Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
AuthorAll Replies


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

reply to dave
Re: Windows File Sharing: Facing The Mystery

said by dave See Profile:

A good summary. I have a couple of technical nits to pick, thoguh.
NetBIOS using these ports was benign enough initially because they were bound to a protocol called Netbeui.
A little confusion here.

You listed some TCP and UDP ports. Netbeui does not use TCP or UDP ports. When MS Networking (SMB) is using Netbeui, no TCP or UDP ports are involved.
Heh, that's not a "little confusion", that's gross error. Thanks for catching that; it was late.

Netbeui is in fact "portless", just like AH, ESP, and most other protocols aside from 06 and 17.

said by dave See Profile:

Also, I wouldn't describe port 135 as being used by Windows File Sharing at all. It's the RPC endpoint mapper, which does not use Windows File Sharing protocols. RPC is not SMB.
Very true, and I covered port 135's role when I described each port. Perhaps I should make the distinction a bit clearer, however.

said by dave See Profile:

As far as I am aware, RPC endpoint mapping does not use port 445.
I think it does, actually. Take for example this advisory by CERT where they advocate the following:

said by CERT:

Using a network or host-based firewall, block RPC network traffic (ports 135/tcp, 139/tcp, 445/tcp, 593/tcp and 135/udp, 137/udp, 138/udp, 445/udp).

»www.kb.cert.org/vuls/id/547820
Thanks so much for your comments, Dave, and everyone else's too. This forum just rocks because of the ability for people to bring content here and get it looked at without the negativity associated with many other venues.
--
dmiessler.com - grep understanding knowledge
Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Friday, 04-Dec 05:39:46 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [142] Avast Antivirus Has Gone Mad
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [103] Comcast Makes NBC Universal Acquisition Official
· [85] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [66] Sprint Defuses GPS Privacy Media Bomb
· [64] Broadband Killed The Game Console
· [61] FCC Ponders Moving From PSTN To IP Voice
Most people now reading
· False positive in Avast! or is it real? [Security]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Warrior tank seem underpowered these days [World of Warcraft]
· Acer 22" wide screen LCD monitor $139 [Canadian Chat]
· [Config] cisco asa 5505 with multiple outside IP addresses [Cisco]
· Usenet Services- Clarification [TekSavvy]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Linux is terrorist - according to MS... [All Things Unix]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]