NetBIOS attacks - What can I do?

  • Thread starter Thread starter harinagar
  • Start date Start date
  • Replies Replies 19
  • Views Views 3,852

harinagar

Newbie
Messages
2
Location
NA
The Sify LAN is connected 24x7, and so are the attempts by some of my neighbouring(?) users to launch NetBIOS attacks. The attempts come from only a select handfull of IP addresses, they might be some wannabe crackers/freeloaders, or some virus using them as a host, but they are really annoying me. I know I can turn off the warnings in ZoneAlarm anytime, but when I have their IP addresses(they are all local: a.b.c.x , a.b.c=same as in my LAN config.), isnt' there something, i can do? Whom can I complain to? the Cableguy or Sify CustCare. Right now i just ping them back to say hello, but one of them, the most troublesome 😛h34r: , i wanna give a boot :wacko: . Please comment.
 
Add the IPs/IP range in the Banned IPs list and relax.Allow only urself in the Trusted IPs list. :lol:
 
hari.....call the customer care and add some masala mirchi and say from this ip i m getting probs.........then be another user again call and say this guy is shutting my pc etc etc.....................or pay some insider of sify some bucks and get info abt this ip......or even dash through him
 
if that guy is smart enough to launch an attack, he would be smart enough to not use his primary assigned ip. better keep yourself away from all this shit.
 
Originally posted by idiot@Jun 12 2005, 11:06 AM
Add the IPs/IP range in the Banned IPs list and relax.

Allow only urself in the Trusted IPs list.  :lol:
[snapback]12436[/snapback]
[/quote]

I think this is the safest and the best way to deny them access... 🙂
 
On Windows if you don't need to share anthing with others on your LAN (like games etc., or chat with them through LAN ) then it's best to just disable your NetBIOS services which will disable the NetBIOS ports.

Here are the instructions to do it manually for--http://www.grc.com/su-bondage.htm

The basic funda of security is just don't run any services you don't need. And let those idiots do whatever they are doing. They won't be able to reach you. You know, when you have Zone Alarm running, it makes you invisible to the outside world. So the annoying script-kiddies that try to get to you might just think you're offline. However when you ping them back they know that you're online! So it may actually do you more harm.

Just don't bother "booting" or pinging unless you want to indulge in childish shoot 'em out games. And simply forget that your CTO will do anything about it. He simply doesn't care in my experience.
 


Well on a lan no firewall can stop u from exposing urself to someone .. firewall disable icmp (pings) but on a lan u can very well know if other machin is up or not via arp bcoz no fwall stops arp packets ( most of them by defaults) .. Btw i am sure ports u are getting warning by zonealarm will be 1025,1032,445,135,139,etc and maybe 1433 if it is so then it most probably its a virus making some other pc as its host and trying to spread ...

All u need is WWDC

And dont worry much abt that warnings if u know how to update windows 😉
 
Recently there has been a group of 7-8 computers suddenly attacking one computer. They all start and stop the same time. Probably a worm, one of those computers (my friends) had the Sify antivirus as well :lol: .
 
I guess I'd rather not meddle with the bad guys. It might as well be some worm spreading through unsecured PCs. I have checked 'Do not show this message again', I will trust my ZoneAlarm. My PC is not sharing anything, so i have disabled NetBIOS.

inetbum: your link had directions for win98/NT, but i felt quite uneasy with them on XP, these were simpler - http://irt.stanford.edu/security/howto/disable-netbios.html


Rohit: All right, you guys. I hate to break this little party, but there are still a lot of bad guys out there(especially in Hari Nagar, Rohit's neighbourhood).
Firewall: Well, then let's go show the bad guys the police are back in force.
 
Yeah those directions were for Win98 and were of use to me because i have win98 😛.
 
Funny...[/b]
Theres nothing funny
Firewall may crash sometimes just like other applications after all its running on windows .. You should make sure you dont get infected even if your firewall is down . Virus containing pc's try to spread all the time ... firewall crashes for a min and u get the virus 😛 .. So windows update is beast recommendation .

Btw theres more words than 'funny' and 'HaHaHaHa' 🙂
 
I had BB connection from 4 different isps in the last 3 years and had the same netbios attacks reported by my outpost firewall with almost all of them ,and yes only some ips constantly bother my firewall ,i have complained repeated to my CTo and isp but no use .I think its the inherent problem of LAN environments where very few people are intelligent enough to use firewall thereby causing problems to others.
 

Top