NNKL.COM welcome to my space |
HOME Netbios_NS & Netbios_DGM |
| Netbios_NS & Netbios_DGM | | Published by: admin 2010-03-14 |
| | ServiceType (ApacheDS DNS Provider 0.1-SNAPSHOT API):: static ServiceType, NETBIOS_NS. static ServiceType, NETBIOS_SSN. static ServiceType, NETRJS_1 . NETBIOS_NS. public static final ServiceType NETBIOS_NS http://people.apache.org/~akarasulu/rsynced-sites/directory/subprojects/providers/dns/apidocs/org/apache/dns/records/internet/ServiceType.htmlHOME | First of all i want to appoligise if this question has been asked before. I did my best in searching the forum for this question but i couldnt find it.
Now to my problem:
+ netbios 213.100.*.* (hidden) NETBIOS_NS Block NetBIOS Traffic 0bytes 0bytes
+ netbios 213.100.*.* (hidden) NETBIOS_DGM Block NetBIOS Traffic 0bytes 0bytes
I get more than over 100,000 msgs like this every day =( Yes its tru, my computer has been online now for 38 minutes and i already have 18,500 blocked attemts like this. As you might figgure not is this so anoying but also making humungus logs.
I have tried to make my own rules so i dont have to see these attempts but they dont seem to be working. When i was running Tiny personal firewall i got 3 gigs of logs from these attempts in only 2-3 days.
I have no clue what this Netbios_NS and Netbios_DGM remote port meens or what kind of traffic it is (0byte traffic ?) and all this is comming from the internal network from the isp. So anyone have any clue what i need to do to get rid of this please help me =) [Samba] error connecting to myhost:139 (Invalid argument):: netbios_ns dgram udp wait untrusted root /opt/samba/bin/nmbd nmbd -d 999 netbios_ns 137/tcp. netbios_ns 137/udp. netbios_ssn 139/tcp http://www.mail-archive.com/samba@lists.samba.org/msg03231.htmlHOME |
Thanx for taking your time to read this.
Hello Petrovski and thx for the help and the welcoming :D
You clearified all my questions and suspisions i had about this anyoing problem =) Plus that i got to learn a little more about the netbios =) I've always though this was a isp "problem" but wasnt shure about it.
Im running 2.1 but i cant see where u can prevent the logfile from getting to big. Dono if im to blind but i've been in every option looking for something like that but havent found anything =( So if u can help me out here that would be awsome, else i'll go with the renamning of the dll, but i would like to keep some logs of the few attacks. Angriff auf Benutzerkonten und jetzt erzeugt mein Rechner NETBIOS :: 2 posts - 1 author - Last post: May 17, 200615:48:42 UDP 202.97.238.132 NETBIOS_NS 15:45:08 NETBIOS AUSGEHEND ABGELEHNT UDP 60.11.125.36 NETBIOS_NS http://forum.emsisoft.com/Default.aspx?g=posts&t=700HOME |
Thanks again for your help and time!
Hello GoonMan and thank you to :D
I was reading in the forum where i saw where you explained for another user how to do this. So i went there when i read it but then my computer crashed so i had to reboot and you wrote the answer again before i could reply :)
But still thank you for your fast respons and help :)
Originally posted by denied
Hello Petrovski and thx for the help and the welcoming :D
You clearified all my questions and suspisions i had about this anyoing problem =) Plus that i got to learn a little more about the netbios =) I've always though this was a isp "problem" but wasnt shure about it.
Im running 2.1 but i cant see where u can prevent the logfile from getting to big. Dono if im to blind but i've been in every option looking for something like that but havent found anything =( So if u can help me out here that would be awsome, else i'll go with the renamning of the dll, but i would like to keep some logs of the few attacks.
Thanks again for your help and time!
notepad - 仕事/二条ルータ設定:: ip filter 32003 pass 192.168.10.10 192.168.20.3,192.168.20.4 udp,tcp * 135,netbios_ns-netbios_ssn,445,netbios_ns,netbios_dgm,netbios_ssn ip filter 40002 http://www.dl.kuis.kyoto-u.ac.jp/~inagawa/ford/hiki/?Ż/롼HOME | Example for RTA50i / かんたん設定の基本操作例:: ip filter 1 reject * * udp,tcp netbios_ns-netbios_ssn * ip filter 2 reject * * udp,tcp * netbios_ns-netbios_ssn ip filter 3 restrict * * tcpfin * www,ftp http://www.rtpro.yamaha.co.jp/RTA50i/example/operation/WindowsFileShare-Filter.htmlHOME |
Hello denied, Welcome to the Forum:)
You can control the log size by Opening the OutPost GUI>Click on Show Detailed Log> Top left File>Log Clean Up settings. You can change this to what settings best fits you and your system.
I hope this Helps.
See Screen Shot.
Im so impressed with the activity of this forum and its users driven intresst to help out other users.
Thank you so much for that web site, im sure i'll have plenty of use for it :)
Your Welcome Sir glad I could help.:)
If you are interested there is a Web Site on OutPost. It was written for V1.0 but alot still applies to 2.0 and 2.1. It is the The Web Hikers Guide To OutPost FireWall. (http://www.outpostfirewall.com/guide/guide_map.htm)
This might give you some details of how OutPost works. I know I went there many times in the past looking for info and still go there.
Hi denied, welcome to the forums :)
I understand you are being troubled with huge amounts of netbios connection requests? Netbios is a protocol that allows PC's in a LAN to communicate with each other on application level. Netbios_NS stands for netbios session if I remember correctly (meaning: a connection between 2 PC's) and Netbios_DGM stands for netbios datagram, a connectionless manner of communication. Obviously, you do not need netbios for internet connection, it is even unwanted for security reasons. The reason why you are seeing 0 kB of traffic is simply because the firewall is doing its job and blocks the netbios traffic. As you point out, the traffic originates from the IP range of your ISP, which makes me believe the problem lies there.
What version of OP are you using denied? If it is 2.1, you can control the log's filesize and prevent it from becoming too large. Version 2.0 does not have this feature, but you can disable logging completely by renaming op_data.dll, located in the outpost main directory. If you are using 1.0, I am not sure this workaround can be applied.
Hope this clears things up a bit for you.
Get Smart About Monitoring Virtual Machines
Microsoft Gets Ex-Streamly Cozy with U.K.'s MediaWave
|
|