Net Send problem

Hello Everybody! We disabled messenger service in our school so pranksters won't use them to disrupt computer classes. However, I found out a couple of machines yesterday which were able to use the net send command to message a teacher's pc.

Everything New Technology 1823 This topic was started by ,


data/avatar/default/avatar36.webp

4 Posts
Location -
Joined 2003-05-02
Hello Everybody!
 
We disabled messenger service in our school so pranksters won't use them to disrupt computer classes. However, I found out a couple of machines yesterday which were able to use the net send command to message a teacher's pc. Those pc's messenger services were disabled (checked using mmc and net start), and nbtstat didn't show anything registered at [03]. So I'm naturally curious how this happend ;( . Any help is appreciated.

Participate on our website and join the conversation

You have already an account on our website? Use the link below to login.
Login
Create a new user account. Registration is free and takes only a few seconds.
Register
This topic is archived. New comments cannot be posted and votes cannot be cast.

Responses to this topic


data/avatar/default/avatar01.webp

738 Posts
Location -
Joined 2002-12-11
Quote:We disabled messenger service in our school so pranksters won't use them to disrupt computer classes. However, I found out a couple of machines yesterday which were able to use the net send command to message a teacher's pc. Those pc's messenger services were disabled (checked using mmc and net start), and nbtstat didn't show anything registered at [03].

netsvc \\machinename start messenger
net send Blah Blah
netsvc \\machinename stop messenger

Well thats only three lines of batch file code to get around that ... only issue is that it requires admin access to start a service ... has the admin account been compromised?

NET SEND uses NetBIOS, and the ports NetBIOS requires are 137, 138 and 139 ... either enable the firewall if you are using Windows XP or disable File and Printer Sharing

HTH

EDIT

I apologize, I misread your post and believed that you stopped the service and not disabled it. With that in mind, disregard the first half of my post.

Have you also considered using IPSEC policies to restrict the use of those ports and/or IPs?

data/avatar/default/avatar36.webp

4 Posts
Location -
Joined 2003-05-02
OP
Thanx for the advice, DS3Circuit.
 
To clarify, I was able to use net send with a student lab account.
 
I am not familiar with IPSec, but the teachers share a lot of teaching material on a server using file and print sharing, so I am not sure if restricting the netbios ports would also disable file and print sharing.
 
Oh, we are using win2k.

data/avatar/default/avatar19.webp

690 Posts
Location -
Joined 2000-05-21
Yeah, disabling the messenger service prevents you from receiveing messages; it does not prevent you from sending them.

data/avatar/default/avatar36.webp

4 Posts
Location -
Joined 2003-05-02
OP
Ha, you are right.
 
Well, we are upgrading anyway. This time we'll make sure the service is disabled when we deploy the new systems.

data/avatar/default/avatar01.webp

738 Posts
Location -
Joined 2002-12-11
Quote:the teachers share a lot of teaching material on a server using file and print sharing, so I am not sure if restricting the netbios ports would also disable file and print sharing.

As an addition, disabling/removing file and printer sharing from client workstation will not hinder their ability to retrieve files from a Print/File Server.

data/avatar/default/avatar36.webp

4 Posts
Location -
Joined 2003-05-02
OP
thanx again for your help, Xiven and DS3Circuit.