RE: Using Messenger Service for 'Net Send' Functionality --- Dangerous?Why?

From: Kern, Tom (tkern_at_CHARMER.COM)
Date: 06/24/05

  • Next message: David LeBlanc: "RE: WSUS/Reboot"
    Date: Fri, 24 Jun 2005 16:20:29 -0400
    To: "Jim Harrison (ISA)" <jmharr@microsoft.com>, "Thor (Hammer of God)" <thor@hammerofgod.com>
    
    

    why do you need netbios for file transfer?
    smb/cifs operates over tcp/ip on port 445(which i would NEVER open to the outside world), it doesn't need netbios. For name resolution use an ip or a fqdn.

    Jim Harrison (ISA) wrote:
    > I've spoken to quite a few folks that believe allowing NetBIOS across
    > your firewall is perfectly reasonable for file transfer functionality.
    > I clearly don't agree with this proposition, but because SSH/FTPS is
    > "unfamiliar", it's what they wanted.
    >
    > Jim Harrison
    > Security Business Unit (ISA SE)
    > "When you come to a fork in the road, take it."
    > --Yogi Berra
    >
    >
    > -----Original Message-----
    > From: Thor (Hammer of God) [mailto:thor@hammerofgod.com]
    > Sent: Friday, June 24, 2005 8:38 AM
    > To: Jesse Weigert; Nick Duda
    > Cc: focus-ms@securityfocus.com
    > Subject: Re: Using Messenger Service for 'Net Send' Functionality ---
    > Dangerous?Why?
    >
    > "Net send" first tries a netbios connection to deliver the message,
    > and will
    > then attempt delivery via UDP 135 (the endpoint mapper.)
    >
    > There is no functional reason why a firewall should be allowing
    > netbios/f&p
    > traffic or UDP135 into your network.
    >
    > T
    >
    > ------
    > *Secure your infrastructure*
    > Microsoft Ninjitsu: Securely Deploying MS Technologies
    > security training delivered by Timothy Mullen.
    > Registration now open for Blackhat Vegas 2005:
    > http://www.blackhat.com/html/bh-usa-05/train-bh-usa-05-tm.html
    >
    >
    >
    >
    >
    >
    >
    >
    > ----- Original Message -----
    > From: "Jesse Weigert" <weigert@gravitec.com>
    > To: "Nick Duda" <nduda@VistaPrint.com>
    > Cc: <kurt.buff@gmail.com>; <michael.mailinglist@securityfocus.com>;
    > "at"
    >
    > <gmail.com@securityfocus.com>; <focus-ms@securityfocus.com>
    > Sent: Thursday, June 23, 2005 8:33 PM
    > Subject: Re: Using Messenger Service for 'Net Send' Functionality ---
    > Dangerous?Why?
    >
    >
    >> I would like to add that there is malware which does just this.
    >> Which is why sometimes even blocking the service at the firewall
    >> doesn't stop the messenger spam.
    >>
    >> Nick Duda wrote:
    >>> FYI, It's very easy to write a short VB app that:
    >>>
    >>> A. doesn't record net sends to event viewer
    >>> B. can spoof the sending name of the computer (NetBIOS)
    >>>
    >>> - Nick
    >
    >
    > ------------------------------------------------------------------------
    > ---
    > ------------------------------------------------------------------------
    > ---
    >
    >
    > ---------------------------------------------------------------------------
    > ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: David LeBlanc: "RE: WSUS/Reboot"

    Relevant Pages

    • RE: Patching a Firewall
      ... NetBIOS has been disabled, since the shares don't exist without NetBIOS. ... In my opinion the OS used for a firewall is not really a big deal, ... need to hack the registry to turn off the administrative shares. ... >>Captus Networks ...
      (Security-Basics)
    • Re: grc.com news server down?
      ... etc.) were a real problem a few years ago. ... There's no doubt that implementing wide ranging and sound security ... He said there was no danger in leaving NetBIOS enabled, ... My ISP wouldn't allow a router, but they did permit a "firewall". ...
      (comp.security.firewalls)
    • Re: Apparent NetBIOS Attack - How Dangerous?
      ... so it seems that IPSec's 'firewall' is working. ... I will read the NSA security configuration guides. ... NetBIOS problem seeems to be taken care of. ... > for XP and 2003 you use RestrictAnonymous and RestrictAnonymousSAM, ...
      (microsoft.public.win2000.security)
    • RE: Patching a Firewall
      ... NetBIOS and stopping the services you aren't using. ... It is difficult and intricate to harden a Windows box sufficiently to ... Any changes made to the firewall ... >>Captus Networks ...
      (Security-Basics)
    • Re: cannot connect two win2k computers
      ... > First those (NetBIOS) names are suspicious but seem to be legal. ... > ping and are on the same subnet ... > and leads us back to name resolution. ... > one that fails) is running a Firewall and has thereby ...
      (microsoft.public.win2000.networking)