Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
AuthorAll Replies

dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

reply to psloss
Re: Windows File Sharing: Facing The Mystery

said by psloss See Profile:

Do you have a cite for this?
I just tried this with Ethereal running (Win2000 to Win2000).

If I connect to a machine I have never connected to ever before, then I see a SYN to TCP/445 immediately followed by a SYN to TCP/139. Eventually, the second connection gets reset.

If I connect to a machine that I connect to often, then only the 445 connection is sent, so there's some memory in the system.

I imagine the odds are that 445 will be chosen, since (a) the 445 connection request is fractionally ahead of the 139 connection request on the wire, (b) smb-over-native involves one less layer than smb-over-nbt, so maybe the turnaround time is a little less.

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).

psloss
Premium
join:2002-02-24
Alpharetta, GA


1 edit
said by dave See Profile:

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).
In the Microsoft server-side implementations I tested, my recollection (which is going on 18 months or thereabouts, so it's fuzzy) is that the 139 connection gets reset even before the negotiate protocol SMB appeared (chronologically) in the Ethereal logs.

But I'd have to go snag the old logs to see for sure what they show; for now, it's easy enough to fire up Ethereal to take a look at a current domain and/or workgroup setup.

And it should be fairly simple to hack something together to send a SYN on 139 before 445...I'll have to try that in some spare time...

(Edit: spelling)

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org

Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Tuesday, 10-Nov 23:55:08 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [125] Moto Sold About 100,000 Droids
· [95] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [67] Government Will Release Some Telco Wiretap Lobbying Documents
· [62] Verizon's Hanging Up On Rural America
· [48] Verizon's Higher ETFs Annoy Senator
· [34] Bill Would Force ISPs To Block Financial Scams
· [32] Sprint Announces Job Cuts
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [24] Google Offers Free Holiday Airport Wi-Fi
Most people now reading
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Massive Slowdowns? [cover,1584]
· House inspector failed to find major gas leak [Home Repair & Improvement]
· Slow speed lately? [TekSavvy]
· [ Classes] ATTN Death Knights - Post your spec for critique! [World of Warcraft]
· Water heater pilot light won't light [Home Repair & Improvement]