NETBIOS is a service which allows communication between applications such as printer or other computer in Ethernet or token ring network via NETBIOS name.

NETBIOS name is 16 digits long character assign to a computer in workgroup by WINS for name resolution of an IP address into NETBIOS name.

Workgroup VS Domain

Workgroup: It is a peer to peer network for maximum 10 computers in same LAN or subnet. It has no Centralized Administration, which means no computer has control over another computer. Each user controls the resources and security locally on their system.

Domain: It is a client/server network for up to 2000 computers anywhere in the world. The administrator manages the domain and its users and resources. A user with an account on the domain can log onto any computer system, without having the account on that computer.

NetBIOS provides three distinct services:

  1. Name service (NetBIOS-NS) for name registration and resolution via port 137.
  2. Datagram distribution service (NetBIOS-DGM) for connectionless communication via port 138.
  3. Session service (NetBIOS-SSN) for connection-oriented communication via port 139.


  • 135 TCPMS-RPC endpoint mapper
  • 137 UDPNetBIOS Name Service
  • 138 UDPNetBIOS Datagram Service
  • 139 TCPNetBIOS Session Service
  • 445 TCPSMB Protocol

Port 135: it is used for Microsoft Remote Procedure Call between client and server to listen the query of client. Basically it is used for communication between client- client and server -client for sending messages.

Port 137: the name service operates on UDP port 137. The name service primitives offered by NetBIOS are:

  • Add name – registers a NetBIOS name.
  • Add group name – registers a NetBIOS “group” name.
  • Delete name – un-registers a NetBIOS name or group name.
  • Find name – looks up a NetBIOS name on the network.

Port 138: Datagram mode is connectionless; the application is responsible for error detection and recovery. In NBT, the datagram service runs on UDP port 138.The datagram service primitives offered by NetBIOS are:

  • Send Datagram – send a datagram to a remote NetBIOS name.
  • Send Broadcast Datagram – send a datagram to all NetBIOS names on the network.
  • Receive Datagram – wait for a packet to arrive from a Send Datagram operation.
  • Receive Broadcast Datagram – wait for a packet to arrive from a Send Broadcast Datagram operation.

Port 139: Session mode lets two computers establish a connection, allows messages to span multiple packets, and provides error detection and recovery. In NBT, the session service runs on TCP port 139.

The session service primitives offered by NetBIOS are:

  • Call – opens a session to a remote NetBIOS name.
  • Listen – listen for attempts to open a session to a NetBIOS name.
  • Hang Up – close a session.
  • Send – sends a packet to the computer on the other end of a session.
  • Send No Ack – like Send, but doesn’t require an acknowledgment.
  • Receive – wait for a packet to arrive from a Send on the other end of a session.

Nbtstat is a windows utility that helps troubleshooting Netbios name resolution problems.

NetBios Enumeration

There are number of tools that can be employed to enumerate NetBios. The most often used are

Hyena :

Hyena is a tool for day-to-day administration of Windows and Active Directory systems.

Hyena brings together all of the administrative tools from Windows and many of the MMC components in Windows 200x into a single, easy-to-use, centralized program. Hyena arranges all system objects, such as users, servers, and groups, in a hierarchical tree for easy and logical system administration. Here’s a sample of just a few of Hyena’s functions:


The Windows NT and Windows 2000 Resource Kits come with a number of command-line tools that help you administer your Windows NT/2K systems. Over time, I’ve grown a collection of similar tools, including some not included in the Resource Kits. What sets these tools apart is that they all allow you to manage remote systems as well as the local one.

The tools included in the PsTools suite, which are downloadable as a package, are:

  • PsExec – execute processes remotely
  • PsFile – shows files opened remotely
  • PsGetSid – display the SID of a computer or a user
  • PsInfo – list information about a system
  • PsPing – measure network performance
  • PsKill – kill processes by name or process ID
  • PsList – list detailed information about processes
  • PsLoggedOn – see who’s logged on locally and via resource sharing (full source is included)
  • PsLogList – dump event log records
  • PsPasswd – changes account passwords
  • PsService – view and control services
  • PsShutdown – shuts down and optionally reboots a computer
  • PsSuspend – suspends processes
  • PsUptime – shows you how long a system has been running since its last reboot (PsUptime’s functionality has been incorporated into PsInfo


  1. g just

    When some one searches for his required thing, therefore he/she
    needs to be available that in detail, therefore that
    thing is maintained over here.

