×

Good News Everybody!

The new search engine is LIVE!

Please report any problems to david (at) midrange.com.




so is this connection dangerous? Are they actually signed on, or does
netbios
transactions operate on some level outside of what we would call normal
authentication?
If I operate a 400 in the DMZ should I disable port 445? If not in the DMZ,
but in a local
network, can i disable 445? What would break - netserver? Client Access?
curious
jim

----- Original Message -----
From: "Hall, Philip" <phall@xxxxxxxx>
To: "Midrange Systems Technical Discussion" <midrange-l@xxxxxxxxxxxx>
Sent: Monday, August 11, 2003 10:21 AM
Subject: RE: Strange Netbios connections


>
> Oliver
>
> > > yesterday, we had some strange netbios TCP/IP connections on
> > > our AS/400's (both of them).
> > > A PC from a remote WAN location was connecting on port 445 to
> > > internal ip-addresses of our
> > > 810 and 820.
>
> Here's some more info;
>
> "port 445 is also an attack vector for RPC-DCOM and 445 is only found on
2k/
> xp / 2k3 as well. As a side note, ASP running on IIS links to dcom
functions, and port 80 is also another vector. With the prevelance of the
dcom exploit, i imagine the port 445 scan is a side affect of routine
exploit fingerprinting from would-be attackers."
>
> And
>
> "We've been seeing increased activity from Randex.D worm infections, which
> generated similar types of scan patterns:
>
> http://securityresponse.symantec.com/avcenter/venc/data/w32.randex.d.html";
>
>
> --phil
>
> _______________________________________________
> This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing
list
> To post a message email: MIDRANGE-L@xxxxxxxxxxxx
> To subscribe, unsubscribe, or change list options,
> visit: http://lists.midrange.com/mailman/listinfo/midrange-l
> or email: MIDRANGE-L-request@xxxxxxxxxxxx
> Before posting, please take a moment to review the archives
> at http://archive.midrange.com/midrange-l.
>
>



As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2026 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.