UDP Port 137 on Windows Server?

LandyMan

Honorary Master
Joined
Feb 28, 2005
Messages
13,363
Reaction score
3,191
Location
Centurion
Hi all,

I just received an e-mail from our hosting environment that we are getting alot of connections on our server on port 137.

According to http://www.iss.net/security_center/advice/Exploits/Ports/137/default.htm, Port 137 is used for DNS lookups. Is this something to be concerned about, as I am not sure what the above link means: Does it mean our server is trying to do lookups, hence the port being accessed, or is it the 'client' machines doing the lookup?

Thanks!
 
It's NETBIOS name lookups, not DNS. DNS is udp/tcp 53.

It's typically used in an exploit. I get craploads of hits on 137, 139 etc on my firewall for those ports.

I hope you have a soft-firewall installed on that box, or it's at least running a secure OS.
 
thisgeek said:
It's NETBIOS name lookups, not DNS. DNS is udp/tcp 53.

It's typically used in an exploit. I get craploads of hits on 137, 139 etc on my firewall for those ports.

I hope you have a soft-firewall installed on that box, or it's at least running a secure OS.
Wanna know the joke? We have a Cisco firewall installed at last hop before our server (managed by the ISP!!) and still they let those hits through.

You reckon I must tell them to close it up?
 
Top
Sign up to the MyBroadband newsletter
X