Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Wireless Security » Wireless question
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
wireless port scan attacked ??? »
AuthorAll Replies

docrice

join:2008-03-31
Fremont, CA

reply to antdude
Re: Wireless question

There are several "name leaks" (if you want to call it that) which occurs with Windows-based systems. In the DHCP Request packet, the hostname of the system is sent as option 12 (in an Active Directory directory environment, this helps the DHCP server update DNS). If dynamic DNS is supported, the client may also try to register their hostname into the DNS server and these are observable via the DNS update queries from the client.

You also have the infamous "NetBIOS" services on UDP 137 and 138 (and optionally TCP 139 which is more or less replaced via TCP 445 these days). These are legacy NetBIOS service enumeration / discovery methods for NetBIOS name suffixes (which denote the service type, whether it's a Workstation service, a PDC, etc.) which generally aren't useful unless you're running an NT 4.0 domain (almost no one these days) or you need your internal network to announce itself in such a manner due to the lack of centralized service enumeration methods (such as DNS SRV records). The Browser service on UDP 138 is there to help populate your "network neighborhood" browse list as well as help in the selection of a Master Browser, etc. (in the NetBIOS sense). All the NetBIOS stuff can be disabled under your interface's IP properties under Advanced -> WINS. You'll need to do this for each individual interface.

SMB / CIFS connections are under the "File and Printer Sharing" option, but there really isn't a "leak" in this sense since having a network share doesn't mean the machine broadcasts its availability.

Windows also tends to give itself away when you have SSDP involved running over UDP 1900. You can look that up. In Vista, you also have Link Layer Topology Discovery and other IPv6 stuff which clutters the network, although it's nice to help draw a network route diagram at a basic level.
-
Forums » Up and Running » Security » Wireless Securitywireless port scan attacked ??? »


Saturday, 28-Nov 18:24:09 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [70] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [64] Weekend Open Thread
· [62] Thanksgiving Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· [Future9] Future9 status [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· how to use the 2nd line with phone hooked to the 1st line? [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· Gizmo5 has added a Google Voice section in its members area. [VOIP Tech Chat]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]