From the course: Certified Ethical Hacker (CEH)

Unlock this course with a free trial

Join today to access over 24,800 courses taught by industry experts.

Performing NetBIOS enumeration

Performing NetBIOS enumeration

- NetBIOS or Network Basic Input Output System was defined back in 1987 with RFCs 1001 and 1002. It's commonly NetBIOS over TCP IP or NBT today. This provides name resolution on a Local Area Network. There's several services that are provided by NetBIOS. We have a name service for registration and resolution running on 137, both UDP and TCP. And then for connectionless communications, we have this datagram distribution service on 138 and then a session service for connection-oriented communications on 139 TCP. NetBIOS names are 15 ASCII bytes, this is seven bit ASCII and there is a one byte suffix. Those suffixes can be used to determine the purpose of a particular system. So if you see a suffix of zero zero with a type of group, you can know that this particular piece of information is the name of a machine group. We can also see things such as domain master browser. If you see a suffix of 1B, then that system is considered the domain master browser. This URL on the bottom of the…

Contents