republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
AuthorAll Replies

psloss
Premium
join:2002-02-24
Alpharetta, GA

reply to Daniel
Re: Windows File Sharing: Facing The Mystery

said by Daniel See Profile:

Old vs. New

When connecting to a Windows 2000/XP machine that has both NetBIOS over TCP and direct hosting enabled (from a client machine that's also using them), both types of connectivity will be attempted. The service responding first will be accepted and continued, i.e. if NetBIOS responds first then an RST will be sent to TCP/445, and vice versa.
Do you have a cite for this? I've seen this anecdotally, but whenever I've looked at this in a home (workgroup) environment, the CIFS client has always selected tcp/445 over tcp/139.

And again anecdotally, I can't recall seeing any of the infected systems spreading malware via Windows remote logins choosing tcp/139 over tcp/445.

(Note that in Microsoft's implementation -- NT 5.0 and up -- one can disable either 445 or 139; tcp/445 via the SMBDeviceEnabled Registry value in the NBT driver SCM parameters, and tcp/139 via the network adapter TCP/IP properties.)

It would also be interesting to see what the Samba SMB client does...

Also, the relationship between MSRPC and SMB/CIFS isn't precise -- but I think Dave is already addressing that.

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org

dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

said by psloss See Profile:

Do you have a cite for this?
I just tried this with Ethereal running (Win2000 to Win2000).

If I connect to a machine I have never connected to ever before, then I see a SYN to TCP/445 immediately followed by a SYN to TCP/139. Eventually, the second connection gets reset.

If I connect to a machine that I connect to often, then only the 445 connection is sent, so there's some memory in the system.

I imagine the odds are that 445 will be chosen, since (a) the 445 connection request is fractionally ahead of the 139 connection request on the wire, (b) smb-over-native involves one less layer than smb-over-nbt, so maybe the turnaround time is a little less.

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).

psloss
Premium
join:2002-02-24
Alpharetta, GA


1 edit
said by dave See Profile:

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).
In the Microsoft server-side implementations I tested, my recollection (which is going on 18 months or thereabouts, so it's fuzzy) is that the 139 connection gets reset even before the negotiate protocol SMB appeared (chronologically) in the Ethereal logs.

But I'd have to go snag the old logs to see for sure what they show; for now, it's easy enough to fire up Ethereal to take a look at a current domain and/or workgroup setup.

And it should be fairly simple to hack something together to send a SYN on 139 before 445...I'll have to try that in some spare time...

(Edit: spelling)

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org



Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

reply to psloss
said by psloss See Profile:

said by Daniel See Profile:

Old vs. New

When connecting to a Windows 2000/XP machine that has both NetBIOS over TCP and direct hosting enabled (from a client machine that's also using them), both types of connectivity will be attempted. The service responding first will be accepted and continued, i.e. if NetBIOS responds first then an RST will be sent to TCP/445, and vice versa.
Do you have a cite for this?
I do.

said by Microsoft See Profile:

If both the direct hosted and NBT interfaces are enabled, both methods are tried at the same time and the first to respond is used. This allows Windows to function properly with operating systems that do not support direct hosting of SMB traffic.

»support.microsoft.com/default.as···;Q204279

--
dmiessler.com - grep understanding knowledge

psloss
Premium
join:2002-02-24
Alpharetta, GA

said by Daniel See Profile:

I do.

said by Microsoft See Profile:

If both the direct hosted and NBT interfaces are enabled, both methods are tried at the same time and the first to respond is used. This allows Windows to function properly with operating systems that do not support direct hosting of SMB traffic.

»support.microsoft.com/default.as···;Q204279
Cool. Thanks. I think Dave's explanation about the sequencing of the SYNs, though, is worth noting.

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

said by psloss See Profile:

I think Dave's explanation about the sequencing of the SYNs, though, is worth noting.
Agreed.

Dave, can I include that in the piece?
--
dmiessler.com - grep understanding knowledge

dave
Premium,MVM
join:2000-05-04
not in ohio
Sure - it's hardly an innvoative piece of work!
Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Monday, 09-Nov 17:26:01 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [61] VoIP Over 3G Still Not Working For iPhone
· [41] Verizon Keeps Swinging At AT&T
· [26] Bill Would Force ISPs To Block Financial Scams
· [14] Mediacom Hints At 50, 100 Mbps Speeds
· [11] Clearwire To Get Another $1.5 Billion
· [9] 15 States Have Now Gotten Broadband Mapping Money
· [4] AT&T Launching New 7.2 Mbps 3G Modem
Most people now reading
· Divorce advice... [General Questions]
· Framed for child porn 151; by a PC virus [Security]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· My cat is reluctant to exercise. [General Questions]
· Blown out Ballasts [Home Repair & Improvement]
· Windows 7 boot manager editing questions [Microsoft Help]
· Bell disconnection fee? WTF? [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· How in the world am I going to get into college? [General Questions]
· 60 Minutes piece on cyber security last night [Security]