Re: Anonymous change of passwords?

From: Benoit HAMET - MVP/MCP W2K (benoit.hamet_at_hametbenoit.fr.st)
Date: 05/21/03


Date: Wed, 21 May 2003 13:16:06 +0200


Hi

anonymous logon is used to open a session anonymous on your pc (for example
by IIS)

your message means that someone is trying to change this user account
password and he succed - maybe it will indicate that you have a security
breach because most of the time we don't change this account password define
by OS

(sorry for any English mystake)

--
Participez aux "Duo gagnant" :
http://register.microsoft.com/regsys/regsys.asp?wizid=6667&lcid=1036
=========================================
Benoit HAMET
MVP / MCP Windows 2000
www.hametbenoit.fr.st
support.microsoft.com
www.mvp.int.ms
"Gunnar Carlson" <gunnar.carlson@zipper.se> a écrit dans le message de news:
0dd601c31f89$487ce0b0$a101280a@phx.gbl...
> We have an account that is marked with "User cannot
> change password". In the security log I found the
> following events for that very account:
>
>
>
> 2003-05-19      13:36:48        Security        Success
> Audit   Account Management      627     NT
> AUTHORITY\ANONYMOUS LOGON    DC2003-1        "Change
> Password Attempt:
>         Target Account Name:    86tefirg
>         Target Domain:  SKOLA
>         Target Account ID:      SKOLA\86tefirg
>         Caller User Name:       ANONYMOUS LOGON
>         Caller Domain:  NT AUTHORITY
>         Caller Logon ID:        (0x0,0x972F)
>         Privileges:     -
> "
> 2003-05-19      13:36:48        Security        Success
> Audit   Account Management      642     NT
> AUTHORITY\ANONYMOUS LOGON    DC2003-1        "User
> Account Changed:
>         Target Account Name:    86tefirg
>         Target Domain:  SKOLA
>         Target Account ID:      SKOLA\86tefirg
>         Caller User Name:       ANONYMOUS LOGON
>         Caller Domain:  NT AUTHORITY
>         Caller Logon ID:        (0x0,0x972F)
>         Privileges:     -
>  Changed Attributes:
>         Sam Account Name:       -
>         Display Name:   -
>         User Principal Name:    -
>         Home Directory: -
>         Home Drive:     -
>         Script Path:    -
>         Profile Path:   -
>         User Workstations:      -
>         Password Last Set:      5/19/2003 1:36:48 PM
>         Account Expires:        -
>         Primary Group ID:       -
>         AllowedToDelegateTo:    -
>         Old UAC Value:  -
>         New UAC Value:  -
>         User Account Control:   -
>         User Parameters:        -
>         Sid History:    -
>         Logon Hours:    -
>
> I cannot interpret this in any other way than that the
> password has been changed. But how is that possible?  And
> what does the "ANONYMOUS LOGON" mean?
>


Relevant Pages

  • Re: DCOM access from a different domain (yes another accessdenied question)
    ... I still can't get anonymous logon to work, even when I enable the guest ... I originally hoped that having an account in the domain with a matching ... The guest account is disabled by default -- no anonymous logon. ... Restrict Anonymous access is enabled. ...
    (microsoft.public.win32.programmer.ole)
  • Re: XPSP 2 upgrade, now OE does not work, Messages:
    ... those errors denote problems on Hotmail's end. ... Has the account ever worked in OE? ... "transparent proxy server" which does not support WebDAV. ... (Anonymous Logon & Prompt for... ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Possible to run an ASP.NET page as ANONYMOUS LOGON?
    ... and I was hoping I could show the Anonymous Logon account instead of IUSR to ... default IUSR. ... impersonate noone and set a separate worker process identity in IIS6. ... I've explicitly granted access to this file to ANONYMOUS LOGON. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Log Information
    ... You might be able to look in your security log if your DCs if you had ... Description: User Account Deleted: ... Target Account ID: %3 Caller User Name: %4 ... Audit account management ...
    (microsoft.public.exchange.admin)
  • Re: Disabled IIS Anonymous account
    ... are authenticating with the IUSR_computername account. ... The anonymous logon ... events you are seeing are probably normal system "null" connections that are ... used by the browse service and other system network connections. ...
    (microsoft.public.win2000.security)