daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

137-138-139-pentesting-netbios.md (4618B)


      1 ---
      2 title: "137,138,139 - Pentesting NetBios"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/137-138-139-pentesting-netbios.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/137-138-139-pentesting-netbios.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 137,138,139 - Pentesting NetBios
     14 
     15 ## NetBios Name Service
     16 
     17 NetBIOS over TCP/IP defines name, datagram, and session services on separate ports:<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     18 
     19 - Name service for name registration and resolution (ports: 137/udp and 137/tcp).
     20 - Datagram distribution service for connectionless communication (port: 138/udp).
     21 - Session service for connection-oriented communication (port: 139/tcp).
     22 
     23 ### Name Service
     24 
     25 For a device to participate in a NetBIOS network, it must have a unique name. This is achieved through a **broadcast process** where a "Name Query" packet is sent. If no objections are received, the name is considered available. Alternatively, a **Name Service server** can be queried directly to check for name availability or to resolve a name to an IP address. Tools like `nmblookup`, `nbtscan`, and `nmap` are utilized for enumerating NetBIOS services, revealing server names and MAC addresses.
     26 
     27 ```bash
     28 PORT    STATE SERVICE    VERSION
     29 137/udp open  netbios-ns Samba nmbd netbios-ns (workgroup: WORKGROUP)
     30 ```
     31 
     32 Enumerating a NetBIOS service you can obtain the names the server is using and the MAC address of the server.
     33 
     34 ```bash
     35 nmblookup -A <IP>
     36 nbtscan <IP>/30
     37 sudo nmap -sU -sV -T4 --script nbstat.nse -p137 -Pn -n <IP>
     38 ```
     39 
     40 The `nbstat` script queries the NetBIOS name table and may also report a MAC address.<sup>[[3]](#references)</sup>
     41 
     42 ### Datagram Distribution Service
     43 
     44 NetBIOS datagrams allow for connectionless communication via UDP, supporting direct messaging or broadcasting to all network names. This service uses port **138/udp**.
     45 
     46 ```bash
     47 PORT    STATE         SERVICE     VERSION
     48 138/udp open|filtered netbios-dgm
     49 ```
     50 
     51 ### Session Service
     52 
     53 For connection-oriented interactions, the **Session Service** facilitates a conversation between two devices, leveraging **TCP** connections through port **139/tcp**. A session begins with a "Session Request" packet and can be established based on the response. The service supports larger messages, error detection, and recovery, with TCP handling flow control and packet retransmission.
     54 
     55 Data transmission within a session involves **Session Message packets**, with sessions being terminated by closing the TCP connection.
     56 
     57 These services provide the NetBIOS naming and transport interfaces over TCP/IP.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     58 
     59 ```bash
     60 PORT      STATE SERVICE      VERSION
     61 139/tcp   open  netbios-ssn  Microsoft Windows netbios-ssn
     62 ```
     63 
     64 **Read the next page to learn how to enumerate this service:**
     65 
     66 
     67 [Readme](/hacktricks/network-services-pentesting/pentesting-smb/overview)
     68 
     69 ## HackTricks Automatic Commands
     70 
     71 ```text
     72 Protocol_Name: Netbios    #Protocol Abbreviation if there is one.
     73 Port_Number:  137,138,139     #Comma separated if there is more than one.
     74 Protocol_Description: Netbios         #Protocol Abbreviation Spelled out
     75 
     76 Entry_1:
     77   Name: Notes
     78   Description: Notes for NetBios
     79   Note: |
     80     Name service for name registration and resolution (ports: 137/udp and 137/tcp).
     81     Datagram distribution service for connectionless communication (port: 138/udp).
     82     Session service for connection-oriented communication (port: 139/tcp).
     83 
     84     For a device to participate in a NetBIOS network, it must have a unique name. This is achieved through a broadcast process where a "Name Query" packet is sent. If no objections are received, the name is considered available. Alternatively, a Name Service server can be queried directly to check for name availability or to resolve a name to an IP address.
     85 
     86     https://book.hacktricks.wiki/en/network-services-pentesting/137-138-139-pentesting-netbios.html
     87 
     88 Entry_2:
     89   Name: Find Names
     90   Description: Three scans to find the names of the server
     91   Command: nmblookup -A {IP} &&&& nbtscan {IP}/30 &&&& nmap -sU -sV -T4 --script nbstat.nse -p 137 -Pn -n {IP}
     92 ```
     93 
     94 ## References
     95 
     96 - [1] [RFC 1001 - NetBIOS concepts and methods](https://www.rfc-editor.org/rfc/rfc1001)
     97 - [2] [RFC 1002 - NetBIOS detailed specifications](https://www.rfc-editor.org/rfc/rfc1002)
     98 - [3] [Nmap - `nbstat` NSE script](https://nmap.org/nsedoc/scripts/nbstat.html)