Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Security Incidents mailing list archives

Re: Port 445 increase?
From: Brian Collins <bcollins () newnanutilities org>
Date: Tue, 04 Jun 2002 12:50:48 -0400


NetBIOS over TCP traditionally uses the following ports:

nbname 137/UDP
nbname 137/TCP
nbdatagram 138/UDP
nbsession 139/TCP

Direct hosted "NetBIOS-less" SMB traffic uses the following port:

MICROSOFT-DS 445/TCP
MICROSOFT-DS 445/UDP

Looks like you're being scanned for open shares (the usual), but the scanner/worm/potential intruder now knows about "NeBIOS-less" SMB traffic port too.

This could be a DoS Attack on port 445 too, see http://www.vnunet.com/News/1131065 but i doubt that since you said It was followed by nbname lookup, so It's probably looking for openshares.

And, if I remember correctly, port 445 is specifically related to Win2k and XP.


Brian Collins
Systems Administrator
Newnan Utilities


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]