Re: Windows 2003 (IIS6) security question

From: David Wang [Msft] (someone_at_online.microsoft.com)
Date: 12/13/03


Date: Fri, 12 Dec 2003 20:23:24 -0800

IIS does cache user tokens (amongst many other things) for performance
reasons. You are not going to see a IUSR logon for every request.

Event logs entries like the ones you are concerned with are not going to DoS
your box since event logs usually recycles over itself. It's going to
possibly prevent you from carrying out repudiation, though.

-- 
//David
IIS
This posting is provided "AS IS" with no warranties, and confers no rights.
//
"ML.net" <mattlunzer@hotmail.com> wrote in message
news:eeR2CdFwDHA.1996@TK2MSFTNGP12.phx.gbl...
If you enable (success) auditing for "Audit Logon Events" or "Audit Account
Logon Events" will it log I_User account logon's? Obviously, my concern
would be for a high traffic web server getting an essentail DOS attack
against itself due to a high volume amount of logging in the security logs.
The descriptions on MS site don't say specifically either way...
TIA,
ML


Relevant Pages

  • RE: Account Lockout (Event ID: 539) Alert message
    ... >Subject: Account Lockout Alert message ... >SBS box with a subject just like the subject of this post. ... > For more information about this event, see the event logs on the server ... >Logon Failure: ...
    (microsoft.public.windows.server.sbs)
  • Re: OWA fails for all non-administators
    ... Certain users cannot log into the OWA system .. ... The event logs show this ... The server was unable to logon the Windows NT account 'joachim.reitman' due ... You may want to reapply the security settings. ...
    (microsoft.public.exchange2000.clients)
  • Security Log: Event ID 537 issue
    ... I support a SBS2003 Standard network at my wife's office and it has been ... An error occurred during logon ... of them) were turned on these errors starting appearing in the Event Logs ... than fifty times for these 2 Tablets. ...
    (microsoft.public.windows.server.sbs)
  • ADFS - Not Authorized To View Message
    ... I've gotten ADFS implemented to the point that I go to http://servername/certsrv ... It's not even possible to logon with domain/UPN is it? ... group claim and I mapped it an AD group. ... In my event logs on the web server there is an event 104 every time I ...
    (microsoft.public.windows.server.active_directory)
  • Re: RWW Monitoring
    ... logoff June VSXP Tue 22/02/2005 10:41:08.45 ... logon MickM VSXP Tue 22/02/2005 10:42:01.07 ... > network the openess of RWW, and the potential breach that> could ensue, You would think that someone or Microsoft would have set up a> more complete reporting - monitoring tool. ... If you users use RWW to logon to network, there will be>> following event in the event logs. ...
    (microsoft.public.windows.server.sbs)