RE: Windows 2000 user login

From: Robinson, Sonja (SRobinson@HIPUSA.com)
Date: 03/27/03

  • Next message: securityfocus@not4not.mailshell.com: "Re: Security Approval Process"
    From: "Robinson, Sonja" <SRobinson@HIPUSA.com>
    To: "'Wright, Bill '" <bwright@ny.whitecase.com>, "'security-basics@securityfocus.com '" <security-basics@securityfocus.com>
    Date: Thu, 27 Mar 2003 15:07:49 -0500
    
    

     Dump your PDC logs using DumpEVT or similar. Search the log files for the
    users user name or by the MS Security Event Code. This will give you all of
    the computer names that his account is trying to be accessed from. So in
    other words you will locate HIS true machine, plus any machine that may have
    a script under his account or if someone is trying to brute force his
    account, etc. Your password policy of 30 days is fine and is not the cause.
    Most likely it is user disfunction or their is a script/batch file/process
    trying to use the account and he forgot about it- which still applies to
    user disfunction.

    -----Original Message-----
    From: Wright, Bill
    To: security-basics@securityfocus.com
    Sent: 3/26/2003 1:16 PM
    Subject: Windows 2000 user login

    I have never posted to this board, so hopefully I'm following the right
    procedures. My issue is that a user's account keeps getting locked out
    due to an aggressive password policy (30 days) and he claims that he
    isn't logged into multiple machines nor is he fat fingering his
    password. Is anybody aware of a product to find out where or how many
    Windows 2000 servers or workstations a user is logged into? My thinking
    is that he's logged into multiple machines under an old password that
    keeps locking him out.

    Thanks,
    Bill

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.surfcontrol.com/go/zsfsbl1

    **********************************************************************
    This message is a PRIVILEGED AND CONFIDENTIAL communication, and is intended only for the individual(s) named herein or others specifically authorized to receive the communication. If you are not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the sender of the error immediately, do not read or use the communication in any manner, destroy all copies, and delete it from your system if the communication was sent via email.

    **********************************************************************

    -------------------------------------------------------------------
    SurfControl E-mail Filter puts the brakes on spam,
    viruses and malicious code. Safeguard your business
    critical communications. Download a free 30-day trial:
    http://www.surfcontrol.com/go/zsfsbl1


  • Next message: securityfocus@not4not.mailshell.com: "Re: Security Approval Process"

    Relevant Pages

    • Re: Password expires for no apparent reason
      ... go to the server and run rsop.msc and check your password policy, ... expires' is set for each user. ... the minimum password age is there to prevent users from blowing ... As Harj said Account lockouts could potentially be a problem as perhaps the ...
      (microsoft.public.windows.server.active_directory)
    • Re: Valid password characters
      ... A good password policy should be combined with a good user name ditto. ... whereby an account would be disabled after a certain of unsuccessful ... The attack on this type of protection will not be a frontal attack ... without even the implied warranty of merchantability ...
      (microsoft.public.inetserver.asp.db)
    • Re: Password Policy for remote users
      ... There is only one password policy per domain or per machine. ... accounts, and this or the highest priority GPO setting account policies ... Change remote users passowrd to more complex. ...
      (microsoft.public.security)
    • password change problem
      ... top and want this password policy accross the domain. ... At first, all was fine, my users could ctrl-alt-delete ... change the password for the domain adminstrator account ... change and next log in, no problem works fine, just cant ...
      (microsoft.public.windows.group_policy)
    • RE: Password Audit Software by Microsoft
      ... Good to see that you've made headway on setting a good password policy by ... >> of the account should know the password. ... >> Mark Whitby ... >>> Does anyone know of a Microsoft download that allows domain administrators to ...
      (microsoft.public.windows.server.active_directory)

    Loading