Weird Windows logon attempts

From: Harry Hoffman (hhoffman@ip-solutions.net)
Date: 02/24/03

  • Next message: Jacco Tunnissen: "Re: Weird Windows logon attempts"
    Date: Mon, 24 Feb 2003 13:27:54 +1300
    From: Harry Hoffman <hhoffman@ip-solutions.net>
    To: incidents@securityfocus.org
    
    

    Hi All,

    We have just setup ntsyslog from sourceforge.net. Our security policy is to log
    events on failure and we have just started seeing the below events. After
    talking with the users we are pretty sure that they are not attempting to access
    the services. And they don't have accounts on that system.

    Has anyone seen this? They are 2k/XP boxes. Does Windows 2k/XP automagically try
    to find out what services are accessible?
    Any insight would be great.

    The username has been changed to USERNAME to protect, the hopefully, innocent.

    Thanks,
    Harry

    Feb 22 13:27:49 exchange.auckland.ac.nz/exchange.auckland.ac.nz
    security[failure] 681 NT AUTHORITY\SYSTEM The logon to account: USERNAME by:
    MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: G731-220-4 failed. The
    error code was: 3221225572
    Feb 22 13:27:49 exchange.auckland.ac.nz/exchange.auckland.ac.nz
    security[failure] 681 NT AUTHORITY\SYSTEM The logon to account: USERNAME by:
    MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 from workstation: G731-220-4 failed. The
    error code was: 3221225572

    -- 
    Harry Hoffman
    ITSS Systems Team Leader
    University of Auckland
    hhoffman@auckland.ac.nz
    hhoffman@ip-solutions.net
    STANDARD DISCLAIMER:
    **********************************************
    *This universe shipped by weight, not volume.*
    *Some expansion may have occured in shipping.*
    *********************************************
    -------------------------------------------------
    This mail sent through IpSolutions: http://www.ip-solutions.net/
    ----------------------------------------------------------------------------
    Do you know the base address of the Global Offset Table (GOT) on a Solaris 8
    box?
    CORE IMPACT does.
    www.securityfocus.com/core
    


    Relevant Pages

    • Re: Unable to change domain password when logged in as local user
      ... all the user accounts "user must change password at next logon". ... Administrator account and created its password to match that person's ... login & password is the same as the domain login & pwd, ... I enter the username and password, ...
      (microsoft.public.windows.server.active_directory)
    • Re: Windows2000 Security event logs
      ... field is populated with a user account name, ... Windows Security Log logon events get mislabeled as malicious activity, ... >Subject: Windows2000 Security event logs ... >frame...same username and domain. ...
      (Security-Basics)
    • RE: cannot log on to user account following password change
      ... cannot log on to user account following password change ... I changed the username on the account in ... | on the sbs box. ...
      (microsoft.public.windows.server.sbs)
    • Re: logon failure
      ... MSSQLServer service after you change the username of administrator account. ... username for the SQL Server startup service account or the SQL Server Agent ... Microsoft SQL Server service account on the SQL Server host computer. ...
      (microsoft.public.windows.server.sbs)
    • RE: cannot log on to user account following password change
      ... home box with an existing local profile in conjunction with the sbs account. ... a local profile on the xp home box called Fiona Bavester had a username ...
      (microsoft.public.windows.server.sbs)