Re: source of Failure Audits is Default Web Site



Well, I'm posting because I don't understand what's wrong. If someone is
trying to crack the Admin account, whatever they are doing depends on having
the Default Web Site up and running on this member server, because stopping
that website stops these errors. I am guessing that the IUSR_SVR1 account
somehow tries to use NT AUTHORITY\SYSTEM, causing the Logon attempt by
MICROSOFT_AUTHENTICATION_PACKAGE_V1_0, whose Logon account is Administrator.
But maybe I'm misreading the Event Log.

Bottom line, I just want these websites to work, without filling the Event
Log on the DC.
________
Greg Stigers, MCSA
remember to vote for the answers you like


.



Relevant Pages

  • Another security question/issue.
    ... I get daily hits to the disabled admin account. ... Event log tells me they ...
    (microsoft.public.windows.server.sbs)
  • RE: Solution: web application can not access event log
    ... I create the event log and source using an admin account and have no problem ... I am using integrated windows authenticaiton in IIS and windows ...
    (microsoft.public.dotnet.security)
  • Re: Event Logging from ASP.NET
    ... create using program that runs under Admin rights. ... user to first run some type of desktop app, ... under Admin account. ... Then your ASP.NET will be able to write into event log. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Event Logging from ASP.NET
    ... it only once simply have a desktop program that does it and run it under ... Admin account. ... Then your ASP.NET will be able to write into event log. ... Can you write if you are using the ASP.NET account or Network Services ...
    (microsoft.public.dotnet.framework.aspnet)