Exactly the ones they say.. :}..
The most common culprit is MS-Proxy.. it seems to want to make Netbios name 
requests to every host it caches from..
Great 'feature' eh?

Bret

At 14:00 7/06/00 +0200, Markus Loeffler wrote:
>i am using Log File Auditing for checking my Firewall on intrusions.
>
>Currently i get connects to the unsecure Interface on the Firewall from
>several IP-Adresses on the Internet with source Port 137 to destination
>Port 137 , protocol is UDP.
>
>IANA Port-Assignment says :
>
>netbios-ns      137/tcp    NETBIOS Name Service
>netbios-ns      137/udp    NETBIOS Name Service
>
>but which Services uses that on the Internet ?
>
>mit freundlichen Gr��en,
>KCS Informationstechnik GmbH & Co. KG
>
>Markus L�ffler
>Netzwerkconsulting und Systemtechnik
>
>Tel.: 0731 / 9 35 69-62
>Fax: 0731 / 9 35 69-55
>email: [EMAIL PROTECTED]
>web: http://www.kcs.net
>
>-
>[To unsubscribe, send mail to [EMAIL PROTECTED] with
>"unsubscribe firewalls" in the body of the message.]

Technical Incursion Countermeasures
[EMAIL PROTECTED]                      http://www.ticm.com/
voice mail/fax: (+65)98421426(UTC+8 hrs)

The Insider - a e'zine on Computer security
http://www.ticm.com/info/insider/index.html

-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to