Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: netbios vuln

From: <Valdis.Kletnieks(at)vt.edu>
Date: Mon Dec 09 2002 - 01:58:48 EST

On Fri, 06 Dec 2002 06:50:02 PST, ohnonono@hushmail.com said:

> of netbios traffic at my main firewall. This morning I read this article. It

We were seeing on the order of 3 *million* probes/day on port 137 back at the beginning of October, thanks to Opaserv/Bugbear. And I'm sure the port 135 traffic was even higher, since the tools in use would only poke 137 if 135 answered. The joys of having 2 /16s hanging off an OC12.. ;)

It's not *that* easy to run arbitrary code directly via netbios. What usually happens is a scanning tool finds some victim who's got C:\ shared read/write to the world with no password or an Administrator password of 'password' or something equally silly. So you mount the share, copy a trojan to it, set the registry entries that say "run me at each boot" and then wait for it to reboot....

See the 'W4-NETBIOS -- Unprotected Windows Networking Shares' entry about this on the SANS Top 20:

http://www.sans.org/top20/

Do you need help?X

(And while you're there, make sure you're all square on the OTHER 19 entries too).

Disclaimer: I didn't get paid to help write the Top 20 - I just did it because the more people that fix it at their sites, the easier *my* job gets. ;)

-- 
				Valdis Kletnieks
				Computer Systems Senior Engineer
				Virginia Tech

  • application/pgp-signature attachment: stored
Received on Tue Dec 10 00:44:58 2002

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:52 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library