  2. g will

    Normally I don’t learn post on blogs, but I would like to say that this
    write-up very pressured me to take a look at and do so!
    Your writing taste has been surprised me. Thank
    you, quite nice article.


    Very great post. I just stumbled upon your weblog and wanted to say that I’ve really loved surfing around your blog posts.
    In any case I’ll be subscribing to your rss feed and I’m
    hoping you write again very soon!

  4. cbd oil that works 2020

    Hey! I know this is somewhat off topic but I
    was wondering which blog platform are you using for this website?
    I’m getting sick and tired of WordPress because I’ve had problems with hackers and I’m looking at options for another platform.

    I would be awesome if you could point me in the direction of a good platform.

  5. Teri

    After looking at a few of the blog articles on your
    website, I seriously appreciate your technique
    of writing a blog. I book-marked it to my bookmark webpage list and
    will be checking back in the near future. Please check out my website too and tell me how you feel.

  6. Efrain

    We are a group of volunteers and starting a new scheme in our community.
    Your site provided us with valuable information to work on. You have done a formidable job
    and our entire community will be thankful to you.

  7. Zelda

    My partner and I stumbled over here from a different web address and thought I should check things out.
    I like what I see so i am just following you. Look forward to looking into your web page yet again.

  8. website host

    My brother suggested I might like this web site.
    He was totally right. This post truly made my day.
    You can not imagine simply how much time I
    had spent for this info! Thanks!

  9. best web hosting 2020

    Whats up this is kind of of off topic but I was wondering if blogs use WYSIWYG editors or if you have to manually code with HTML.
    I’m starting a blog soon but have no coding experience so I wanted to get
    advice from someone with experience. Any
    help would be enormously appreciated!

  10. best web hosting company

    Greetings! This is my 1st comment here so I just wanted to give a quick shout out and tell you I really enjoy reading your
    blog posts. Can you recommend any other blogs/websites/forums that cover the same topics?
    Thanks for your time!

  11. web hosting company

    Oh my goodness! Amazing article dude! Thanks,
    However I am having issues with your RSS. I don’t know the reason why I am unable
    to join it. Is there anybody else getting the same RSS problems?
    Anyone who knows the solution can you kindly respond?


  12. hosting services

    Wonderful beat ! I would like to apprentice even as you amend your website, how can i subscribe for a blog web site?
    The account helped me a appropriate deal. I had been a
    little bit acquainted of this your broadcast provided vivid clear idea

  13. best web hosting sites

    I know this if off topic but I’m looking into starting my own weblog and
    was curious what all is required to get setup? I’m assuming having a blog like
    yours would cost a pretty penny? I’m not very web smart so I’m not 100%
    positive. Any suggestions or advice would be greatly appreciated.
    Thank you

  14. Stevie Navaro

    you’re a great author.I will be sure to bookmark your blog and will eventually come back at some point. I want to encourage you to definitely continue your great posts, have a nice afternoon!

  15. web hosting providers

    Good day! I could have sworn I’ve visited this blog before but after going through
    some of the posts I realized it’s new to
    me. Nonetheless, I’m certainly happy I stumbled upon it and I’ll be book-marking it and
    checking back often!

  16. webhosting

    Hello there I am so glad I found your blog, I really found you by accident, while I was browsing on Yahoo for something else, Regardless I am here now and would just like
    to say thank you for a marvelous post and a all round enjoyable
    blog (I also love the theme/design), I don’t have time
    to look over it all at the moment but I have bookmarked it and also included your RSS feeds, so
    when I have time I will be back to read much more, Please do keep up the great b.

  17. cheap flights

    I just like the valuable info you provide on your articles.

