Re: Security breach

From: Shenan Stanley (news_helper_at_hushmail.com)
Date: 02/18/04


Date: Tue, 17 Feb 2004 18:39:13 -0600

Annita wrote:
> I've been suspended from work because I was accused of creating some
> accounts without going through due procedure. I did not create the
> accounts. Even if someone knows my user admin password shouldn't they
> be able to tell from the security log:
> a) which machine they were logged into ('cos it can't have been mine,
> via the IP)
> b) what time and date it was done (and compare it to when I was on my
> machine)
> c) could someone have manipulated the security logs and is it
> traceable
> d) what other possibilities should I be investigating, as to how
> someone has used my machine/log in & does it help me if my company has
> key stroke logging?
>
> I have to go in on Friday to discuss this & I'd really appreciate some
> help

Until they present the proof that you created these accounts, you have
nothing to counter with. Although they can log some of the things you
mentioned, they may not.

Also, since they are the ones with the access to the computers at this
point, nothing you can actually say would mean too much, as they could
create pretty much whatever they wanted.

-- 
<- Shenan ->
-- 


Relevant Pages

  • Re: Authentication Auditing
    ... I do see an event in the DC1 or DC2 security log. ... I don't see an event in DC1, DC2 or IIS1 security log. ... >> to either domain or local machine accounts. ...
    (microsoft.public.win2000.security)
  • Security breach
    ... goal is to perform forensics work. ... >accounts without going through due procedure. ... Even if someone knows my user admin password ... >be able to tell from the security log: ...
    (microsoft.public.security)
  • Re: Local System Account & Network Access
    ... check the security log on the server that has the administrator share to see ... yet on planning security for service accounts. ... -- The Services and Service Accounts Security Planning Guide ... send commands to the service instructing it to install software packages ...
    (microsoft.public.security)
  • Security breach
    ... accounts without going through due procedure. ... be able to tell from the security log: ... what time and date it was done (and compare it to when I was on my ... what other possibilities should I be investigating, ...
    (microsoft.public.security)
  • Security Breach
    ... I've been suspended from work 'cos I was accused of creating some accounts without going through due procedure. ... Even if someone knows my user admin password shouldn't they be able to tell from the security log: ... what other possibilities should I be investigating, as to how someone has used my machine & does it help me if my company has key stroke logging? ...
    (microsoft.public.windowsxp.general)