TCP port 139 attacks include:
- Reconnaissance
- Access
- Dos
The following are NetBIOS Attack
signatures: 
- 3300—NETBIOS OOB data (severity 5,
DoS): This signature is triggered when an attempt to send Out Of
Band data to port 139 is detected. This can be used to crash
Windows machines.
- 3301—NETBIOS Stat (severity 1,
information): This signature is triggered when NBTSTAT is used.
The Windows NT called "NBTSTAT" is used to display
protocol statistics and current TCP/IP connections using NetBIOS.
This application can be used to list a remote machines name table.
This tool allows an intruder to determine legitimate user names,
the Windows Domain or Workgroup name, and many other facts useful
in attacking a Windows network. There are UNIX tools available
that perform the same function as NBTSTAT.
- 3302—NETBIOS Session Setup Failure
(severity 1, information/access): When a client connects to a SMB
server (WinNT, Win95, Samba, and so on) a TCP connection to port
139 is established. The client then provides the server with its
NetBIOS name and the NetBIOS name it wishes to connect to. If the
name does not exist on the server, the session setup attempt fails
and an error message is sent to the client. This could indicate an
attack.
- 3303—Windows Guest login (severity
1, access): When a client establishes an connection to an SMB
server (WinNT or Samba), it provides an account name and password
for authentication. If the server does not recognize the account
name, it may log the user in as a guest. This is optional behavior
by the server and guest privileges should be limited. As a general
security precaution, users should not be allowed access as guest.
- 3304—Windows Null Account Name
(severity 1, information): When a client establishes an connection
to an SMB server (WinNT or Samba), it provides an account name and
password for authentication. This signature is triggered when a
null account name is passed during session establishment. There
are some hacking tools available (Red Button and NAT) that use
null account names.
- 3305—Windows Password File Access
(severity 5, access): This alarm occurs whenever a client attempts
to access a ".PWL" file on the server. These files
contain user passwords on Windows 95 and other systems. This
represents an abnormal attempt to read or copy the .PWL file.
- 3306—Windows Registry Access
(severity 5, access): This signature is triggered when a client
attempts to access the registry on the Windows server. Microsoft
tools like "REGEDIT" provide the ability to access a
server's registry over the network. There are several hacking
tools that also provide similar capabilities. Every attempted
access will cause an alarm to be sent. An attacker can cause
serious damage to a computer system by changing the registry.
- 3307—Windows RedButton (severity
5, access): This alarm occurs when the RedButton tool is run
against a server. The tool is designed to demonstrate the security
flaw in Windows NT 4.0 that allows remote registry access without
a valid user account. Although this flaw has been fixed with
Microsoft's NT Service Pack 3, the tool may still be run against
servers. A level five alarm shows the seriousness of this type of
attack.
|