munotes®

NetBIOS and SMB Enumeration

Get access to whole semester resourcesSemester Pass

Chapter Forty-Five

Syllabus topic Module 1, "Enumeration and Service Identification: Study enumeration techniques such as ... NetBIOS scanning"

Pages 216 to 220 of 578

In one line

SMB is how Windows machines share files and printers, and NetBIOS is the older naming layer beside it. Queried by a stranger, they can reveal machine names, the domain, shared folders and user accounts, and historically they have been the route by which the most damaging worms spread.

In examination wording: NetBIOS provides name, session and datagram services for legacy Windows networking; the Server Message Block protocol provides file, printer and named-pipe sharing; enumeration of these services can disclose host and domain names, available shares, and user and group accounts, particularly where anonymous or null-session access is permitted.

What they are, and the ports

NetBIOS is the older mechanism, providing a flat name service for machines on a local network. It survives for compatibility.

SMB is the file-sharing protocol itself, and in modern deployments it runs directly over TCP without needing NetBIOS.

The ports a student must recognise:

PortService
137/UDPNetBIOS name service
138/UDPNetBIOS datagram service
139/TCPNetBIOS session service (SMB over NetBIOS)
445/TCPSMB directly over TCP, the modern path

Seeing 445 open from the internet is, on its own, a finding of substance. Seeing 137 to 139 exposed is worse, since it indicates a genuinely old configuration.

What enumeration yields

Machine and domain names. The NetBIOS name service will return a host's name, the workgroup or domain it belongs to, and the services it is advertising, along with the MAC address on a local segment. That is identity and grouping, handed over without authentication.

Shares. A list of shared folders, including administrative shares. The names alone are informative: a share called Payroll, Backups or Finance tells an attacker where to concentrate, and whether the share is readable is the next question.

Users and groups. This is the most valuable output. Where anonymous access is permitted, enumeration can return the list of local or domain user accounts, sometimes with details such as full names, comments, the account's security identifier, last logon, and whether the password never expires. A list of valid user names converts password attacks from guessing both halves of a credential to guessing one, which is an enormous advantage, and account comments have been known to contain passwords.

Password policy. Minimum length, complexity requirements and, critically, the lockout threshold. Knowing there is no lockout tells an attacker that online password guessing is viable; knowing the threshold tells them how to stay below it.

The null session

The historically important mechanism and the one examiners ask about.

A null session is a connection to the interprocess-communication share with an empty username and empty password. Older Windows versions permitted it by default, because certain legitimate functions between machines in a domain needed unauthenticated access to basic information.

munotes.in216

NetBIOS and SMB Enumeration

The consequence was that an unauthenticated stranger could connect and enumerate shares, users, groups and policy. It became the standard first step against Windows networks.

Modern Windows restricts this substantially: anonymous enumeration is disabled or limited by default, and the relevant policies allow it to be tightened further. But three qualifications keep it examinable and relevant:

  • Legacy systems persist, especially embedded and industrial devices running old Windows versions that cannot be updated.
  • Misconfiguration re-enables it, often to make an old application work.
  • Authenticated enumeration remains possible: an attacker who has obtained any valid low-privileged credential can usually enumerate users, groups and policy fully, which matters because it turns one weak account into a map of every account.

Why this protocol has the worst history

SMB has been the vector for the most damaging self-propagating malware in the field's history, and the pattern is worth understanding rather than memorising.

A worm needs a service that is reachable, present on nearly every machine, and exploitable without authentication. SMB has repeatedly satisfied all three: it is on every Windows machine, it is enabled by default on internal networks, and vulnerabilities in its implementation have permitted remote code execution without credentials. Add that internal networks are frequently flat, and a single compromised machine can reach every other machine's port 445 directly.

The lesson generalises beyond SMB, and it is the reason this chapter sits where it does: a service that is ubiquitous, enabled by default, and reachable across a flat internal network is the ideal propagation path. The defences that follow are therefore not only about enumeration; they are about limiting how far an internal compromise can spread.

Countermeasures

Never expose SMB or NetBIOS to the internet. Block 137, 138, 139 and 445 at the perimeter in both directions. This is not a hardening nicety; it is the single most important line in the chapter. Outbound blocking matters too, because a client tricked into connecting to an external SMB server can leak authentication material.

Disable NetBIOS over TCP/IP where nothing requires it, leaving SMB on 445 alone.

Restrict anonymous access. Ensure the policies that prevent anonymous enumeration of shares, users and policy are set, and do not relax them for a legacy application without compensating controls.

Use SMB version 3 and disable version 1. SMBv1 is obsolete, was the vehicle for the worst worm incidents, and should be removed rather than merely discouraged. SMBv3 adds signing, which prevents tampering and relay attacks, and encryption, which protects file contents in transit on the internal network.

Require SMB signing, which defeats a class of relay attack in which an attacker forwards a victim's authentication to another machine.

munotes.in217

NetBIOS and SMB Enumeration

Apply least privilege to shares. Each share visible and accessible only to those who need it, with the principle that a user should not be able to enumerate the existence of shares they cannot use. Remove unused shares, which accumulate.

Segment the network. Since the propagation pattern depends on every machine being able to reach every other machine's port 445, segmentation is what converts a worm outbreak from an estate-wide event into a contained one. Host firewalls that block inbound SMB between workstations are highly effective, because workstations almost never need to share files directly with each other.

Patch promptly. The specific flaws that enabled the worst incidents were patched before the outbreaks; the damage was done to systems that had not applied the fix.

