Differences between revisions 1 and 3 (spanning 2 versions)
Revision 1 as of 2005-03-20 15:56:33
Size: 1626
Editor: UlfLamping
Comment: use subpages
Revision 3 as of 2006-06-05 03:19:21
Size: 1631
Editor: localhost
Comment:
Deletions are marked like this. Additions are marked like this.
Line 12: Line 12:
 * ["TCP"]: NBSS uses ["TCP"] as its transport protocol. The wellknown TCP port for NBSS traffic is 139.  * ["TCP"]: NBSS uses ["TCP"] as its transport protocol. The well known TCP port for NBSS traffic is 139.
Line 16: Line 16:
XXX - Add example traffic here (as plain text or Ethereal screenshot). XXX - Add example traffic here (as plain text or Wireshark screenshot).
Line 18: Line 18:
== Ethereal == == Wireshark ==
Line 28: Line 28:
XXX - Add a simple example capture file to the SampleCaptures page and link from here. Keep it short, it's also a good idea to gzip it to make it even smaller, as Ethereal can open gzipped files automatically. XXX - Add a simple example capture file to the SampleCaptures page and link from here. Keep it short, it's also a good idea to gzip it to make it even smaller, as Wireshark can open gzipped files automatically.
Line 31: Line 31:
A complete list of NBSS display filter fields can be found in the [http://www.ethereal.com/docs/dfref/n/nbss.html display filter reference] A complete list of NBSS display filter fields can be found in the [http://www.wireshark.org/docs/dfref/n/nbss.html display filter reference]

NetBIOS Session Service (NBSS)

The NetBIOS Session Service is part of the NetBIOS-over-TCP protocol suite, see the ["NetBIOS"] page for further information.

History

XXX - add a brief description of NBSS history

Protocol dependencies

  • ["TCP"]: NBSS uses ["TCP"] as its transport protocol. The well known TCP port for NBSS traffic is 139.

Example traffic

XXX - Add example traffic here (as plain text or Wireshark screenshot).

Wireshark

The NBSS dissector is fully functional.

Preference Settings

(XXX add links to preference settings affecting how NBSS is dissected).

Example capture file

XXX - Add a simple example capture file to the SampleCaptures page and link from here. Keep it short, it's also a good idea to gzip it to make it even smaller, as Wireshark can open gzipped files automatically.

Display Filter

A complete list of NBSS display filter fields can be found in the [http://www.wireshark.org/docs/dfref/n/nbss.html display filter reference]

  • Show only the NBSS based traffic:

     nbss 

Capture Filter

You cannot directly filter NBSS while capturing. However, as it runs atop ["TCP"] port 139, you can filter on that one.

  • Capture NBSS traffic:

     tcp port 139 

Discussion

NetBIOS/NBSS (last edited 2008-04-12 17:51:24 by localhost)