?
Solved

Excessive Outbound Traffic on UDP Port 137

Posted on 2008-06-23
3
Medium Priority
?
3,325 Views
Last Modified: 2013-12-04
I've been noticing in my firewall logs an excessive amount of outbound traffic on udp port 137 from a single workstation. This port is blocked in my firewall, so it's not getting through, but I wanted to know if anyone could help me find the source of this traffic.

I have run CA AntiVirus and Anti Spyware as well as Spybot. The AV scan was clean and the spyware/adware scan only came up with a handful of cookies that have been removed. Netstat and Nbtstat both seem clean as well.

Thanks for the help.
0
Comment
Question by:Luis_Romero
3 Comments
 
LVL 12

Accepted Solution

by:
alikaz3 earned 1500 total points
ID: 21850393
udp port 137 is used for NetBIOS. You could try changing the NetBIOS setting on that workstation and see what you get.
>>>>>>>>>>>>
NetBIOS name service (UDP)

firewalls: Firewall administrators will frequently see large numbers of incoming packets to port 137. This is due to the behavior of Windows servers that use NetBIOS (as well as DNS) to resolve IP addresses to names using the "gethostbyaddr()" function. As users behind the firewalls surf Windows-based web sites, those servers will frequently respond with NetBIOS lookups.
>>>>>>>>>>>>
0
 
LVL 32

Expert Comment

by:r-k
ID: 21851063
Please post a HJT log from the suspect workstation just in case:

Download HijackThis from http://www.hijackthis.de/
(use the "direct download" link in the upper-right corner)
Unzip to any folder on your hard drive (other than the desktop)
Run the program by double-clicking on the HijackThis.exe file.
Click on "Do a System Scan.."
Copy-and-paste the resulting log here.
Optionally, you can post back to that same web page, and click "Analyze"
0
 

Author Closing Comment

by:Luis_Romero
ID: 31470272
Thanks. Your response actually reminded me that I've had this problem before but added a new NIC that used the default NetBios settings. Once I turned off NetBios over TCP/IP the problem was resolved.

Thanks for your help!
0

Featured Post

A Cyber Security RX to Protect Your Organization

Join us on December 13th for a webinar to learn how medical providers can defend against malware with a cyber security "Rx" that supports a healthy technology adoption plan for every healthcare organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Transferring data across the virtual world became simpler but protecting it is becoming a real security challenge.  How to approach cyber security  in today's business world!
One of the biggest threats facing all high-value targets are APT's.  These threats include sophisticated tactics that "often starts with mapping human organization and collecting intelligence on employees, who are nowadays a weaker link than network…
this video summaries big data hadoop online training demo (http://onlineitguru.com/big-data-hadoop-online-training-placement.html) , and covers basics in big data hadoop .
Screencast - Getting to Know the Pipeline
Suggested Courses

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question