Re: Brute force attack but no IP's in log??

From: Rob (mayan12@hotmail.com)
Date: 11/21/02


From: "Rob" <mayan12@hotmail.com>
Date: Thu, 21 Nov 2002 09:47:10 -0500

Really no way of telling the IP in Event Viewer.?
Ok lets think about this.
You get the Machines name but not IP. hmmmmm

Why am I not surprised?
Oh well.

"x y" <x@y.com> wrote in message news:eRQVLzWkCHA.2460@tkmsftngp10...
>
> "Rob" <mayan12@hotmail.com> wrote in message
> news:eosTKgWkCHA.2848@tkmsftngp10...
> > I have set the audit level to log all failed logins but the stupis thing
> > doesnt show the IP of the attacker in the Event viewer /security.
> > Am I missing something here?
> > How do I get the actual IP of the attacker in the logs?
> > Is this a hidden feature?
> > Do I need a 3party software to track this? if so which one would you
> > recommend
>
> Yes, ideally a firewall. You'd then probably need to correlate the
separate
> log entries yourself using the timestamps in the two logs. Check out:
>
> http://securityadmin.info/faq.htm#4.31
> http://securityadmin.info/faq.htm#firewall
>
>
>
>



Relevant Pages

  • Re: New XP box will only boot in safe mode?
    ... Also, this is happening on two identical, new machines with the ... combination does boot in normal mode. ... You can access Event Viewer by selecting Start, Administrative Tools, ... done I had to install a couple of applications that some of the ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: New XP box will only boot in safe mode?
    ... What versions of eCopy are on the older machines that ... Also, this is happening on two identical, new machines with ... combination does boot in normal mode. ... You can access Event Viewer by selecting Start, ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Windows task manager
    ... I will have to do it on around 80 machines. ... There no such errors on the event viewer. ... information (the same as in Windows task manager) using script. ... >> all applications in the computer when the computer starts slowing down. ...
    (microsoft.public.windowsxp.basics)
  • Re: New XP box will only boot in safe mode?
    ... What versions of eCopy are on the older machines that ... Also, this is happening on two identical, new machines with ... combination does boot in normal mode. ... You can access Event Viewer by selecting Start, ...
    (microsoft.public.windowsxp.help_and_support)
  • RE: Virus is getting domain account listing
    ... The Event Viewer logs on the PDC's was the way ... I was able narrow down which machines the Failed logon request was ... I found that the Virus definitions on those machines were ... Virus is getting domain account listing ...
    (Focus-Microsoft)