Re: Can Somone Tell Me If We Have a Hacker?



Been getting quite a few of these myself ..... everything from IIS to FTP to
SMTP (most common is my SMTP server). As with yourself however, I tend to
use quite complex pw's that are changed twice daily.

--
Regards

Steven Burn
Ur I.T. Mate Group
www.it-mate.co.uk

Keeping it FREE!

"razor" <razor@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:7BF4A62E-0BE8-4A57-AD23-147AA71AB5C3@xxxxxxxxxxxxxxxx
Hello--

I am pasting an event log from our IIS/web server that repeats about 50
times every day during non-business hours. Our SQL administrator seems to
believe that somone is trying to hack into our system via FTP.

Can somone tell me if the below is a hacker, and what we can do about it?

Event Type: Warning
Event Source: MSFTPSVC
Event Category: None
Event ID: 100
Date: 6/25/2006
Time: 12:45:25 PM
User: N/A
Computer: PWARDELLIIS
Description:
The server was unable to logon the Windows NT account 'Administrator' due
to
the following error: Logon failure: unknown user name or bad password.
The
data is the error code.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 2e 05 00 00 ....

Many thanks,

sd




.



Relevant Pages

  • Re: Can Somone Tell Me If We Have a Hacker?
    ... I wish we could track the IP, but it is not in the logs and we currently ... FTP server" which is probably not an option. ... Can somone tell me if the below is a hacker, and what we can do about it? ...
    (microsoft.public.inetserver.iis.security)
  • Re: Port Forwarding
    ... I plan to close all the ports I can, once I know what ports the mx ... As for the FTP server being in the DMZ, I am planning that once I ... even the smtp server I setup ...
    (microsoft.public.exchange.setup)
  • Re: Port Forwarding
    ... I plan to close all the ports I can, once I know what ports the mx record my ... The FTP server is not high on my list of things to sort right now. ... and a ftp & smtp server on another. ...
    (microsoft.public.exchange.setup)
  • KB893066 Update
    ... If the KB893066 update installs on my machine, I am no longer able to: ... send emails through my smtp server ... access the ftp or web based access for uploading files to my homepage ...
    (microsoft.public.windows.mediacenter)
  • Help with IPFW + NATD + Passive FTP
    ... passive FTP connections through IPFW with NATD enabled. ... $cmd 005 allow all from any to any via dc0 ... # Interface facing Public internet ... # Allow out access to my ISP's Domain name server. ...
    (freebsd-questions)