Re: Brute force attack but no IP's in log??

From: x y (x@y.com)
Date: 11/21/02


From: "x y" <x@y.com>
Date: Thu, 21 Nov 2002 09:44:51 -0500


"Rob" <mayan12@hotmail.com> wrote in message
news:eosTKgWkCHA.2848@tkmsftngp10...
> I have set the audit level to log all failed logins but the stupis thing
> doesnt show the IP of the attacker in the Event viewer /security.
> Am I missing something here?
> How do I get the actual IP of the attacker in the logs?
> Is this a hidden feature?
> Do I need a 3party software to track this? if so which one would you
> recommend

Yes, ideally a firewall. You'd then probably need to correlate the separate
log entries yourself using the timestamps in the two logs. Check out:

http://securityadmin.info/faq.htm#4.31
http://securityadmin.info/faq.htm#firewall



Relevant Pages

  • Brute force attack but no IPs in log??
    ... I have set the audit level to log all failed logins but the stupis thing ... doesnt show the IP of the attacker in the Event viewer /security. ... How do I get the actual IP of the attacker in the logs? ...
    (microsoft.public.security)
  • Re: Brute force attack but no IPs in log??
    ... Really no way of telling the IP in Event Viewer.? ... You get the Machines name but not IP. ... >> doesnt show the IP of the attacker in the Event viewer /security. ...
    (microsoft.public.security)