Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old August 22nd, 2004, 12:51 PM
Thaer Thaer is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Location: Michigan - USA
Posts: 61 Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 9 h 27 m 17 sec
Reputation Power: 7
Send a message via AIM to Thaer Send a message via MSN to Thaer Send a message via Yahoo to Thaer
Exclamation Can port ::139:: be dangerous ?!

Hi,

I was scanning open ports in my PC (uses Windows XP) , and I found that Port 139 is open ( I guess it's the NetBIOS port ), So I made a little VB program, and connected to my PC through the port successfully using that program, My question is will I be able to hack my computer using that port ?? Even though I don't have any network connections or shared files except my High-Speed internet connection.

Reply With Quote
  #2  
Old August 22nd, 2004, 12:57 PM
RolandG RolandG is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: New York
Posts: 140 RolandG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 50 sec
Reputation Power: 6
Port 139 NetBIOS

NetBIOS Session (TCP), Windows File and Printer Sharing
This is the single most dangerous port on the Internet. All "File and Printer Sharing" on a Windows machine runs over this port. About 10% of all users on the Internet leave their hard disks exposed on this port. This is the first port hackers want to connect to, and the port that firewalls block.

_________________________________________
Enter ye in at the strait gate: for wide is the gate, and broad is the way, that leadeth to destruction, and many there be which go in thereat
Mat 7:13

Reply With Quote
  #3  
Old August 22nd, 2004, 01:10 PM
Thaer Thaer is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Location: Michigan - USA
Posts: 61 Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 9 h 27 m 17 sec
Reputation Power: 7
Send a message via AIM to Thaer Send a message via MSN to Thaer Send a message via Yahoo to Thaer
Exclamation Thanks RonaldG

Thanks RolandG, But on my PC I don't have the "File and Printer Sharing" service enabled, I don't even have the NetBIOS protcol ,I try sending the "Get c:\somefile" command but my PC closes the connection, What does that mean ?? and If there is any other commands I can send to my PC to hack it please tell us about them

Thank you again

Reply With Quote
  #4  
Old August 22nd, 2004, 02:39 PM
RolandG RolandG is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: New York
Posts: 140 RolandG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 50 sec
Reputation Power: 6
Try using fport it will let you know which program is binding to port 139.

http://www.foundstone.com

fport.exe is able link the port to pid to program name in one command line program. See sample output below

c:\fport

Pid Process Port Proto Path
392 svchost -> 135 TCP C:\WINNT\system32\svchost.exe
8 System -> 139 TCP
8 System -> 445 TCP
508 MSTask -> 1025 TCP C:\WINNT\system32\MSTask.exe

392 svchost -> 135 UDP C:\WINNT\system32\svchost.exe
8 System -> 137 UDP
8 System -> 138 UDP
8 System -> 445 UDP
224 lsass -> 500 UDP C:\WINNT\system32\lsass.exe
212 services -> 1026 UDP C:\WINNT\system32\services.exe


____________________________________________
The way of a fool is right in his own eyes: but he that hearkeneth unto counsel is wise.
Pro 12:15

Reply With Quote
  #5  
Old August 23rd, 2004, 12:18 PM
Thaer Thaer is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Location: Michigan - USA
Posts: 61 Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level)Thaer User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 9 h 27 m 17 sec
Reputation Power: 7
Send a message via AIM to Thaer Send a message via MSN to Thaer Send a message via Yahoo to Thaer
Question

RonaldG, Thanks but I couldn't find the FPort..

CPORT says that the "system" uses this process...

Process name: System
Process ID: 4
Process Path: N/A
File Name: N/A
Protocol: TCP
Local Port Name: netbios-ssn
Local Address: XXX.XXX.12.67 <<-My IP Address
Remote Address: 0.0.0.0
State: Listening

Is it Windows XP that's using this process ?? If yes, What program or service in XP uses this port ?? and How dangerous can it be??

Thanks in advance

Reply With Quote
  #6  
Old August 23rd, 2004, 01:30 PM
RolandG RolandG is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: New York
Posts: 140 RolandG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 50 sec
Reputation Power: 6
Here is the download link for fport,

http://www.foundstone.com/resources/freetools/fport.zip

Who knows what it is, you have to link the port to the program file name and then verify that the program file is authentic. If you have a feeling that your machine is hacked you should also consider reinstalling the OS. After you reinstall the machine, don't enable Netbios / file sharing then check to see if port 139 is active. If port 139 is still active you probably have nothing to worry about but you can still contact the Microsoft support line to verify.

Reply With Quote
  #7  
Old August 29th, 2004, 02:23 PM
Talos_DK Talos_DK is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2004
Posts: 21 Talos_DK User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 8 m 10 sec
Reputation Power: 0
do you know of any programs like this one for linux???

Reply With Quote
  #8  
Old August 29th, 2004, 02:27 PM
Talos_DK Talos_DK is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2004
Posts: 21 Talos_DK User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 8 m 10 sec
Reputation Power: 0
nm, found out that "netstat -pan" did that

Reply With Quote
  #9  
Old August 29th, 2004, 03:17 PM
RolandG RolandG is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2003
Location: New York
Posts: 140 RolandG User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 4 h 4 m 50 sec
Reputation Power: 6
Those netstat options only work on new versions of Windows (like XP). besides I think that you were refering to the "-o" option.

Finally my 100th and final post, take care all!

Last edited by RolandG : August 29th, 2004 at 05:41 PM.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Can port ::139:: be dangerous ?!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT