RE: Virus is getting domain account listing

From: Samuel Petreski (petreski_at_ksu.edu)
Date: 05/10/04

  • Next message: David Carlin: "Re: Virus is getting domain account listing"
    To: "'David Carlin'" <djc6@cwru.edu>, <focus-ms@securityfocus.com>
    Date: Mon, 10 May 2004 09:26:07 -0500
    
    

    I would enable audit logging events in the Domain Security Policy and see
    which machines try to password guess your accounts and when. You will have
    to go through some logs, but it will be worth since you will see exactly who
    is logging and when, and how many failed logins per attempt.

    Samuel Petreski CCNA, MCSA
    petreski@ksu.edu

    -----Original Message-----
    From: David Carlin [mailto:djc6@cwru.edu]
    Sent: Monday, May 10, 2004 8:11 AM
    To: focus-ms@securityfocus.com
    Subject: Virus is getting domain account listing

    Hello,

    I work on a college campus and have been plagued for months by
    something that is going through all of the accounts in my domains and
    locking the accounts out by failed password attempts. I have two PDCs
    for two different domains, running NT 4.0 and clients running XP
    scattered around campus in various subnets. I have setup an ACL on my
    cisco switch to block traffic to the PDCs except from these subnets,
    but it doesn't help because there are machines in those subnets
    administered by other people that continue to get "infected".

    My question is, how do I stop whatever this is from getting my account
    listing in the first place? I have run Microsoft baseline analyzer, it
    says I'm all good.. The free Nessus scanner doesn't report any
    problems. I have all patches, RestrictAnonymous=1 is in the registry.

    I've renamed my admin account, this thing always picks up on it. It
    knows which accounts are domain admins and attacks them more
    aggressively. I've contacted the owners of the various machines
    attacking, they never find any strange software, virus scanners always
    come up empty - even when done remotely over the administrative shares.

    Any ideas how to protect my user list?

            -David

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: David Carlin: "Re: Virus is getting domain account listing"

    Relevant Pages

    • Re: Local Accounts
      ... All 3 users had accounts on all 3 computers. ... Well maybe true but when the client machines were not in a domain we had sofware installed that we did not want to reinstall when on the domain. ... The local admin account can be useful for some system changes, ...
      (microsoft.public.windows.server.sbs)
    • Re: Crypt questions
      ... For the right account it can be decrypted if both accounts have ... If the machines are not both ... If I encrypt the harddrives on ... will a theif be able to decrypt the data? ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Disabling Interactive Logon Against Security Group
      ... Essentially this is to secure half a dozen guest accounts on domain of ... question "disable interactive logon privilages against specific OU/User ... Where I follow least privilege this is a total non-issue, as the machines ... If you set this in a GPO then the list that is to be denied that you ...
      (microsoft.public.security)
    • Re: Terminal release ip command?
      ... Apart from networking between the two machines right:-) ... pick up a single DHCP address from your ISP, ... DHCP IP addresses on your own private network and NAT taking care ... the case of free dial-up accounts where an ISP may create far more ...
      (comp.sys.mac.system)
    • Re: Domain Users to have Local Admin rights
      ... Refreshed group policy on the other machines. ... machine, that kinda startup script? ... We have various admin accounts other then administrator ...
      (microsoft.public.windows.server.security)

  • Quantcast