Monitor. Internal SMB scanning, and one host connecting to many others on 445, is a hallmark of both worm propagation and lateral movement, and is among the highest-value internal alerts an organisation can configure.

A worked example

A tester assesses an internal network with authorisation.

  • From the internet, 445 is correctly blocked at the perimeter. Positive finding.
  • Internally, a file server permits an unauthenticated connection to list shares. Fourteen shares are visible, including HR-Confidential and Backup. Attempting to read them requires credentials, so the disclosure is of names rather than contents. Finding: share enumeration is permitted anonymously, which tells an attacker exactly where to aim.
  • A legacy industrial control machine running an old Windows version permits a null session, returning the full local user list with comments, one of which reads "temporary password Summer2019". Finding: anonymous enumeration and a credential in an account comment, the more serious of the two.
  • Using a low-privileged test account supplied by the client, the tester enumerates the domain and obtains the complete user list and the password policy, which shows no account lockout threshold. Finding: any valid credential yields a full user list, and the absence of lockout makes online password guessing viable.
  • Workstations accept inbound connections on 445 from other workstations. Finding: no host-level segmentation, so a single compromised workstation can reach every other directly, which is the worm propagation path.

Recommendations in priority order: set a lockout threshold and review the exposed credential immediately; block inbound SMB between workstations with host firewalls; restrict anonymous share and user enumeration; isolate the legacy control machine on its own segment since it cannot be updated; disable SMBv1 and require signing; and review share permissions so that names are not visible to those without access.

The finding that will surprise the client is the last of the five: the perimeter was correct and the interior was flat, which is the pattern the engagement-types chapter predicted when it argued that internal testing is usually more revealing than external.

munotes.in218

NetBIOS and SMB Enumeration

What beginners get wrong

  • Thinking SMB needs NetBIOS. Modern SMB runs directly on 445; NetBIOS on 137 to 139 is legacy and should usually be disabled.
  • Treating share-name disclosure as trivial. Names tell an attacker where the valuable data is and where to concentrate credential attacks.
  • Believing null sessions are a solved historical problem. They persist on legacy and embedded systems, and any valid low-privileged credential usually restores full enumeration.
  • Underestimating a user list. It halves the password-attack problem, and account comments have contained passwords.
  • Ignoring the lockout policy as an enumeration finding. Learning that no lockout exists is what makes online guessing worth attempting.
  • Blocking SMB inbound only. Outbound blocking matters too, because a client induced to connect outward can leak authentication material.
  • Leaving SMBv1 enabled "for compatibility". It was the vehicle for the worst incidents in the field and should be removed.

Quick revision

  • Ports: 137/UDP name, 138/UDP datagram, 139/TCP session (SMB over NetBIOS), 445/TCP SMB direct. 445 exposed to the internet is a finding in itself.
  • Yields: machine and domain names, share names, user and group accounts with details, and the password policy including the lockout threshold.
  • A null session is a connection with empty username and password, historically permitting full anonymous enumeration; restricted in modern Windows but alive on legacy and embedded systems, and any valid low-privileged credential usually restores it.
  • Worst history in the book: ubiquitous, default-enabled and reachable across flat internal networks, which is the ideal worm propagation path.
  • Countermeasures: block 137 to 139 and 445 at the perimeter both ways; disable NetBIOS over TCP/IP; restrict anonymous enumeration; disable SMBv1, use SMBv3 with signing and encryption; least privilege on shares; segment, including host firewalls blocking workstation-to-workstation SMB; patch promptly; and alert on internal 445 sweeps.

Test yourself

  1. Which ports carry NetBIOS and SMB, and which single observation is a finding on its own?

NetBIOS uses 137/UDP for names, 138/UDP for datagrams and 139/TCP for sessions; SMB runs directly over 445/TCP in modern deployments. Port 445 reachable from the internet is a finding on its own, and exposure of 137 to 139 indicates an even older configuration.

  1. What is a null session, and why does it still matter despite modern defaults?

A connection to the interprocess-communication share using an empty username and password, which historically permitted anonymous enumeration of shares, users, groups and password policy. It still matters because legacy and embedded systems that cannot be updated continue to permit it, because misconfiguration re-enables it for old applications, and because any valid low-privileged credential typically restores full enumeration anyway.

  1. Why is obtaining a list of valid user names so valuable to an attacker?
munotes.in219

NetBIOS and SMB Enumeration

Because it reduces a credential attack from guessing both the username and the password to guessing only the password against accounts known to exist. Combined with knowledge of the password policy, particularly the absence of a lockout threshold, it makes online guessing practical, and account comments have been found to contain passwords outright.

  1. Why has SMB been the vector for the most damaging worms, and what does that imply for defence?

Because it satisfies every requirement for propagation: it is present on virtually every Windows machine, enabled by default internally, and has had vulnerabilities permitting remote code execution without authentication, while internal networks are typically flat so every machine can reach every other on port 445. It implies that segmentation, including host firewalls preventing workstation-to-workstation SMB, is what converts an outbreak from estate-wide to contained.

  1. Name four countermeasures for SMB exposure, in order of importance.

Block 137 to 139 and 445 at the internet perimeter in both directions; segment internally so hosts cannot reach each other's SMB ports unnecessarily; disable SMBv1 and require SMB signing with SMBv3; and restrict anonymous enumeration of shares, users and policy, together with least-privilege share permissions and prompt patching.

munotes.in220

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!