Re: Help with possible hacker...

From: Joe Richards [MVP] (humorexpress@hotmail.com)
Date: 12/31/02


From: "Joe Richards [MVP]" <humorexpress@hotmail.com>
Date: Tue, 31 Dec 2002 12:02:09 -0500


The IP's are not natively available in W2K. They will be in Dot NET Server.
You can install firewall software or IDS software to help get this info now.

--
Joe Richards
www.joeware.net
---
"Tom Rossi" <TomRossi7@yahoo.com> wrote in message
news:cb00dd30.0212310622.4a922227@posting.google.com...
> I continue to get a group of login failures every few days.  The login
> attempts spread all of the local accounts on one of my servers.  I
> cannot tell from the security log the IP address of the hacker.  Is
> there somewhere else I can look?  Please help...
>
> Here is an example from the event log:
>
> 12/23/2002 12:18:25 PM Security Failure Audit Account Logon 681 NT
> AUTHORITY\SYSTEM SERVERNAME The logon to account: MemProxyUser1
>  by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
>  from workstation: SPSERVER
>  failed. The error code was: 3221226036
> 1


Relevant Pages

  • Re: user cant access OWA or RWW
    ... I filtered the Security log on the server using her name in the User box and unchecked Success. ... Now I see Event 533's for her account when I tried it this morning. ... There should be a couple of events during this login process. ...
    (microsoft.public.windows.server.sbs)
  • Re: Losing access to a shared folder
    ... I see no failures in the security log. ... Both shares are on the same file server. ... domain controllers as preferred and secondary dens servers. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: "Access Is Denied" when XPPro Client tries to Join Domain
    ... I didn't see an error in the security log when I received "Access is ... >> I added SBS2003 server and ran it through it config, ... >> domain users or administrators, and didn't assign a computer to them. ... and it had several folders being shared with the other PCs ...
    (microsoft.public.windows.server.sbs)
  • Re: dns server unable to open active directory
    ... Systems Administrator ... The Security Log is set to maximum size of 512 kb, ... Event Source: DNS ... The DNS server was unable to open the Active Directory. ...
    (microsoft.public.windows.server.active_directory)
  • Re: dns server unable to open active directory
    ... The Security Log is set to maximum size of 512 kb, ... Systems Administrator ... The DNS server was unable to open the Active Directory. ...
    (microsoft.public.windows.server.active_directory)