyIso"/>

        <Service Name="IKEEXT"/>

        <Service Name="Dhcp"/>

      </Services>

      <Firewall>

        <FirewallRule Id="corenet-icmp4-dufrag-in"/>

        <FirewallRule Id="corenet-icmp6-du-in"/>

        <FirewallRule Id="corenet-icmp6-ld-in"/>

        <FirewallRule Id="corenet-icmp6-ld-out"/>

        <FirewallRule Id="corenet-icmp6-lq-in"/>

        <FirewallRule Id="corenet-icmp6-lq-out"/>

        <FirewallRule Id="corenet-icmp6-lr-in"/>

        <FirewallRule Id="corenet-icmp6-lr-out"/>

        <FirewallRule Id="corenet-icmp6-lr2-in"/>

        <FirewallRule Id="corenet-icmp6-lr2-out"/>

        <FirewallRule Id="corenet-icmp6-nda-in"/>

        <FirewallRule Id="corenet-icmp6-nda-out"/>

        <FirewallRule Id="corenet-icmp6-nds-in"/>

        <FirewallRule Id="corenet-icmp6-nds-out"/>

        <FirewallRule Id="corenet-icmp6-pp-in"/>

        <FirewallRule Id="corenet-icmp6-pp-out"/>

        <FirewallRule Id="corenet-icmp6-ptb-in"/>

        <FirewallRule Id="corenet-icmp6-ptb-out"/>

        <FirewallRule Id="corenet-icmp6-ra-in"/>

        <FirewallRule Id="corenet-icmp6-ra-out"/>

        <FirewallRule Id="corenet-icmp6-rs-out"/>

        <FirewallRule Id="corenet-icmp6-te-in"/>

        <FirewallRule Id="corenet-icmp6-te-out"/>

        <FirewallRule Id="corenet-igmp-in"/>

        <FirewallRule Id="corenet-igmp-out"/>

        <FirewallRule Id="corenet-ipv6-in"/>

        <FirewallRule Id="corenet-ipv6-out"/>

        <FirewallRule Id="corenet-teredo-in"/>

        <FirewallRule Id="corenet-teredo-out"/>

        <FirewallRule Id="corenet-dhcp-in"/>

        <FirewallRule Id="corenet-dhcp-out"/>

        <FirewallRule Id="corenet-iphttps-in"/>

        <FirewallRule Id="corenet-iphttps-out"/>

      </Firewall>

    </Role>

    <Role Status="Enabled"

          Type="Independent"

          Name="Independent">

      <Selected Value="FALSE"/>

      <Services>

        <Service Name="hidserv"/>

        <Service Name="Themes"/>

        <Service Name="SysMain"/>

        <Service Name="THREADORDER"/>

      </Services>

    </Role>

  </Roles>

  <Services>

    <Service Name="Appinfo">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

    <Service Name="DcomLaunch">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="RpcEptMapper">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="Dhcp">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="Eventlog">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="EventSystem">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="IKEEXT">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

    <Service Name="KeyIso">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

    <Service Name="PlugPlay">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

    <Service Name="RpcSs">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="SamSs">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="Schedule">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="ShellHWDetection">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="sppsvc">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="THREADORDER">

      <Optional>FALSE</Optional>

      <Startup_Default>Disabled</Startup_Default>

    </Service>

    <Service Name="TrustedInstaller">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

    <Service Name="vds">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

    <Service Name="Winmgmt">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="CryptSvc">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="gpsvc">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="iphlpsvc">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="MpsSvc">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="ProfSvc">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="nsi">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="Netman">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

    <Service Name="BFE">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="NlaSvc">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="netprofm">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="hidserv">

      <Optional>FALSE</Optional>

      <Startup_Default>Disabled</Startup_Default>

    </Service>

    <Service Name="Themes">

      <Optional>FALSE</Optional>

      <Startup_Default>Automatic</Startup_Default>

    </Service>

    <Service Name="SysMain">

      <Optional>FALSE</Optional>

      <Startup_Default>Manual</Startup_Default>

    </Service>

  </Services>

  <Firewall>

    <FirewallRules>

      <FirewallRule Id="corenet-icmp4-dufrag-in"

                    Name="@firewallapi.dll,-25251"

                    Description="@firewallapi.dll,-25257"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V4"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="3"

                Code="4"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-du-in"

                    Name="@firewallapi.dll,-25110"

                    Description="@firewallapi.dll,-25112"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="1"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-ld-in"

                    Name="@firewallapi.dll,-25082"

                    Description="@firewallapi.dll,-25088"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="132"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-ld-out"

                    Name="@firewallapi.dll,-25083"

                    Description="@firewallapi.dll,-25088"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="132"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-lq-in"

                    Name="@firewallapi.dll,-25061"

                    Description="@firewallapi.dll,-25067"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="130"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-lq-out"

                    Name="@firewallapi.dll,-25062"

                    Description="@firewallapi.dll,-25067"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="130"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-lr-in"

                    Name="@firewallapi.dll,-25068"

                    Description="@firewallapi.dll,-25074"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="131"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-lr-out"

                    Name="@firewallapi.dll,-25069"

                    Description="@firewallapi.dll,-25074"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="131"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-lr2-in"

                    Name="@firewallapi.dll,-25075"

                    Description="@firewallapi.dll,-25081"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="143"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-lr2-out"

                    Name="@firewallapi.dll,-25076"

                    Description="@firewallapi.dll,-25081"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="143"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-nda-in"

                    Name="@firewallapi.dll,-25026"

                    Description="@firewallapi.dll,-25032"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="136"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-nda-out"

