Port 137NetBIOS Name Service
NetBIOS Name Service (NBNS) is an essential part of the NetBIOS protocol suite, primarily used for local network name resolution and registration in Windows-based environments. It enables networked devices to register their NetBIOS names and resolve others, facilitating communication across devices without relying on DNS..
- transport
- tcp · udp
- in transit
- cleartext
- assignment
- official
- risk
- 4/10
- lookups
- 12,737
2 transports registered
payload readable on path
registered with iana
caution
rank 304 of 993 · top 31%
Technical Details
what runs on :137NetBIOS Name Service (NBNS), operating typically on port 137, is fundamental in older Windows networking. NBNS handles the registration of NetBIOS names, making it possible for computers to broadcast their existence and for clients to resolve NetBIOS names to IP addresses within the same local network segment.
Historically, NetBIOS was developed for network communication over IBM PC Network and later extended in Windows networking architecture. NBNS acts similarly to DNS but for NetBIOS names, facilitating the association of network-layer IP addresses with application-layer NetBIOS names using broadcast or, with WINS, unicast queries.
In practice, NBNS exchanges take the form of UDP datagrams, but also include TCP fallback for larger transactions or specific service requirements. While newer Windows networks primarily use DNS alongside other discovery protocols, NBNS still persists as a legacy support feature, especially in mixed or legacy-heavy networks.
Security Information
exposure of :137risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
network services averages 3.9 across 604 ports — this one sits 0.1 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
official
registered with iana for this service — scanners fingerprint it by number
reachable over
tcp · udp
udp is connectionless — source addresses are trivially spoofed and it is a reflection favourite
security overview
Common Vulnerabilities:
- Susceptible to spoofing attacks when an attacker responds maliciously to NBNS queries
- Can be leveraged for poisoning attacks (NBNS spoofing), diverting traffic for man-in-the-middle (MITM) attacks
- Frequent target for information disclosure about internal network structure
Common Mitigations:
- Disable NetBIOS over TCP/IP when not required
- Implement internal network segmentation and firewalls to restrict port 137 traffic
- Use modern name resolution techniques like DNS and remove WINS servers
- Monitor network traffic for anomalous NBNS activity indicative of poisoning attempts
- Enable secure authentication protocols to mitigate MITM attempts
Related Ports
the 8 most looked-up other ports in network services — 604 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :9080 | Groove RPC | TCPUDP | Web Services | caution | 70.8k |
| :6543 | Jetnet | UDP | Network Services | caution | 65.3k |
| :5938 | TeamViewer | TCPUDP | Remote Access | caution | 65.0k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3233 | WhiskerControl Protocol | TCPUDP | Network Services | caution | 61.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Tatsoft Default HTTP Proxy | TCP | Web Services | caution | 46.8k |
risk mix of the 8 listed
- caution100%
0 of 8 encrypted