Hacked!!! Question on port 137

Hacked!!! Question on port 137

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Hacked!!! Question on port 137 Ralph Gustavsen 12-11-2007
Posted by =?Utf-8?B?UmFscGggR3VzdGF2c2Vu on December 11, 2007, 1:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I've recently had my linksys befsx41 router hacked.

I've installed a packet sniffer and am watching the logs. Im noticing a
random UDP Packet being sent out port 137 from my XP pro box. Its going to a
few addresses in asia. Should I be overly concerned with this? It happens in
safe mode which strikes me as odd. No viruses, trojans etc found.

Thanks in advance,

Ralph Gustavsen

Posted by Shenan Stanley on December 11, 2007, 3:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Ralph Gustavsen wrote:
> I've recently had my linksys befsx41 router hacked.
>
> I've installed a packet sniffer and am watching the logs. Im
> noticing a random UDP Packet being sent out port 137 from my XP pro
> box. Its going to a few addresses in asia. Should I be overly
> concerned with this? It happens in safe mode which strikes me as
> odd. No viruses, trojans etc found.

Buy a new router and/or change all your passwords on the router - turn off
remote management completely in fact.
Did you have a software firewall on your comouter(s) as well?

Password protected systems?
Diligent backups? (If so - you may be safest wiping and installing from
scratch on everyone and restoring only files/stuff you have backed up - not
system files, just your stuff.)

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html



Posted by =?Utf-8?B?UmFscGggR3VzdGF2c2Vu on December 11, 2007, 3:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I had remote flash enabled. Bad.

I've reflashed it with the latest, changed passwords. Lots of backups,
strong passwords on everything, win2k3 server and xp pro.

I was just curious about the strange udp packet going out. It looks like a
netbios packet, im just not sure if i should be worried, or reformat.

Thanks!

"Shenan Stanley" wrote:

> Ralph Gustavsen wrote:
> > I've recently had my linksys befsx41 router hacked.
> >
> > I've installed a packet sniffer and am watching the logs. Im
> > noticing a random UDP Packet being sent out port 137 from my XP pro
> > box. Its going to a few addresses in asia. Should I be overly
> > concerned with this? It happens in safe mode which strikes me as
> > odd. No viruses, trojans etc found.
>
> Buy a new router and/or change all your passwords on the router - turn off
> remote management completely in fact.
> Did you have a software firewall on your comouter(s) as well?
>
> Password protected systems?
> Diligent backups? (If so - you may be safest wiping and installing from
> scratch on everyone and restoring only files/stuff you have backed up - not
> system files, just your stuff.)
>
> --
> Shenan Stanley
> MS-MVP
> --
> How To Ask Questions The Smart Way
> http://www.catb.org/~esr/faqs/smart-questions.html
>
>
>

Posted by =?Utf-8?B?QW50ZWF1cw==?= on December 17, 2007, 11:14 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Port 137 is used for netbios name resolution, and it is normal to find
broadcasts going-on all the time, within the confines of the LAN, or more
specifically within the local subnet. What is strange, though, is that your
router redirects these to the Internet. That shouldn't happen, and it
suggests there is something not quite right with the router's firewall
policies.

"Ralph Gustavsen" wrote:

>
> I was just curious about the strange udp packet going out. It looks like a
> netbios packet, im just not sure if i should be worried, or reformat.
>


Similar ThreadsPosted
Question concerning remote port-forwarding with SSH July 7, 2005, 8:59 am
Remote Desktop Port Question April 9, 2007, 3:35 pm
Port scan says port 21 is open June 21, 2007, 12:51 pm
firewall question and windows installer/spyware question September 24, 2006, 8:48 am
Can't get out on port 80 December 9, 2005, 6:39 pm
Port 80 February 21, 2006, 5:10 am
What port does IKE use? February 15, 2007, 4:24 pm
Port 21 March 17, 2007, 3:25 am
blocking port 25 June 28, 2005, 1:37 am
Port Blocking August 19, 2005, 10:56 am

The site map in XML format XML site map

Contact Us | Privacy Policy