Great Circle Associates Firewalls
(June 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ICQ and port 139
From: "Jens Peschke" <j @ peschke . h . eunet . de>
Date: Thu, 19 Jun 1997 21:20:43 +0200
To: <Firewalls @ GreatCircle . COM>

> hello world,
> 
> i found out that this program ICQ from MIRABILIS send some strange querys
> out.
> it's a request from port 40 to port 139. port 139 is, so far i know, used
> for netbios
> over tcp ... what the hell they are looking for on this port.is this
> something against the
> security?-) or do they have another reason to do this so ?-)..i can not
> exlain this to me
> and i would be happy if somebody could help me in understanding this. i
> hope you
> could read my english. ;-)
> 
> thanx Andreas Engel :) 

The ports 137 - 139 are used for netbios over tcp (139 actually is nbss).
If you send an special "Out of bound" meassge to that port unfixed Windows
PC´s can be 
Winnuked:
NT WS and Server is killed (blue screen with processor halt);
You can fix it using SP3 and the OOB fix.

Win 95 stays running - but without any network connection left.
The info for fixing it, can be found at the ms site.

If attacking Win 3.x, a dos session ramains ...
MS will not fix it.

If you are running a firewall on NT WS or Server (Checkpoint or Raptor
eagle) you have to aply additional fixes to prevent the fw crashing down.

If using any router between fw and Internet, you should block those udp and
tcp ports (incoming and outcoming) to prevent windows broadcasts (Netbios
over TCP/IP) and Winnuke.

Jens Peschke



Indexed By Date Previous: Re: DES has been cracked! (DES w/56-bit key)
From: Vincent Poy <vince @ mail . MCESTATE . COM>
Next: configuration 2 domain in FW
From: "Raul Navarro G." <rnavarro @ bolchile . cl>
Indexed By Thread Previous: ICQ and port 139
From: "Andreas Engel" <Andreas . Engel @ cylink . net>
Next: Re: ICQ and port 139 -Reply
From: Scott Fagg <scott . fagg @ arup . com>

Google
 
Search Internet Search www.greatcircle.com