Results 1 to 9 of 9

Thread: Netstat---Netbios

  1. #1
    Senior Member
    Join Date
    Mar 2004
    Posts
    113

    Netstat---Netbios

    Hi,

    I work for a company and today on of the machines after typing netstat -an I see that some one is connected to my machine on port 1033 the remote machine was in the same network (the machine that connected to mine) and had port 139 in use. There was no one using that machine, so i typed in the same netstat command on the remote machine, but there was no connection onto mine.

    Also when i did a nslookup on the ipaddress the machine had an alias as 21.x.x.x (i don't remember the entire ip), i did terminate the connection using tcp tools fro sysinternals, but i am not able to understand why this happened, Also the OS in win2kpro and there was nothing in the logs of event viewer. No unknown processes found.

    plaese help!!!

    MRG.

  2. #2
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Win2k boxes on a network "chatter" to each other a lot. It probably is nothing to worry about unless the IP that you are talking about doesn;t belong to your network. If that's the case I would ask:-

    1. Do you have a firewall?
    2. Do you have egress rules?
    3. Are port 135, 137, 139 & 445 blocked from both ingress and egress?
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  3. #3
    Jaded Network Admin nebulus200's Avatar
    Join Date
    Jun 2002
    Posts
    1,356

    Re: Netstat---Netbios

    Originally posted here by mrg81
    Hi,

    I work for a company and today on of the machines after typing netstat -an I see that some one is connected to my machine on port 1033 the remote machine was in the same network (the machine that connected to mine) and had port 139 in use. There was no one using that machine, so i typed in the same netstat command on the remote machine, but there was no connection onto mine.

    Also when i did a nslookup on the ipaddress the machine had an alias as 21.x.x.x (i don't remember the entire ip), i did terminate the connection using tcp tools fro sysinternals, but i am not able to understand why this happened, Also the OS in win2kpro and there was nothing in the logs of event viewer. No unknown processes found.

    plaese help!!!

    MRG.
    I think you may be a little confused about the direction. Netbios (tcp/139) was probably the destination port (especially since the other port was > 1024). What this indicates to me is that your machine attempted to do something like map a drive to the remote computer (What was the connection state? ESTABLISHED?). Did you check to make sure you were not mapping any drives? Someone could have mapped the drive and then logged out and the tcp connection may have persisted in a time-wait, or possibly the connection could have failed and therefore still be working on timing out...
    There is only one constant, one universal, it is the only real truth: causality. Action. Reaction. Cause and effect...There is no escape from it, we are forever slaves to it. Our only hope, our only peace is to understand it, to understand the 'why'. 'Why' is what separates us from them, you from me. 'Why' is the only real social power, without it you are powerless.

    (Merovingian - Matrix Reloaded)

  4. #4
    Senior Member
    Join Date
    Mar 2004
    Posts
    113
    For tiger,

    I don't have any firewalls, the only reason i am worried is because of the alias ip address that shoed up when i try to do nslookup

    for nebulus 200 , i didn't map any drives Also the connection was in the established state before i terminated the connection, one more thing there were no sessions when i went to sessions in manage in my computer.

    Also the direction was from my machine with ipaddress:1033 ----- > ipaddress:139


    MRG.

  5. #5
    Jaded Network Admin nebulus200's Avatar
    Join Date
    Jun 2002
    Posts
    1,356
    Originally posted here by mrg81
    For tiger,

    I don't have any firewalls, the only reason i am worried is because of the alias ip address that shoed up when i try to do nslookup

    for nebulus 200 , i didn't map any drives Also the connection was in the established state before i terminated the connection, one more thing there were no sessions when i went to sessions in manage in my computer.

    Also the direction was from my machine with ipaddress:1033 ----- > ipaddress:139


    MRG.
    Ugh, I am tired, now you have confused me, could you please change on of them to read 'my ip' and 'remote ip', vielen dank!~
    There is only one constant, one universal, it is the only real truth: causality. Action. Reaction. Cause and effect...There is no escape from it, we are forever slaves to it. Our only hope, our only peace is to understand it, to understand the 'why'. 'Why' is what separates us from them, you from me. 'Why' is the only real social power, without it you are powerless.

    (Merovingian - Matrix Reloaded)

  6. #6
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Ok.... Lets start by getting a firewall or firewalls for the individual computers if you can't afford a linksys or whatever. Having done that you won't have these worries in the future.
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  7. #7
    Senior Member
    Join Date
    Mar 2004
    Posts
    113
    oops! sorry the first on is myip and the second one is remote ip

    myip:1033----->remoteip:139

  8. #8
    AO Ancient: Team Leader
    Join Date
    Oct 2002
    Posts
    5,197
    Then your box connected to the remote.... Get a firewall please.....
    Don\'t SYN us.... We\'ll SYN you.....
    \"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides

  9. #9
    Jaded Network Admin nebulus200's Avatar
    Join Date
    Jun 2002
    Posts
    1,356
    I agree with Tiger, a firewall is essential in this age of the Worm. Are you the only one that uses this computer? Is it part of a workgroup or a domain? Is your AV up to date? Done a complete scan for Adware and Viruses? Something caused your computer to make that connection, and until you can figure out what did, I wouldn't trust the security of it (as a matter of fact, I would trust the security of any of the systems if you don't have a firewall).
    There is only one constant, one universal, it is the only real truth: causality. Action. Reaction. Cause and effect...There is no escape from it, we are forever slaves to it. Our only hope, our only peace is to understand it, to understand the 'why'. 'Why' is what separates us from them, you from me. 'Why' is the only real social power, without it you are powerless.

    (Merovingian - Matrix Reloaded)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •