republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
psloss
Premium
join:2002-02-24
Alpharetta, GA

Re: Windows File Sharing: Facing The Mystery

said by Daniel See Profile:

Old vs. New

When connecting to a Windows 2000/XP machine that has both NetBIOS over TCP and direct hosting enabled (from a client machine that's also using them), both types of connectivity will be attempted. The service responding first will be accepted and continued, i.e. if NetBIOS responds first then an RST will be sent to TCP/445, and vice versa.
Do you have a cite for this? I've seen this anecdotally, but whenever I've looked at this in a home (workgroup) environment, the CIFS client has always selected tcp/445 over tcp/139.

And again anecdotally, I can't recall seeing any of the infected systems spreading malware via Windows remote logins choosing tcp/139 over tcp/445.

(Note that in Microsoft's implementation -- NT 5.0 and up -- one can disable either 445 or 139; tcp/445 via the SMBDeviceEnabled Registry value in the NBT driver SCM parameters, and tcp/139 via the network adapter TCP/IP properties.)

It would also be interesting to see what the Samba SMB client does...

Also, the relationship between MSRPC and SMB/CIFS isn't precise -- but I think Dave is already addressing that.

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org
dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

Re: Windows File Sharing: Facing The Mystery

said by psloss See Profile:

Do you have a cite for this?
I just tried this with Ethereal running (Win2000 to Win2000).

If I connect to a machine I have never connected to ever before, then I see a SYN to TCP/445 immediately followed by a SYN to TCP/139. Eventually, the second connection gets reset.

If I connect to a machine that I connect to often, then only the 445 connection is sent, so there's some memory in the system.

I imagine the odds are that 445 will be chosen, since (a) the 445 connection request is fractionally ahead of the 139 connection request on the wire, (b) smb-over-native involves one less layer than smb-over-nbt, so maybe the turnaround time is a little less.

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).
psloss
Premium
join:2002-02-24
Alpharetta, GA


1 edit

Re: Windows File Sharing: Facing The Mystery

said by dave See Profile:

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).
In the Microsoft server-side implementations I tested, my recollection (which is going on 18 months or thereabouts, so it's fuzzy) is that the 139 connection gets reset even before the negotiate protocol SMB appeared (chronologically) in the Ethereal logs.

But I'd have to go snag the old logs to see for sure what they show; for now, it's easy enough to fire up Ethereal to take a look at a current domain and/or workgroup setup.

And it should be fairly simple to hack something together to send a SYN on 139 before 445...I'll have to try that in some spare time...

(Edit: spelling)

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

said by psloss See Profile:

said by Daniel See Profile:

Old vs. New

When connecting to a Windows 2000/XP machine that has both NetBIOS over TCP and direct hosting enabled (from a client machine that's also using them), both types of connectivity will be attempted. The service responding first will be accepted and continued, i.e. if NetBIOS responds first then an RST will be sent to TCP/445, and vice versa.
Do you have a cite for this?
I do.

said by Microsoft See Profile:

If both the direct hosted and NBT interfaces are enabled, both methods are tried at the same time and the first to respond is used. This allows Windows to function properly with operating systems that do not support direct hosting of SMB traffic.

»support.microsoft.com/default.as···;Q204279

--
dmiessler.com - grep understanding knowledge
psloss
Premium
join:2002-02-24
Alpharetta, GA

Re: Windows File Sharing: Facing The Mystery

said by Daniel See Profile:

I do.

said by Microsoft See Profile:

If both the direct hosted and NBT interfaces are enabled, both methods are tried at the same time and the first to respond is used. This allows Windows to function properly with operating systems that do not support direct hosting of SMB traffic.

»support.microsoft.com/default.as···;Q204279
Cool. Thanks. I think Dave's explanation about the sequencing of the SYNs, though, is worth noting.

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org

Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

Re: Windows File Sharing: Facing The Mystery

said by psloss See Profile:

I think Dave's explanation about the sequencing of the SYNs, though, is worth noting.
Agreed.

Dave, can I include that in the piece?
--
dmiessler.com - grep understanding knowledge
dave
Premium,MVM
join:2000-05-04
not in ohio

Re: Windows File Sharing: Facing The Mystery

Sure - it's hardly an innvoative piece of work!
Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Friday, 04-Dec 18:35:33 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [124] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [81] FCC Ponders Moving From PSTN To IP Voice
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
· [64] Broadband Killed The Game Console
Most people now reading
· False positive in Avast! or is it real? [Security]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· I finally jumped off the Windows ship! [All Things Macintosh]
· Linux is terrorist - according to MS... [All Things Unix]
· How happy are you with your current ISP? [General Questions]
· DNS options, what are YOU using? [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [Unlock] TUTORIAL: VONAGE WRTP54G/RTP300 WITH 5.01.04 [VOIP Tech Chat]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]