Unauthorized account listing from a remote system

From: Paul Haltenberg (haltenberg@yahoo.com)
Date: 11/04/02


From: haltenberg@yahoo.com (Paul Haltenberg)
Date: 4 Nov 2002 03:44:23 -0800

My security logs on Windows NT 4.0 SP6a servers show hundreds of 529
and 539 events for last night. Looks like someone outside my LAN
attempted to login with the credentials of every user in my domain
thus locking out user accounts. First of, I wonder how could this be
possible that someone obtained user list for my domain? Second, how
could someone attempt to login from a non-domain-member computer?
Third, how do I figure out who it was (even log shows workstation name
\\ATHLON2000XP, but I don't have such workstation in my domain)?
Fourth, how do I prevent this in the future?

Any advice/comment would be greatly appreciated!

---



Relevant Pages

  • Re: Event Logs
    ... Because someone tried to login into WHATEVER from TESTMACHINE. ... > I have been looking at the security logs on one of my workstations. ... > Successful Network Logon ... > Why would a logon event for the user test going to the workstation ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Unauthorized account listing from a remote system
    ... Looks like someone outside my LAN ... > attempted to login with the credentials of every user in my domain ... how do I figure out who it was (even log shows workstation name ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Cannot browse to a domain controller across windows domains
    ... There are no security audit entrys success ... > or failure in the security logs when I try to log on...as though the ... > workstation which I am trying to browse the DC with has never contacted ... > to the domain controller of the outside domain. ...
    (microsoft.public.windows.server.networking)
  • Re: File that manages login details
    ... I have created a number of users so that my friends and family may login to ... > Domain Controller Security Policy and logon events for Domain Security ... > security logs of multiple computer or buy a third party program that can ...
    (microsoft.public.security)
  • Re: Auditing Account Logons
    ... I'm seeing it in the security logs when logged directly on to the DC via ... remote desktop from a workstation. ... >> I need to audit when a user logs on to the domain from a workstation. ... >> workstation they are logging in from. ...
    (microsoft.public.windows.server.security)