Re: Help with possible hacker...

From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 12/31/02


From: "Karl Levinson [x y] mvp" <levinson_k@excite.com>
Date: Tue, 31 Dec 2002 16:26:18 -0500


"Tom Rossi" <TomRossi7@yahoo.com> wrote in message
news:cb00dd30.0212310622.4a922227@posting.google.com...
> I continue to get a group of login failures every few days. The login
> attempts spread all of the local accounts on one of my servers. I
> cannot tell from the security log the IP address of the hacker. Is
> there somewhere else I can look? Please help...
>
> Here is an example from the event log:
>
> 12/23/2002 12:18:25 PM Security Failure Audit Account Logon 681 NT
> AUTHORITY\SYSTEM SERVERNAME The logon to account: MemProxyUser1
> by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> from workstation: SPSERVER
> failed. The error code was: 3221226036
> 1

If you think you've been hacked, here's how to determine whether you have
and how it happened:

http://securityadmin.info/faq.htm#hacked

...then, how to re-secure and harden your computer:

http://securityadmin.info/faq.htm#re-secure [only necessary if you have
been hacked]
http://securityadmin.info/faq.htm#harden



Relevant Pages

  • Help with possible hacker...
    ... I continue to get a group of login failures every few days. ... attempts spread all of the local accounts on one of my servers. ... cannot tell from the security log the IP address of the hacker. ...
    (microsoft.public.win2000.security)
  • Re: Help with possible hacker...
    ... What does your firewall logs say? ... > I continue to get a group of login failures every few days. ... > attempts spread all of the local accounts on one of my servers. ...
    (microsoft.public.win2000.security)
  • Local Account Password Reset
    ... We have a bunch of standalone W2K machines with many local accounts. ... the servers, to our Customer Support department who handle customer calls. ... What is the best way for me to allow non-Admin level customer support folks ...
    (microsoft.public.win2000.security)
  • Re: Local user accounts disappear when moving member server to new domain (and forrest)
    ... Having moved literally hundreds of servers between domains I have never seen anything happen to local accounts. ... Both the old and new domains have Windows Server 2003 systems as the DCs. ... They've been using local user accounts on the Win2K TS servers for the terminal services users. ... the two domains are in different forrests as well. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to change PASSWORD expiration settings with command line?
    ... I have several LOCAL accounts created and i wanna to disable PASSWORD ... expiration via Script ... I found a Script (Modify a Local User Account So It Never Expires) in ... Servers that are not DC's do have local accounts. ...
    (microsoft.public.windows.server.scripting)