> Is there any *valid* reason to see UDP traffic directed at a unix box's
> port 137 coming from IP sources across the internet ? The unix servers in
> question are most definitely *not* running samba, and there is absolutely no
> NT anywhere on this customer's network (that is seeing the incoming UDP
> traffic directed at an IP destination address on port 137). (A couple of 95
> boxes scattered across an Ethernet comprise the Micro$oft part of the
> network). None of the 95 boxen are running any file or print serving (sharing)
> resources.

Are you shure these don't have ip broadcast addresses on them?  I've seen 
MS UDP packets with as the destination address if the
WIN box isn't set up reasonably.
> I can't think of any valid reason to see this traffic, personally. Anybody out
> there that can present a scenario where I would expect to see these UDP
> packets coming back in ?
> netbios-ns      137/tcp         nbns
> netbios-ns      137/udp         nbns
> netbios-dgm     138/tcp         nbdgm
> netbios-dgm     138/udp         nbdgm
> netbios-ssn     139/tcp         nbssn
