Re: Event ID 560

From: Kumar Pandit [MS] (kumarp@microsoft.com)
Date: 01/09/02

  • Next message: ME: "Re: need help deleting strange files!!!"

    From: kumarp@microsoft.com (Kumar Pandit [MS])
    Date: 09 Jan 2002 14:28:05 -0800
    
    

    Hi,
    The event indicates an attempt at enumerating accounts and/or creating
    groups over a null (anonymous) connection. Anonymous enumerations are
    usually the first step in remotely hacking a machine. You should
    disable anonymous access if you do not need it. See the article
    "Restricting Information Available to Anonymous Logon Users" in MSDN
    for more information.

    "viciousdog" <viciousdog@zdnetonebox.com> writes:

    > I keep getting Security Log entries for failed object access attempts by
    > NTAUTHORITY\ANONYMOUS for Event ID 560 and this description:
    >
    > Object Open:
    > Object Server: Security Account Manager
    > Object Type: SAM_DOMAIN
    > Object Name: <mydomain>
    > New Handle ID: -
    > Operation ID: {0,7260117} this ID varies from entry to entry
    > Process ID: 2161210400
    > Primary User Name: SYSTEM
    > Primary Domain: NT AUTHORITY
    > Primary Logon ID: (0x0,0x3E7)
    > Client User Name:
    > Client Domain:
    > Client Logon ID: (0x0,0x295B)
    > Accesses CreateGlobalGroup
    > LookupIDs
    >
    > Privileges -
    >
    >
    > There doesn't appear to be any pattern to the times the entries occur.
    >
    > Any ideas on what could be causing it?
    >
    >

    -- 
    Kumar Pandit
    Microsoft Security Developer
    

    (This posting is provided "AS IS" with no warranties, and confers no rights.)



    Relevant Pages

    • RE: Event ID 529 on cleint workstation
      ... Security Event ID 529 is a failure audit for logon/logoff. ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ...
      (microsoft.public.windows.server.sbs)
    • Re: Event ID 529 on cleint workstation
      ... "logon events" generate the events on domain controllers for domain account ... The Event 529 was caused by the machine account password not being ... I suggest that you re-join the client to ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • Re: NT4 -> Win2K3 question
      ... "not allow me logon to domain." ... I suspect you still unable to join the ... client into domain, right? ... Get Secure! ...
      (microsoft.public.windows.server.migration)
    • Re: windows client cant start completely...get blank desktop and no icons, start button, task bar, e
      ... Can you access the registry remotely from another workstation or the ... "Logon to the problematic client as a user who can logon to other ... Logon to a working client as the user who encountered the problem. ... not supported in newsgroup support. ...
      (microsoft.public.windows.server.sbs)
    • Re: windows client cant start completely...get blank desktop and no icons, start button, task bar, e
      ... "Logon to the problematic client as a user who can logon to other ... Logon to a working client as the user who encountered the problem. ... please check the following registry keys that define the ... not supported in newsgroup support. ...
      (microsoft.public.windows.server.sbs)

  • Quantcast