RE: c2 failed login correlation to an origination IP/host ?

From: John Bell (jbellnewsposts_at_hotmail.com)
Date: 06/23/05

  • Next message: BC DBA: "RE: Restricting Access to BUILTIN\Administrators"
    Date: Thu, 23 Jun 2005 00:19:01 -0700
    
    

    Hi

    A guess... but can you link this into your firewall logs somethow?

    John

    "Simo Sentissi" wrote:

    > hey there
    >
    > I wanted to know how people correlate a failed login attempt from within sql
    > logs or c2 logs and the origination address. I am thinking maybe people
    > looks at the events logs, but do those say what are the connections from
    > wich the failed loging started ??
    >
    > I am in a dillema !
    >
    >
    >


  • Next message: BC DBA: "RE: Restricting Access to BUILTIN\Administrators"

    Relevant Pages

    • Auth.log
      ... My daily cron jobs recently ... did a thorough check and determined that the failed login attempt ... all logs, especially security related logs... ... Gerhardt Information Technologies ...
      (freebsd-questions)
    • RE: c2 failed login correlation to an origination IP/host ?
      ... "Simo Sentissi" wrote: ... > I wanted to know how people correlate a failed login attempt from within sql ... > logs or c2 logs and the origination address. ...
      (microsoft.public.windows.server.security)
    • c2 failed login correlation to an origination IP/host ?
      ... I wanted to know how people correlate a failed login attempt from within sql ... logs or c2 logs and the origination address. ...
      (microsoft.public.sqlserver.security)
    • c2 failed login correlation to an origination IP/host ?
      ... I wanted to know how people correlate a failed login attempt from within sql ... logs or c2 logs and the origination address. ...
      (microsoft.public.windows.server.security)
    • RE: FW/IPS log correlation software
      ... As part of our Managed Security Services, we manage multiple enVision platforms and have successfully written alerts that correlate IPS/FW logs. ... Once you adopt an alert rule creation methodology possible within enVision and research the relevant message ID's, half the battle is done - also, testing various scenarios and thresholds is key. ...
      (Security-Basics)