Possible security problem?

Possible security problem?

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Possible security problem? Tony Cameron 07-28-2005
Posted by Tony Cameron on July 28, 2005, 12:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I am running a Mac G5 with 10.3.9 and have just discovered that at
regular but intermittent intervals, several times an hour, the process
nmbd attempts to make a UDP contact with a wide variety of addresses
mostly US based, but some European, on various ports ranging from 135 to
62253.

I run Firewalk X2 but have not worried in the past about what apps and
processes were getting out, just incoming, but turned logging on the
other day and discovered this consistent communication. I have blocked
nmbd for the moment, with no apparent ill effects, but I am very curious
as to the reason behind it. I don't see how I could have been hacked,
but it does look suspicious.

This occurs regardless of the apps running at the time, even after
rebooting and with nothing aside from system services started. I do have
Virtual PC on the system, but even with it not started, or killing it
from the activity monitor makes no difference to the activity. Samba is
not running.

Can anybody shed some light on this? Google doesn't seem to offer much
in the way of explanation.

Regards

Tony


Posted by Tom Stiller on July 27, 2005, 10:30 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> I am running a Mac G5 with 10.3.9 and have just discovered that at
> regular but intermittent intervals, several times an hour, the process
> nmbd attempts to make a UDP contact with a wide variety of addresses
> mostly US based, but some European, on various ports ranging from 135 to
> 62253.
>
> I run Firewalk X2 but have not worried in the past about what apps and
> processes were getting out, just incoming, but turned logging on the
> other day and discovered this consistent communication. I have blocked
> nmbd for the moment, with no apparent ill effects, but I am very curious
> as to the reason behind it. I don't see how I could have been hacked,
> but it does look suspicious.
>
> This occurs regardless of the apps running at the time, even after
> rebooting and with nothing aside from system services started. I do have
> Virtual PC on the system, but even with it not started, or killing it
> from the activity monitor makes no difference to the activity. Samba is
> not running.
>
> Can anybody shed some light on this? Google doesn't seem to offer much
> in the way of explanation.
>

Nnbd is part of the samba PC file sharing suite. If you don't need
samba, turn off "Windows Sharing" in the Sharing System Preferences
pane. If you need samba, but want to restrict its activities, read up
on the configuration options in the man page for smb.conf.

--
Tom Stiller

PGP fingerprint = 5108 DDB2 9761 EDE5 E7E3
7BDA 71ED 6496 99C0 C7CF


Posted by James D. Beard on July 27, 2005, 9:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Tony Cameron wrote:
> I am running a Mac G5 with 10.3.9 and have just discovered that at
> regular but intermittent intervals, several times an hour, the process
> nmbd attempts to make a UDP contact with a wide variety of addresses
> mostly US based, but some European, on various ports ranging from 135 to
> 62253.

If you are running OS X, see if your system has the command
lsof. If so, read the man page and use it to see what file(s)
are associated with the attempt to make the UDP contact.

The lsof is available on Linux, but I am too lazy to go to
my wife's G5 and check for you. <g>

jim b.

--
Unix is not user-unfriendly; it merely
expects users to be computer-friendly.


Posted by Ilgaz Ocal on July 28, 2005, 9:36 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> I am running a Mac G5 with 10.3.9 and have just discovered that at
> regular but intermittent intervals, several times an hour, the process
> nmbd attempts to make a UDP contact with a wide variety of addresses
> mostly US based, but some European, on various ports ranging from 135
> to 62253.
>
> I run Firewalk X2 but have not worried in the past about what apps and
> processes were getting out, just incoming, but turned logging on the
> other day and discovered this consistent communication. I have blocked
> nmbd for the moment, with no apparent ill effects, but I am very
> curious as to the reason behind it. I don't see how I could have been
> hacked, but it does look suspicious.
>
> This occurs regardless of the apps running at the time, even after
> rebooting and with nothing aside from system services started. I do
> have Virtual PC on the system, but even with it not started, or killing
> it from the activity monitor makes no difference to the activity. Samba
> is not running.
>
> Can anybody shed some light on this? Google doesn't seem to offer much
> in the way of explanation.
>
> Regards
>
> Tony

Hi,

Well if you see a strange command connecting to net, try running
Terminal, type "man (command name)" , e.g.

cable25-100:/etc ilgaz$ man nmbd

NAME
nmbd - NetBIOS name server to provide NetBIOS over IP naming services
to clients
(snip arguments part)
DESCRIPTION
This program is part of the samba(7) suite.

nmbd is a server that understands and can reply to NetBIOS over IP name
service requests, like those produced by SMB/CIFS clients such as Win-
dows 95/98/ME, Windows NT, Windows 2000, Windows XP and LanManager
clients. It also participates in the browsing protocols which make up
the Windows "Network Neighborhood" view.

Have a nice day

Ilgaz



Similar ThreadsPosted
Norton Internet Security 2005 Problem June 21, 2005, 1:46 pm
Symantec Gateway security 460 vpn rollover problem September 18, 2006, 10:23 am
Norton Internet Security 2005 after uninstall problem May 5, 2005, 2:24 am
Norton Internet Security 2005 Firewall problem. July 1, 2005, 8:16 pm
Problem With Norton Internet Security 2004 - Unable To Access E-Mail July 30, 2004, 11:28 am
New site dedicated to security conferences : www.security-briefings.com May 6, 2006, 11:17 am
Security programs 2005 - , Firewall programs 2005 -, Antivirus programs 2005 -, APPDEV DOT NET SECURITY, Linux Security and Firewall programs 2005 -, CiscoWorks ( CW ) Security programs 2005 - , February 25, 2005, 5:03 am
Home Security eBook - Home Security - How to Protect Your Family and Your Property - Home_Security.exe (0/2) November 5, 2004, 5:25 pm
Vpn nat problem December 22, 2004, 3:13 am
LAN problem with TPF February 20, 2005, 11:11 pm

The site map in XML format XML site map

Contact Us | Privacy Policy