Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » General Security Discussion » Netbios Traffic with dst to 133.130.2.10

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Netbios Traffic with dst to 133.130.2.10


Posted by khursheed on December 07, 2006 07:28:18

I am seeing this type of traffic from lots of machine in single subnet. No other subnet have this kind of traffic and snort does not pick it as anomly. But why to an ip dst to japan and why all of then machine.


23:19:25.277069 IP (tos 0x0, ttl 126, id 30178, offset 0, flags [none], proto: UDP (17), length: 252) x.x.x.x.netbios-dgm > 133.130.2.10.netbios-dgm:

SourceName=server NameType=0x00 (Workstation)
DestName=
WARNING: Short packet. Try increasing the snap length