6.4 3000 Series—TCP Signatures
6.4.11 NetBIOS Attack signatures
TCP port 139 attacks include:
  • Reconnaissance
  • Access
  • Dos

The following are NetBIOS Attack signatures:

  • 3300—NETBIOS OOB data (severity 5, DoS): This signature is triggered when an attempt to send Out Of Band data to port 139 is detected. This can be used to crash Windows machines.
  • 3301—NETBIOS Stat (severity 1, information): This signature is triggered when NBTSTAT is used. The Windows NT called "NBTSTAT" is used to display protocol statistics and current TCP/IP connections using NetBIOS. This application can be used to list a remote machines name table. This tool allows an intruder to determine legitimate user names, the Windows Domain or Workgroup name, and many other facts useful in attacking a Windows network. There are UNIX tools available that perform the same function as NBTSTAT.
  • 3302—NETBIOS Session Setup Failure (severity 1, information/access): When a client connects to a SMB server (WinNT, Win95, Samba, and so on) a TCP connection to port 139 is established. The client then provides the server with its NetBIOS name and the NetBIOS name it wishes to connect to. If the name does not exist on the server, the session setup attempt fails and an error message is sent to the client. This could indicate an attack.
  • 3303—Windows Guest login (severity 1, access): When a client establishes an connection to an SMB server (WinNT or Samba), it provides an account name and password for authentication. If the server does not recognize the account name, it may log the user in as a guest. This is optional behavior by the server and guest privileges should be limited. As a general security precaution, users should not be allowed access as guest.
  • 3304—Windows Null Account Name (severity 1, information): When a client establishes an connection to an SMB server (WinNT or Samba), it provides an account name and password for authentication. This signature is triggered when a null account name is passed during session establishment. There are some hacking tools available (Red Button and NAT) that use null account names.
  • 3305—Windows Password File Access (severity 5, access): This alarm occurs whenever a client attempts to access a ".PWL" file on the server. These files contain user passwords on Windows 95 and other systems. This represents an abnormal attempt to read or copy the .PWL file.
  • 3306—Windows Registry Access (severity 5, access): This signature is triggered when a client attempts to access the registry on the Windows server. Microsoft tools like "REGEDIT" provide the ability to access a server's registry over the network. There are several hacking tools that also provide similar capabilities. Every attempted access will cause an alarm to be sent. An attacker can cause serious damage to a computer system by changing the registry.
  • 3307—Windows RedButton (severity 5, access): This alarm occurs when the RedButton tool is run against a server. The tool is designed to demonstrate the security flaw in Windows NT 4.0 that allows remote registry access without a valid user account. Although this flaw has been fixed with Microsoft's NT Service Pack 3, the tool may still be run against servers. A level five alarm shows the seriousness of this type of attack.