UDP Port 137 Question

From: John Smithson (why1234_at_hotmail.com)
Date: 01/20/04

  • Next message: Steve Frank: "Re: Dumb question abt. Wireless WEP security"
    To: security-basics@securityfocus.com
    Date: Tue, 20 Jan 2004 12:16:22 -0800
    
    

    Gurus,

    I have couple of servers that are constantly trying to go outbound on UDP
    Port 137 (Nbname). The event is occurring 4-5 times per second. All
    outbound traffic is being dropped by my firewall. However, I am just trying
    to find out what is the reason -

    I have AV on the server with latest definition - I have ran manual AV Scan -
    I have ran Welchia / Nimda / etc removal tool - I have ran Spyware removal
    tool - All of them comes up clean. The outbound address are for example:
    156.67.52.182 to 156.67.52.204 --- 9.108.180.138-154 -- 145.46.77.202-241 -
    There are more of these network ranges ( I have already done whois on all
    these IP range)

    Oh yeah - the servers are Win2k with SP3 or Win2k with SP4 with latest HF.

    Please help me to isolate what I am facing? This should not be a normal
    Traffic Pattern, since only couple of my servers are producing this traffic

    TIA

    _________________________________________________________________
    Let the new MSN Premium Internet Software make the most of your high-speed
    experience. http://join.msn.com/?pgmarket=en-us&page=byoa/prem&ST=1

    ---------------------------------------------------------------------------
    Ethical Hacking at InfoSec Institute. Mention this ad and get $720 off any
    course! All of our class sizes are guaranteed to be 10 students or less.
    We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention,
    and many other technical hands on courses.
    Visit us at http://www.infosecinstitute.com/securityfocus to get $720 off
    any course!
    ----------------------------------------------------------------------------


  • Next message: Steve Frank: "Re: Dumb question abt. Wireless WEP security"

    Relevant Pages

    • Re: UDP Port 137 Question
      ... I have couple of servers that are constantly trying to go outbound on UDP ... There are more of these network ranges (I have already done whois on all ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion Prevention, ...
      (Security-Basics)
    • RE: UDP Port 137 Question
      ... Subject: UDP Port 137 Question ... I have couple of servers that are constantly trying to go outbound on ... All outbound traffic is being dropped by my firewall. ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ...
      (Security-Basics)
    • RE: antivirus software for DMS computers???
      ... Say you're running an Web+FTP server in your DMZ... ... > All of my servers in the DMZ have AV protection. ... > Ethical Hacking at the InfoSec Institute. ... > pen testing experience in our state of the art hacking lab. ...
      (Security-Basics)
    • Re: Question about outbound rules and security
      ... What I meant was that if you have an access rule - say allowing http trafic from 'inside' to 'outside', only trafic initiated from the 'inside' network is allowed. ... Outbound means that clients (and servers acting as clients) can initiate ...
      (microsoft.public.isa.configuration)
    • Re: UDP Port 137 Question
      ... If you unclick the check boxes to use Netbios for name resolution on the ... servers that are doing this, ... We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ...
      (Security-Basics)