users locked out spontaneously...

From: Patrick M. Ring (cyclops@)
Date: 10/31/02


From: "Patrick M. Ring" <cyclops@<nospam>louisianawebhost.com>
Date: Wed, 30 Oct 2002 23:09:07 -0600


I run a small web hosting and presence provision company. Our servers are
Windows 2000 (sp2) and we have separate servers running DNS, IIS (5),
Exchange (5.5sp4), etc. The domain model basically has one "PDC" (or active
directory equivalent) with the others getting the replicated security, AD,
and DNS information.

The problem is this: Twice now, I have had instances where not just one or
two, but ALL users are for no apparent reason locked out of their accounts
(Win2K).

Is it possible that someone has hacked far enough to get the usernames of
the accounts?

What is possibly happening? Are there any articles or security measures I
might be missing?
>> I have tried to take as much into account as possible, but these holes
are discovered daily....

Thanks in advance,
Patrick M. Ring
cyclops@louisiana<nospam>webhost.com