This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hello, I have many nbns queries in my network from all hosts looking up for 0.0.0.0/0

here is a sample capture : https://www.cloudshark.org/captures/c268dfd3e600 alt text

Any ideas on what's the origin ? The process sending this lookups is windows system process (pid 4)

asked 27 May '16, 00:39

Nicodonald's gravatar image

Nicodonald
6112
accept rate: 0%

edited 27 May '16, 02:41

grahamb's gravatar image

grahamb ♦
19.8k330206

Not really an Ask Wireshark question as Wireshark can't tell you anything about processes. I'll leave it open though as someone might have seen it before. You might get more help on a Windows networking forum.

(27 May '16, 02:25) grahamb ♦
Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×34
×31
×12
×12

question asked: 27 May '16, 00:39

question was seen: 1,003 times

last updated: 27 May '16, 02:41

p​o​w​e​r​e​d by O​S​Q​A