Welcome to Smokey's Security Forums.
Guests have only limited access to the board and it's features, please consider registering to gain full access!
Registration is free and it only takes a few moments to complete.

Smokey's Security Forums

Please login or register.

Login with username, password and session length
Multilingual OTL (OldTimer ListIt) Log Analysis * Multilingual OTL Tutorials * OTL Downloads * Malware Removal * Microsoft Security Info & Alert Center * Official Jetico Inc. Support Forums

Share this topic on FacebookShare this topic on MySpaceShare this topic on Del.icio.usShare this topic on DiggShare this topic on RedditShare this topic on StumbleUponShare this topic on TwitterAuthorTopic: JPF2 and NetBios file sharing  (Read 1743 times)

0 Members and 1 Guest are viewing this topic.

xaocTopic starter

  • Full Member
  • **
  • Offline Offline
  • Posts: 48
JPF2 and NetBios file sharing
« Reply #1 on: October 18, 2008, 07:45:30 PM »
Here is my set of rules for windows file sharing:
Code: [Select]
<config>
    <export>
        <table action="continue" id="24" name="System">
            <rule type="7" action="accept" name="netbios-ns out">
                <event value="0x200" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <remote_port value="137" />
            </rule>
            <rule type="7" action="accept" name="netbios-ns in">
                <event value="0x400" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <local_port value="137" />
            </rule>
            <rule type="7" action="accept" name="netbios-dgm out">
                <event value="0x200" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <remote_port value="138" />
            </rule>
            <rule type="7" action="accept" name="netbios-dgm in">
                <event value="0x400" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <local_port value="138" />
            </rule>
            <rule type="7" action="accept" name="netbios-ssn out">
                <event value="0x2" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <remote_port value="139" />
            </rule>
            <rule type="7" action="accept" name="netbios-ssn in">
                <event value="0x1" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <local_port value="139" />
            </rule>
            <rule type="7" action="accept" name="microsoft-ds in">
                <event value="0x2" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <remote_port value="445" />
            </rule>
            <rule type="7" action="accept" name="microsoft-ds out">
                <event value="0x1" />
                <protocol value="0x00000002" />
                <remote_addr group="lan" />
                <local_port value="445" />
            </rule>
        </table>
    </export>
</config>
(group "lan" contains ip's from my local network)
(we must jump to this rule table with application value="System")
Rule table is attached to the post

If anybody has another ruleset for ms file sharing - you are welcome
 

* Permissions
You can't post new topics.
You can't post replies.
You can't post attachments.
You can't modify your posts.
BBCode Enabled
Smilies Enabled
[img] Enabled
HTML Disabled


Except where otherwise stated, all content © 2006 - 2010 Smokey Services™ -- All rights reserved
Design of all board graphics, banners and images by Emma aka Tinker - © 2006 - 2010 Smokey Services™ -- All rights reserved
Smokey's Security Forums is member AQMRB - Alliance of Qualified Malware Removal Boardsâ„¢, an organisation of Approved Qualified Malware Removal Help & Support Boards
Member ASAP - Alliance of Security Analysis Professionalsâ„¢

    

  

Smokey's provide fully qualified OTL (OldTimer ListIt) Log Analysis & Malware Removal services in English, German and Spanish language