Are yah listening???

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Or, more aptly, is your system listening on TCP port 445???

Or 135, 136, 137, 138 or 139, for that matter???

The general consensus among the people who I was with all week this week whose names I will not mention here, is that the network traffic directed to these ports have increased dramatically over teh past few weeks.

Port 445 has now become the single most popular doorway for the people pushing the Sasser and Kongo worms.

If your answer is either a "no" or an "I don't know", you might want to read on through this discourse. I promise I will make every attempt to make it readable to any non-geek person. I will also provide some useful links which in turn have links to instructions on how to correct your systems and prevent them from become victims of Micro$oft's foolhardiness.

Once, when this Redmond-Washingon based company was entertaining some rather grandiose ideas of dominating the world Internet based on some very succinct statements from its Chairman, they had devised a method of moving data from PCs which were running their operating system without having to go through the hassles of logging in, verification, encryption, and such other seemingly unnecessary things among machines which belonged to the same people, and where trust was not at all an issue. They even gave it a name, NetBIOS. This was a time when they were touting "ease of use" over security and safeguarding of data.

For that very same reason, the highpriests of the Internet said they could not in good conscience allow this to become a routable protocol. Despite Micro$oft, and all its clout, and also the persuasiveness of Mr. Gates, and even their SoP of intimidation, threats to sue and go to court!!!

This did not make these highpriests bend over.

To this day, NetBIOS is not routable protocol. Why? Because it is a NON-routable protocol, not over any of the traditional transport mechanisms, the Internet Protocol, which is fondly referred to as IP or even IPX, which was more common in the Novell based systems architecture.

For reasons best known to themselves, perhaps to maintain this "ease of use" image among the public to whom heavens only know how many operating systems they have sold, and how many "upgrades" they have forced them to buy.

Micro$oft has continued to support NetBIOS on their platform, and not they even wrote the algorithms to use TCP wrappers so that it could be sent over IP embedded inside TCP packets, which are accepted by the Internet Protocol.

That is like saying:


Ohh, so you won't accept this bag of ammonium sulphate to send over in this train??? No problem, I'll put it in a box, seal it and write the name of the addressee on it so you can take it over.


That is called NetBIOS over TCP/IP Something like NetBIOS/TCP/IP

In order to do all this, though, some ports must be kept open, and more importantly, systems who are on the receiving ennd must be listening on these ports

So what do our friends in Redmond Washington do??? Remember now, "ease of use", don't make the customer do too much work now!!!

The ports are opened by default, and are listening??? By DEFAULT!!! This has suited some very dangerous people on the internet very weell indeed. Thank you ver much!!!

Port 445 has become THE single most popular port for people propagatiing, deliberately, the ugliest worms created ala Sasser, Kongo, and WhatHaveYou.

Watch out for yourselves, people!!! Otherwise, you will have only yourself to blame.


Here are the links I promised:





http://seclists.org/lists/incidents/2003/Mar/0010.html

http://ntsecurity.nu/papers/port445/

http://www.petri.co.il/what_is_port_445_in_w2kxp.htm

http://www.linklogger.com/TCP445.htm
 

buddy

Registered User
Forum Member
Nov 21, 2000
10,897
85
0
Pittsburgh, Pa.
KMA,

Putting it mildly, I'm a non-geek.

But I read every one of your posts and pay close attention to what you have to say.

One might ask, "why pay close attention if you don't understand what he's talking about?"

Answer - I print out your posts and show them to a friend who knows what to do.

You provide a very valuable contribution to this forum and I don't want you to think your efforts go unnoticed.

Thank you for taking the time to post.
 

Chanman

:-?PipeSmokin'
Forum Member
Great post as always KMA. I can only infer from your blatent disregard of my posts requesting personal info or pix that you see me as a dime a dozen keyboard nitwit looking for attention. That or you are playing hard to get. :confused:
 

cisco

Registered
Forum Member
Dec 1, 2000
6,360
18
0
usa/mexico
KMA-
Thanks for the tip. I went in and disabled the NetBIOS using the instructions from one of the links you posted. I just hope it doesn't screw up my computer.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Disregard Chanman??? I wasn't aware that I ever ignored a tech question of yours. *L* I'm 5' 2" with blonde hair and blue eyes, I am in school for Neuroscience. How do youplay hard to get on an internet forum???
 
Last edited:

Chanman

:-?PipeSmokin'
Forum Member
Hope I got a laugh. I just like your posts and thought your background was interesting. I was prepared to respond w/something like "Now I know what KMA stands for!" Thanks and GL2U in school. :)

(I'm 5' 2" with blonde hair and blue eyes)

P.S.- You don't have a twin in Burbank do you, Mary Kate/Ashley?
 
Last edited:

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
*LOL* My background Chanman??? So much for the disregard!!!


Thank you Cisco and RexBudler!!!
 

Chanman

:-?PipeSmokin'
Forum Member
newbie.jpg


DAMMIT! First thing in the morning and I'm owned by a woman. Oh well at least she is a neuroscience-whatever that means. Hmmmm*thinks to himself as he opens a can of beer* Wonder if Nascar is on the TV today?
 

Turfgrass

Registered User
Forum Member
Sep 26, 2002
1,153
5
0
Raleigh
I have noticed some folks here are having some virus problems with their computers. Steve Gibson has a cool web site that will probe all the ports on your computer and let you know if you are vulnerable to intruders.

Shields Up!

Link to site


First time users should start by checking their Windows File Sharing and Common Ports vulnerabilities with the "File Sharing" and "Common Ports" buttons.

Please examine the pages provided below for important background information about Internet vulnerabilities, precautions and solutions.

For orientation and information about the Port Authority system, click the Home or Help icons in the titlebar.
 
Bet on MyBookie
Top