    I’ll bookmark your blog and take a look at once more right here frequently.
    I am reasonably certain I’ll be told many new stuff right here!

    Good luck for the following!

  18. cheap flights

    Hey I know this is off topic but I was wondering if you knew of
    any widgets I could add to my blog that automatically tweet my newest twitter updates.
    I’ve been looking for a plug-in like this for quite some time and was hoping
    maybe you would have some experience with something like this.
    Please let me know if you run into anything.

    I truly enjoy reading your blog and I look forward to
    your new updates. cheap flights 3aN8IMa

  19. cheap flights

    After I initially left a comment I appear to have clicked on the -Notify me when new
    comments are added- checkbox and from now on each time a comment is
    added I receive 4 emails with the exact same comment.

    There has to be an easy method you are able to remove me from that service?

    Many thanks!

  20. black mass

    I have learn a few good stuff here. Definitely worth bookmarking for revisiting.
    I wonder how so much attempt you set to create this sort of
    great informative website.

  21. Denrok

    [url=]generic advair price[/url] [url=]zestoretic medication[/url] [url=]generic for flagyl[/url] [url=]price of tetracycline tablets in india[/url] [url=]where can i get antabuse[/url]

  22. Eyerok

    [url=]buy cialis 20mg uk[/url] [url=]buy tetracycline online usa[/url] [url=]order viagra uk[/url] [url=]dipyridamole capsules[/url] [url=]levitra 80 mg[/url] [url=]can you buy baclofen[/url] [url=]priligy online usa[/url] [url=]clopidogrel 25 mg[/url] [url=]tadalafil soft[/url] [url=]buy viagra 100mg online india[/url] [url=]atarax 40 mg[/url] [url=]anafranil 25 mg price[/url] [url=]tadalafil price in south africa[/url] [url=]suhagra 100mg price[/url] [url=]levitra canadian online pharmacy[/url] [url=]diclofenac gel prescription[/url] [url=]triamterene-hctz 75-50 mg[/url] [url=]trental 400 mg online[/url] [url=]discount viagra pills[/url] [url=]prozac canadian pharmacy[/url]

  23. life

    Rather than wгite aany extrа in regards to the biology of gallstones, I’d prefer to skip aⅼll that,
    аnd share what I’ve discoverеd over the previous couple of weeks about dwelling
    ѡith gallstones after getting them, and you don’t need suгgery.
    The turning plint ffor me was when fireman Aⅾib was кilⅼed in the course of
    the temple riot finaⅼ year. The laѕt straw for me was the
    best way they trid to justіfy Adib’s loss of life.
    I simply can’t forgѵive them, particularly for the way in which thedy reacted to thе inciԀent.

    For such folks the traineгs have cоme out with a brand neеw
    and fun strategy to drop somme pounds. Stuрidd statements from stupid ministers dayy in and day out.
    This info resembles а kind of biofeedback (eg,
    “Today your blood strain has been lowered to that of a nonsmoker.”), and the subject is further elaborated on the ᴡebsite of the day.
    Nowadays, people make tһeir objeϲtive pasѕwd ooff referring to having
    a property byy getting quite a lot off gym
    from tһese enterprіse, as these companies eхpertise on this
    markst and have nice communicational terminals wіth thee eaсh sort of
    occasions, involved to sale and interesteⅾ to get a land oor house.

  24. Carlrok

    [url=]100mg sildenafil price[/url] [url=]acyclovir medicine[/url] [url=]buy prednisolone online[/url] [url=]generic viagra coupon[/url] [url=]viagra 1500mg[/url]

  25. Denrok

    [url=]buy sildenafil online nz[/url] [url=]paroxetine hcl 20mg[/url] [url=]prevacid tablets price[/url] [url=]sildenafil 500 mg[/url] [url=]viagra in women[/url]

  26. Tara Schriefer

    I like the helpful info you provide in your articles.
    I’ll bookmark your blog and check again here frequently.
    I’m quite certain I will learn plenty of new stuff right here!
    Good luck for the next!

  27. Pingback: slipped viagra mom

  28. Pingback: viagra boner mom