                    Name="@firewallapi.dll,-25027"

                    Description="@firewallapi.dll,-25032"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="136"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-nds-in"

                    Name="@firewallapi.dll,-25019"

                    Description="@firewallapi.dll,-25025"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="135"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-nds-out"

                    Name="@firewallapi.dll,-25020"

                    Description="@firewallapi.dll,-25025"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="135"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-pp-in"

                    Name="@firewallapi.dll,-25116"

                    Description="@firewallapi.dll,-25118"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="4"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-pp-out"

                    Name="@firewallapi.dll,-25117"

                    Description="@firewallapi.dll,-25118"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="4"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-ptb-in"

                    Name="@firewallapi.dll,-25001"

                    Description="@firewallapi.dll,-25007"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="2"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-ptb-out"

                    Name="@firewallapi.dll,-25002"

                    Description="@firewallapi.dll,-25007"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="2"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-ra-in"

                    Name="@firewallapi.dll,-25012"

                    Description="@firewallapi.dll,-25018"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="134"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-ra-out"

                    Name="@firewallapi.dll,-25013"

                    Description="@firewallapi.dll,-25018"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="134"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-rs-out"

                    Name="@firewallapi.dll,-25008"

                    Description="@firewallapi.dll,-25011"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <RemoteAddresses DefaultGateway="False"

                         WINSServers="False"

                         DHCPServers="False"

                         DNSServers="False"

                         LocalSubnet="True"/>

        <ICMPs>

          <ICMP Type="133"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-te-in"

                    Name="@firewallapi.dll,-25113"

                    Description="@firewallapi.dll,-25115"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="3"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-icmp6-te-out"

                    Name="@firewallapi.dll,-25114"

                    Description="@firewallapi.dll,-25115"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="ICMP_V6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <ICMPs>

          <ICMP Type="3"

                Code="*"/>

        </ICMPs>

      </FirewallRule>

      <FirewallRule Id="corenet-igmp-in"

                    Name="@firewallapi.dll,-25376"

                    Description="@firewallapi.dll,-25382"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="IGMP"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections"/>

      <FirewallRule Id="corenet-igmp-out"

                    Name="@firewallapi.dll,-25377"

                    Description="@firewallapi.dll,-25382"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="IGMP"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections"/>

      <FirewallRule Id="corenet-ipv6-in"

                    Name="@firewallapi.dll,-25351"

                    Description="@firewallapi.dll,-25357"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="IPV6"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections"/>

      <FirewallRule Id="corenet-ipv6-out"

                    Name="@firewallapi.dll,-25352"

                    Description="@firewallapi.dll,-25358"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="IPV6"

                    Direction="Outbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections"/>

      <FirewallRule Id="corenet-teredo-in"

                    Name="@firewallapi.dll,-25326"

                    Description="@firewallapi.dll,-25332"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="UDP"

                    Direction="Inbound"

                    Program="%systemroot%\system32\svchost.exe"

                    Service="iphlpsvc"

                    Enabled="True"

                    Action="AllowConnections">

        <LocalPorts>

          <Port Value="0"/>

        </LocalPorts>

      </FirewallRule>

      <FirewallRule Id="corenet-teredo-out"

                    Name="@firewallapi.dll,-25327"

                    Description="@firewallapi.dll,-25333"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="UDP"

                    Direction="Outbound"

                    Program="%systemroot%\system32\svchost.exe"

                    Service="iphlpsvc"

                    Enabled="True"

                    Action="AllowConnections"/>

      <FirewallRule Id="corenet-dhcp-in"

                    Name="@firewallapi.dll,-25301"

                    Description="@firewallapi.dll,-25303"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="UDP"

                    Direction="Inbound"

                    Program="%systemroot%\system32\svchost.exe"

                    Service="dhcp"

                    Enabled="True"

                    Action="AllowConnections">

        <LocalPorts>

          <Port Value="68"/>

        </LocalPorts>

        <RemotePorts>

          <Port Value="67"/>

        </RemotePorts>

      </FirewallRule>

      <FirewallRule Id="corenet-dhcp-out"

                    Name="@firewallapi.dll,-25302"

                    Description="@firewallapi.dll,-25303"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="UDP"

                    Direction="Outbound"

                    Program="%systemroot%\system32\svchost.exe"

                    Service="dhcp"

                    Enabled="True"

                    Action="AllowConnections">

        <LocalPorts>

          <Port Value="68"/>

        </LocalPorts>

        <RemotePorts>

          <Port Value="67"/>

        </RemotePorts>

      </FirewallRule>

      <FirewallRule Id="corenet-iphttps-in"

                    Name="@firewallapi.dll,-25426"

                    Description="@firewallapi.dll,-25428"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="TCP"

                    Direction="Inbound"

                    Program="system"

                    Enabled="True"

                    Action="AllowConnections">

        <LocalPorts SpecialPorts="IPTLSIn"/>

      </FirewallRule>

      <FirewallRule Id="corenet-iphttps-out"

                    Name="@firewallapi.dll,-25427"

                    Description="@firewallapi.dll,-25429"

                    Group="@firewallapi.dll,-25000"

                    ProtocolKeyword="TCP"

                    Direction="Outbound"

                    Program="%SystemRoot%\system32\svchost.exe"

                    Service="iphlpsvc"

                    Enabled="True"

                    Action="AllowConnections">

        <RemotePorts SpecialPorts="IPTLSOut"/>

      </FirewallRule>

    </FirewallRules>

  </Firewall>

</SCWKnowledgeBase>


© 2026 UnknownSec