Event Security

From: Michael J. Demirdjian (flu_shot@bigfoot.com)
Date: 10/17/02


From: "Michael J. Demirdjian" <flu_shot@bigfoot.com>
Date: Thu, 17 Oct 2002 08:52:10 -0400


Hi There,

We have a customer with a Windows 2000 Server and IIS, and it seems someone
is running a tools to try to guess the password because. The event viewer
kicks out a failed security audit every 3 seconds, and there is about 30
failed audits with random user names. This happens once or twice a
day.

The server sits behind a firewall but how can we get the IP Address of the
hacker preferably using the Windows 2000 server (event) audit service? Is
there a way to track this hacker?

The events id that kicks is something like 529 but there is no IP address.

You can tell the tool they are using is crude because of the type of
user names and domains it tries, but I still want to catch this person and
report
them!
Any help
Thanks
Mike



Relevant Pages

  • SecurityFocus Microsoft Newsletter #154
    ... MICROSOFT VULNERABILITY SUMMARY ... ISS RealSecure Server Sensor SSL Denial Of Service Vulnerabi... ... Roger Wilco Remote Server Side Buffer Overrun Vulnerability ... available for Microsoft Windows operating systems. ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #49
    ... Subject: SecurityFocus Microsoft Newsletter #49 ... Microsoft Windows NNTP Denial of Service Vulnerability ... Microsoft IIS SSI Buffer Overrun Privelege Elevation Vulnerability ... Microsoft ISA Server H.323 Memory Leak Denial of Service... ...
    (Focus-Microsoft)
  • Re: 2003 Web Server - Sicherheitsbedenken
    ... dass die Hauptgefahr nicht irgendwelche Top Hacker ... Er hat doch gar kein Interesse, sich irgend einen Server genauer anzusehen! ... Windows ist in meinen Augen sicherheitstechnisch nicht unbedingt ... Eine richtige Firewall ist etwas feines - und richtig heisst, ...
    (microsoft.public.de.german.windows.server.setup)
  • Questions Relating to Administering Windows 2000 Server
    ... installed the network client on the target computer. ... Sarah has been attempting to install Windows 2000 ... Server for two days. ... Sarah has checked the cables and hard drives. ...
    (microsoft.public.cert.exam.mcse)
  • Questions Relating to Administering Windows 2000 Server
    ... installed the network client on the target computer. ... Sarah has been attempting to install Windows 2000 ... Server for two days. ... Sarah has checked the cables and hard drives. ...
    (microsoft.public.cert.exam.mcse)