Why does XP establish HTTP connection when browsing network shares?
From: o00o_j (o00o_j@yahoo.com)Date: 05/24/02
- Previous message: Thad Horak: "Wingate Replacement"
- Next in thread: Dave Feustel: "Re: Why does XP establish HTTP connection when browsing network shares?"
- Reply: Dave Feustel: "Re: Why does XP establish HTTP connection when browsing network shares?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 24 May 2002 12:13:49 -0700 (PDT) From: o00o_j <o00o_j@yahoo.com> To: focus-ms@securityfocus.com
I've noticed some strange behavior from our IDS. Ever since deploying
Windows XP to our network, I've been seeing connection attempts to port 80
on servers not running HTTP daemons. Taking a closer look, I discovered
darn near every one was from a windows XP machine belonging to techs who
service those servers. I left it as a curiosity until one day, by chance,
I noticed my machine triggered the same IDS alarm right after I opened a
network share (C$) on that machine.
Digging down further, I captured a TCP conversation between my PC (an XP
machine) and a server. Sure enough, towards the end of all the SMB jargon
is an HTTP exchange, with my client at one point sending the following:
--- OPTIONS / HTTP/1.1 translate: f User-Agent: Microsoft-WebDAV-MiniRedir/5.1.2600 Host: [NetBIOS name of host i'm trying to connect to] --- and receiving back a canned warning from my IDS. I'm sure this is nothing to worry about, however I'm concerned about disabling it to limit false positives on my IDS. Any ideas? thoughts? Any info. would help here... our XP guru in-house had never heard of this before. thanks in advance.-j
__________________________________________________ Do You Yahoo!? LAUNCH - Your Yahoo! Music Experience http://launch.yahoo.com
- Previous message: Thad Horak: "Wingate Replacement"
- Next in thread: Dave Feustel: "Re: Why does XP establish HTTP connection when browsing network shares?"
- Reply: Dave Feustel: "Re: Why does XP establish HTTP connection when browsing network shares?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|