137-138-139-pentesting-netbios.md (4618B)
1 --- 2 title: "137,138,139 - Pentesting NetBios" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/137-138-139-pentesting-netbios.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/137-138-139-pentesting-netbios.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 137,138,139 - Pentesting NetBios 14 15 ## NetBios Name Service 16 17 NetBIOS over TCP/IP defines name, datagram, and session services on separate ports:<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 18 19 - Name service for name registration and resolution (ports: 137/udp and 137/tcp). 20 - Datagram distribution service for connectionless communication (port: 138/udp). 21 - Session service for connection-oriented communication (port: 139/tcp). 22 23 ### Name Service 24 25 For a device to participate in a NetBIOS network, it must have a unique name. This is achieved through a **broadcast process** where a "Name Query" packet is sent. If no objections are received, the name is considered available. Alternatively, a **Name Service server** can be queried directly to check for name availability or to resolve a name to an IP address. Tools like `nmblookup`, `nbtscan`, and `nmap` are utilized for enumerating NetBIOS services, revealing server names and MAC addresses. 26 27 ```bash 28 PORT STATE SERVICE VERSION 29 137/udp open netbios-ns Samba nmbd netbios-ns (workgroup: WORKGROUP) 30 ``` 31 32 Enumerating a NetBIOS service you can obtain the names the server is using and the MAC address of the server. 33 34 ```bash 35 nmblookup -A <IP> 36 nbtscan <IP>/30 37 sudo nmap -sU -sV -T4 --script nbstat.nse -p137 -Pn -n <IP> 38 ``` 39 40 The `nbstat` script queries the NetBIOS name table and may also report a MAC address.<sup>[[3]](#references)</sup> 41 42 ### Datagram Distribution Service 43 44 NetBIOS datagrams allow for connectionless communication via UDP, supporting direct messaging or broadcasting to all network names. This service uses port **138/udp**. 45 46 ```bash 47 PORT STATE SERVICE VERSION 48 138/udp open|filtered netbios-dgm 49 ``` 50 51 ### Session Service 52 53 For connection-oriented interactions, the **Session Service** facilitates a conversation between two devices, leveraging **TCP** connections through port **139/tcp**. A session begins with a "Session Request" packet and can be established based on the response. The service supports larger messages, error detection, and recovery, with TCP handling flow control and packet retransmission. 54 55 Data transmission within a session involves **Session Message packets**, with sessions being terminated by closing the TCP connection. 56 57 These services provide the NetBIOS naming and transport interfaces over TCP/IP.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup> 58 59 ```bash 60 PORT STATE SERVICE VERSION 61 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 62 ``` 63 64 **Read the next page to learn how to enumerate this service:** 65 66 67 [Readme](/hacktricks/network-services-pentesting/pentesting-smb/overview) 68 69 ## HackTricks Automatic Commands 70 71 ```text 72 Protocol_Name: Netbios #Protocol Abbreviation if there is one. 73 Port_Number: 137,138,139 #Comma separated if there is more than one. 74 Protocol_Description: Netbios #Protocol Abbreviation Spelled out 75 76 Entry_1: 77 Name: Notes 78 Description: Notes for NetBios 79 Note: | 80 Name service for name registration and resolution (ports: 137/udp and 137/tcp). 81 Datagram distribution service for connectionless communication (port: 138/udp). 82 Session service for connection-oriented communication (port: 139/tcp). 83 84 For a device to participate in a NetBIOS network, it must have a unique name. This is achieved through a broadcast process where a "Name Query" packet is sent. If no objections are received, the name is considered available. Alternatively, a Name Service server can be queried directly to check for name availability or to resolve a name to an IP address. 85 86 https://book.hacktricks.wiki/en/network-services-pentesting/137-138-139-pentesting-netbios.html 87 88 Entry_2: 89 Name: Find Names 90 Description: Three scans to find the names of the server 91 Command: nmblookup -A {IP} &&&& nbtscan {IP}/30 &&&& nmap -sU -sV -T4 --script nbstat.nse -p 137 -Pn -n {IP} 92 ``` 93 94 ## References 95 96 - [1] [RFC 1001 - NetBIOS concepts and methods](https://www.rfc-editor.org/rfc/rfc1001) 97 - [2] [RFC 1002 - NetBIOS detailed specifications](https://www.rfc-editor.org/rfc/rfc1002) 98 - [3] [Nmap - `nbstat` NSE script](https://nmap.org/nsedoc/scripts/nbstat.html)