Virus is getting domain account listing

From: David Carlin (djc6_at_cwru.edu)
Date: 05/10/04

  • Next message: shimi: "Re: Virus is getting domain account listing"
    To: focus-ms@securityfocus.com
    Date: Mon, 10 May 2004 09:10:54 -0400
    
    

    Hello,

    I work on a college campus and have been plagued for months by
    something that is going through all of the accounts in my domains and
    locking the accounts out by failed password attempts. I have two PDCs
    for two different domains, running NT 4.0 and clients running XP
    scattered around campus in various subnets. I have setup an ACL on my
    cisco switch to block traffic to the PDCs except from these subnets,
    but it doesn't help because there are machines in those subnets
    administered by other people that continue to get "infected".

    My question is, how do I stop whatever this is from getting my account
    listing in the first place? I have run Microsoft baseline analyzer, it
    says I'm all good.. The free Nessus scanner doesn't report any
    problems. I have all patches, RestrictAnonymous=1 is in the registry.

    I've renamed my admin account, this thing always picks up on it. It
    knows which accounts are domain admins and attacks them more
    aggressively. I've contacted the owners of the various machines
    attacking, they never find any strange software, virus scanners always
    come up empty - even when done remotely over the administrative shares.

    Any ideas how to protect my user list?

            -David

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: shimi: "Re: Virus is getting domain account listing"

    Relevant Pages

    • Re: Being hacked...
      ... You sound a litle vauge on your firewall protection. ... The fact that ALL your accounts are locked out tells me that either ... these attacks are coming from. ... I've installed an event log analyzer to help with event log ...
      (microsoft.public.win2000.security)
    • Re: looking for tools/scripts to clean up unused AD accounts
      ... looking for tools/scripts to clean up unused AD accounts ... Audit your website security with Acunetix Web Vulnerability Scanner: ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: How effective is a Limited User Account?
      ... Then there is software where the security holes are actually features - see ... attacks, and other attacks. ... bypassing limited user ... Limited User Accounts are very effective in ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Virus is getting domain account listing
      ... If this stuff is remote, nothing will help you in blocking the DCs from ... MICROSOFT SERVICES from the outside world. ... you can lock accounts through them) to the outside world, ... > knows which accounts are domain admins and attacks them more ...
      (Focus-Microsoft)
    • Being hacked...
      ... nor have the attacks dimminished. ... I have the accounts locked out forever ... are we really being attacked twice, ... the lock outs while we are unlocking, causing both DC to show locked ...
      (microsoft.public.win2000.security)