Service Report
Global UDP/137 (netbios-ns)
-
Top Attacks (past 24 hours)
-
Sources (past 24 hours)
By Country
Key Country 
Bytes per subnet 
Percentage 
US (United States)4.63 kB 12.9%
CN (China)3.63 kB 10.1%
ZA (South Africa)3.50 kB 9.7%
BR (Brazil)2.26 kB 6.3%
GR (Greece)1.67 kB 4.7%
AR (Argentina)1.62 kB 4.5%
GB (Great Britain)1.41 kB 3.9%
IT (Italy)1.24 kB 3.5%
IN (India)1.09 kB 3.0%
MY (Malaysia)1.05 kB 2.9%Other 13.85 kB 38.5%By ASN
Key ASN 
Bytes per subnet 
Percentage 
AS4134 (CHINANET-BACKBONE) 2.41 kB 6.7%AS3741 (IS) 2.11 kB 5.9%AS5713 (SAIX-NET) 1.42 kB 4.0%AS1241 (FORTHNET-GR) 1.39 kB 3.9%AS3269 (ASN-IBSNAZ) 1.06 kB 2.9%AS683 (ARGONNE-AS) 1.05 kB 2.9%AS7738 (Telecomunicacoes) 912.48 B 2.5%AS5617 (TPNET) 885.94 B 2.5%AS5432 (BELGACOM-SKYNET-AS) 862.64 B 2.4%AS10292 (CWJ-1) 802.96 B 2.2%Other 23.04 kB 64.1%By Host
Key Host 
Bytes per subnet 
Percentage 
193.92.29.46 1.39 kB 3.9%219.132.37.9 1.11 kB 3.1%196.209.26.44 (196-209-26-44-nngy-esr-2.dynamic.isadsl.co.za) 897.70 B 2.5%196.209.104.52 (196-209-104-52-wblv-esr-3.dynamic.isadsl.co.za) 778.07 B 2.2%210.19.40.16 752.33 B 2.1%219.148.178.74 572.70 B 1.6%125.64.24.39 559.87 B 1.6%130.202.234.76 517.08 B 1.4%87.0.55.246 (host246-55-dynamic.0-87-r.retail.telecomitalia.it) 454.97 B 1.3%222.73.204.17 438.49 B 1.2%Other 28.48 kB 79.2%By Country
Key Country 
Attacks per subnet 
Percentage 
Other 0.00 0.0%By ASN
Key ASN 
Attacks per subnet 
Percentage 
Other 0.00 0.0%By Host
Key Host 
Attacks per subnet 
Percentage 
Other 0.00 0.0%
Background
| Vendors: | Symantec, Microsoft |
Vulnerabilities
CVE-2004-0444
Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary code via (1) a manipulated length byte in the first-level decoding routine for NetBIOS Name Service (NBNS) that modifies an index variable and leads to a stack-based buffer overflow, (2) a heap-based corruption problem in an NBNS response that is missing certain RR fields, and (3) a stack-based buffer overflow in the DNS component via a Resource Record (RR) with a long canonical name (CNAME) field composed of many smaller components. |
|||
CVE-2004-0445
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a DNS response with a compressed name pointer that points to itself. |
|||
CVE-2003-0825
The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code. |