I am getting continually hit with Port 137 Intrusion alerts (Windows Networking). What are these and what can I do?
Your ISP is passing other user’s chatty Windows Networking datagrams …which really are not a threat to the Mac user. They are more of a nuisance (and waste of bandwidth). Another possible source of these datagrams is the recent (October 2002) “bugbear” and “scrup” worms which invade Windows machines via email attachments. Once again, these intrusions do NOT directly attack Macs, but any such intrusion should certainly be considered an “unwanted guest”. For more information regarding the Bugbear worm, please see: W32.Bugbear@mm or I-Worm.Tanatos Port 137 Scans Windows continually broadcasts such datagrams just to see what other Windows are out there (in the “Windows Neighborhood”). Initially we included a trigger in the IPNetSentry Config file which would detect such datagrams and then block any access from these Windows machines. Afterall, most Mac users will have no need to have any Windows users see them on the public network. There are a couple of solutions to eliminate the intrus