Re: Windows2000 Security event logs

From: Times Enemy (times_at_krr.org)
Date: 09/16/04

  • Next message: Kluge: "Re: learning ethical hacking"
    Date: Wed, 15 Sep 2004 16:50:02 -0700 (MST)
    To: <security-basics@securityfocus.com>
    
    

    Greetings.

    I have not personally dealt with this, but one source i often turn to,
    other than Google, is EventID.net to get a better grasp of what the heck
    MS is trying to tell me.

    http://eventid.net/display.asp?eventid=576&eventno=58&source=Security&phase=1

    Good luck!

    ciao
    .te

    > Hi All,
    >
    > Has anyone seen this type of Windows Security Event Log activity before?
    > This was found on multiple computers.... All within a 2 minute time
    > frame...same username and domain.
    >
    > EVENT ID: 576
    > Special privileges assigned to new logon:
    > User Name: username
    > Domain:
    > Logon ID: (0x0,0x5F893A8)
    > Assigned: SeChangeNotifyPrivilege
    >
    > EVENT ID: 540
    > Successful Network Logon:
    > User Name: username
    > Domain: DOMAIN
    > Logon ID: (0x0,0x5F893A8)
    > Logon Type: 3
    > Logon Process: Kerberos
    > Authentication Package: Kerberos
    > Workstation Name:
    >
    > EVENT ID: 538
    > User Logoff:
    > User Name: username
    > Domain: DOMAIN
    > Logon ID: (0x0,0x5F893A8)
    > Logon Type: 3
    >
    > One of the computers provided a source IP address so I have checked the
    > computer of the user in question for root kits, trojans, ect. It is
    > fully patched and has AV up to date
    >
    > thanks,
    > Dave
    >
    > ---------------------------------------------------------------------------
    > Computer Forensics Training at the InfoSec Institute. All of our class
    > sizes are guaranteed to be 12 students or less to facilitate one-on-one
    > interaction with one of our expert instructors. Gain the in-demand
    > skills of a certified computer examiner, learn to recover trace data
    > left behind by fraud, theft, and cybercrime perpetrators. Discover the
    > source of computer crime and abuse so that it never happens again.
    >
    > http://www.infosecinstitute.com/courses/computer_forensics_training.html
    > ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------


  • Next message: Kluge: "Re: learning ethical hacking"

    Relevant Pages

    • RE: Windows2000 Security event logs
      ... field really populated with the datum username or is ... Subject: Windows2000 Security event logs ... Special privileges assigned to new logon: ... Logon Type: 3 ...
      (Security-Basics)
    • Re: how to pass nt password ?
      ... i logon in xp, run the service locally on xp1 local machine. ... reach out to other machines having similar services and check whether it is ... f) the logonuser fucntion requires username, ... > with the minimum credentials required to operate). ...
      (microsoft.public.dotnet.languages.vb)
    • Re: Password access for folders over network
      ... the network logon always uses the currently logged on user ... but you *can* get it to prompt for the password. ... username, ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Data Type mismatch error?
      ... reference to the DAO ... > 'Your message/actions here for invalid logon ... >you have to step through every record in the recordset ... >> I have logon box which when the user enters a username ...
      (microsoft.public.access.modulesdaovba)
    • Re: Share Point & CRM
      ... I can see that when I try to logon the username area flicks to ... > SBS Newsgroups: ... >>> Installing and Securing Microsoft CRM 1.2 on a Windows Small Business ...
      (microsoft.public.windows.server.sbs)

    Loading