Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

Re: Windows File Sharing: Facing The Mystery

said by psloss See Profile:

Do you have a cite for this?
I just tried this with Ethereal running (Win2000 to Win2000).

If I connect to a machine I have never connected to ever before, then I see a SYN to TCP/445 immediately followed by a SYN to TCP/139. Eventually, the second connection gets reset.

If I connect to a machine that I connect to often, then only the 445 connection is sent, so there's some memory in the system.

I imagine the odds are that 445 will be chosen, since (a) the 445 connection request is fractionally ahead of the 139 connection request on the wire, (b) smb-over-native involves one less layer than smb-over-nbt, so maybe the turnaround time is a little less.

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).
psloss
Premium
join:2002-02-24
Alpharetta, GA


1 edit

Re: Windows File Sharing: Facing The Mystery

said by dave See Profile:

(I didn't pay close attention to looking at how far the 445 connection setup had to proceed -- there are several SMBs needed for complete connection setup after the TCP connection is ready -- before the 139 connection was abandoned).
In the Microsoft server-side implementations I tested, my recollection (which is going on 18 months or thereabouts, so it's fuzzy) is that the 139 connection gets reset even before the negotiate protocol SMB appeared (chronologically) in the Ethereal logs.

But I'd have to go snag the old logs to see for sure what they show; for now, it's easy enough to fire up Ethereal to take a look at a current domain and/or workgroup setup.

And it should be fairly simple to hack something together to send a SYN on 139 before 445...I'll have to try that in some spare time...

(Edit: spelling)

Philip Sloss
--
Feedback? e-mail: stuff@lupwa.org

Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Tuesday, 01-Dec 06:09:05 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [60] Baltimore To Ban Lazy Cable Installs
· [48] Broadband Killed The Game Console
· [36] Rural Carriers Quickly Embracing Fiber
· [31] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [25] Charter Exits Chapter 11
· [22] Midcontinent Socked With Easement Lawsuit
· [4] Monday Evening Links
· [3] Monday Morning Links
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [Rant] called out sick! [Rants, Raves, and Praise]
· [Newsgroups] Newzleech down? [Filesharing Software]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· persistent connection to qw-in-f113.1e100.net on boot [Security]