Frequently Security Question on Network (ONE)-NetBIOS Applied VulnerabilityNetBIOS,Network Basic Input Output System is a kind of input system on network. NetBIOS' main function is to let users share resource through network. Windows system's neighbor and Unix system's Samba both belong to NetBIOS, and generally we call them Neighbor. In 1985, IBM began to use Domain Zone of NetBIOS and Microsoft produced "Windows For Workgroups" operation system that adapt the suitable Window system's NetBIOS. Neighbor created a new time that the users could share their resource in Domain Zone and it only needed a few information of system to reach high transmission efficiently. Although at present, there is no standard to check the vulnerability assessment. However, to American information security administration, they do have their own rule of thumbs to inspect the system, but those rule of thumbs are not real "criterions" or regulations on document. In Taiwan, because there is no related official information for assessment, only one function would be compared. (There is no doubt that simple comparison is helpful for selling but is not good for information security's improvement. If this comparison continues, it would have bad effect for development of information security in Taiwan. The users could use the same printer, share their information and so on in their Domain Zone through NetBIOS, because NetBIOS could provide these services to save manpower, material resources and system resources. Hence, NetBIOS need opening 139 and 445 ports to work. Some hackers could use these ports to attack the users' workstation due to managers are worried about using neighbor. In May of this year, the 445 port be opened and caused Sasser Worm's dangerous from bad to worse. DragonSoft Security Team suggests that the managers should set up security Mechanism with firewall or other related security tools to protect the users' data before patch the vulnerability. Frequently NetBIOS Security Question on Workstation: 1.Use tools to search shared resources:
|
|
|
|

