Guest is made Administrator

From: Ferris (mshelp@ferrishall.com)
Date: 06/11/02


From: "Ferris" <mshelp@ferrishall.com>
Date: Mon, 10 Jun 2002 16:37:28 -0700


Having a security problem: the Guest account (previously
diabled) is constantly enabled, password changed, and
added to the Administrator Group. Happens about 5 times
randomly throughout the day. The event log shows each -
User: NT AUTHORITY\SYSTEM
Event ID: 628 (password set), 642 (Account Changed, added
to Admin Group)
Running IIS 5, MailMarshal, BlackIce,...
Have virus scanner and patches up to date. The Guest
account has never been accessed/logged-on as far as I can
tell.
Anyone know of a hack, virus or legit reason that would
cause the Guest acount to be so popular?
Most importantly, anyone have thoughts to stop it or a
work around?
Many thanks, Ferris



Relevant Pages

  • Re: Guest is made Administrator
    ... the Guest account (previously ... >> added to the Administrator Group. ... >> Have virus scanner and patches up to date. ...
    (microsoft.public.win2000.security)
  • Re: Guest is made Administrator
    ... the Guest account (previously ... > added to the Administrator Group. ... > Have virus scanner and patches up to date. ...
    (microsoft.public.win2000.security)
  • Re: Guest is made Administrator
    ... the Guest account (previously ... > added to the Administrator Group. ... > Have virus scanner and patches up to date. ...
    (microsoft.public.win2000.security)
  • Re: Guest is made Administrator
    ... You might try just renaming the guest account. ... (And it does sound like Nimda) ... > added to the Administrator Group. ... > Have virus scanner and patches up to date. ...
    (microsoft.public.win2000.security)
  • Re: Allowing file share browsing for un-authenticated users
    ... It seems that if I simply enable the guest account on my Server ... Guest account still allows me to enumerate file shares so that Network ...
    (microsoft.public.windows.server.general)