increase in smb scans

From: Nathan W. Labadie (ab0781@wayne.edu)
Date: 03/08/02


Date: Fri, 8 Mar 2002 09:06:37 -0500
From: "Nathan W. Labadie" <ab0781@wayne.edu>
To: incidents@securityfocus.com

Has anyone else noticed a _huge_ increase in SMB scans? I'm seeing sweeps
of various subnets 5-10 times a day. This started around two weeks ago...
they appear to be looking for open \\<netbios-name>\C shares. My guess is
that there looking for machines previously infected with Nimda, but I
could be wrong. It shows up as "NETBIOS SMB C access" under snort, and
"Tree Connect AndX Request" when the tpcdump is viewed with ethereal.

-- 
Nathan W. Labadie       | ab0781@wayne.edu	
Sr. Security Specialist | 313/577.2126
Wayne State University  | 313/577.1338 fax
C&IT Information Security Office: http://security.wayne.edu

---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Re: increase in smb scans
    ... four different hosts all scanned a /24. ... or four subnets that get scanned on a semi-regular basis (as opposed to ... C&IT Information Security Office: http://security.wayne.edu ...
    (Incidents)
  • RE: To disable SMB packet and secure channel signing enforcement on Windows Server 2003-based domain
    ... I've done a lot of security assessments on Multi-Function Devices ... To disable SMB packet and secure channel signing ... If you disable the SMB signing requirement it means that all your SMB ...
    (Focus-Microsoft)
  • RE: [Full-Disclosure] Learn from history?
    ... SMB generally arent worrie about running simething like WIndows Update ... >>That does not work with the workarounds customer need to facilitate ... Block the ports BEFORE they hit the LAN. ... Proactive security. ...
    (Full-Disclosure)
  • iXsecurity.tool.smbat.0.9.3
    ... The SMB Auditing Tool is a password auditing tool for the Windows- ... against Windows 2000/XP, shows statistics up to 1200 logins/sec. ... Support for SMB over Netbios ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: ipc$ help
    ... Vulnerable for what SMB issue? ... Some will disable the require security ... when possible option only is used SMB signing will occur between Windows ... I also got dinged on the SMB vulnerability ...
    (microsoft.public.security)