how to shut off netbios-ns/port:137 (udp)

From: Alex Fitterling (Alex.Fitterling_at_gmx.net)
Date: 06/03/03


Date: Tue, 03 Jun 2003 15:42:34 +0200


Dear Microsoft Users,

when scanning certain win2k-clients in my network with the opensource
security tool nessus, I get following security warning:

---
Warning netbios-ns (137/udp) . The following 2 NetBIOS names have been
gathered : NAME = Computer 1) name that is registered for the
messenger service on a computer that is a WINS client.  BENUTZER1 =
Computer name that is registered for the messenger service on a
computer that is a WINS client.  . The remote host has the following
MAC address on its adapter : XXXXXXXXXXXXXXXXXXX 1)
If you do not want to allow everyone to find the NetBios name
of your computer, you should filter incoming traffic to this port.
Risk factor : Medium
CVE : CAN-1999-0621
Nessus ID : 10150
1) due to security reasons the values has been made irrecognizable.
----
I definitely want to deactivate the whole port, not allowing the
clients to share anything on net. Is there a way to reach this, or
could that (only microsoft knows) for any reason be dangerous?
So far I took a look in certain newsgroups. There were actually a
whole bunch of inquiries I myself wasn't able to deal with. So this is
my own posting.
Sincerely,
Alex


Relevant Pages

  • Re: how to shut off netbios-ns/port:137 (udp)
    ... m/freeDownload.jsp Actually the built in security policy ... is capable of blocking netbios attacks but as the previous ... Settings -> Security Settings. ... security rule consists of two key components: an IP filter ...
    (microsoft.public.security)
  • Re: Defeating information bars/security warnings in links from Pow
    ... Well, as far as I'm concerned, it's kind of like talking to a brick wall when it comes to Microsoft and "security," but a couple of the MVPs are masochists and keep trying. ... What's new in PowerPoint 2007? ... does work, however, so I'm just going to quickly trigger the security warning ... > the file now opens without the Information bar and its attendant> security ...
    (microsoft.public.powerpoint)
  • Re: How Important Is NetBIOS
    ... ZA's "security levels" or whatever they're called blocks ... off these ports on the internet side if set properly. ... router with a firewall that is already doing this. ... > I can trace back to programs, but I was wondering about how useful NetBIOS ...
    (comp.security.firewalls)
  • Re: Apparent NetBIOS Attack - How Dangerous?
    ... so it seems that IPSec's 'firewall' is working. ... I will read the NSA security configuration guides. ... NetBIOS problem seeems to be taken care of. ... > for XP and 2003 you use RestrictAnonymous and RestrictAnonymousSAM, ...
    (microsoft.public.win2000.security)
  • [NT] Circumvent Windows XP SP2 Security Features using execCommand SaveAs Function
    ... Get your security news from a reliable source. ... Bypasses the "File Download - Security Warning". ... will trigger a 404 error message as defined above. ...
    (Securiteam)