NT user list publically available?

From: Joey Ramone (tenrecandrew@hotmail.com)
Date: 12/22/02


From: tenrecandrew@hotmail.com (Joey Ramone)
Date: 22 Dec 2002 14:14:22 -0800

I've been unable to find information about this... On our NT 4.0
(.1381) server that is on the internet, periodically I'll find that
most of the accounts have been locked out. Checking the event viewer
shows a ton of these sort of entries:

Source: Security
User: NT Authority\system
Type: Failure audit
Category: logon/logoff
Logon failure: Unknown username or bad password
User name: Administrator
Domain: CHAPEL-W9Z3B8E
Logon Process: KSecDD
Workstation Name: \\CHAPEL-W9Z3B8E

The strange thing is, some of the names it's logging on as are not the
type that one could reasonably guess, and I don't see logon attempts
for combinations of non-user names. It seems that either a) non-user
names aren't logged or more likely b) someone has found a way to get a
list of usernames on the server. Is this a known hole that I haven't
patched yet?

Thanks a lot for any input

Andrew



Relevant Pages

  • Re: Please help refresh my memory on AD DC
    ... When I boot my Laptop I reach the Logon screeen for XP Laptop and here ... admin account to be able to Login so I can control it from the DC. ... A domain user can by default logon to any domain computer, except Domain controllers. ... A Server has websites already hosted on it in a Workgroup and now I ...
    (microsoft.public.windows.server.active_directory)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.dns)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.networking)
  • RE: Problems with 529 Events
    ... attempting to logon on some services on the SBS server. ... and then click Account Lockout Policy. ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon Server Unavailable
    ... There are currently no logon servers available to service ... You use a office laptop to connect the office VPN, when you map a network ... you may receive this message: "This account is the ... The server is not configured for transactions"> "A domain controller for your domain could not be contacted" ...
    (microsoft.public.windows.server.general)