EMZETT.
Login

NetBIOS-NS

In short: The name service of NetBIOS (port 137) — resolves NetBIOS computer names in the local network to IP addresses, similar to DNS for domain names.

In more detail: In pure Windows networks without a DNS server, computers used to be able to find each other by their NetBIOS name alone (e.g. PC-OFFICE1). Today largely replaced by DNS, but still active in many Windows installations for compatibility reasons — and a well-known attack vector if reachable unprotected from the internet.

In Depth

NetBIOS-NS (Name Service, UDP/TCP port 137) performs the same basic task within a Windows network as DNS does on the wider internet: it resolves a human-readable computer name to an IP address. The central difference: by default, NetBIOS-NS works via broadcast within the local network segment — every computer essentially “shouts” into its segment asking who can be reached under a particular name, instead of querying a central, hierarchical database as with DNS. This only works within the same subnet, since broadcasts are normally not forwarded by routers.

Because NetBIOS-NS answers unprotected plain-text requests without authentication, the service could be misused in the past for “NBT-NS poisoning” attacks: an attacker in the same network segment answers NetBIOS-NS requests faster than the actual target computer and thus impersonates it, for example to intercept credentials. For this reason, it’s recommended to deactivate NetBIOS-NS in modern networks where it’s no longer needed for legacy compatibility.

See also: NetBIOS-DGM, DNS