User accounts locked out

From: Rick Hawkes (mediawebrick@hotmail.com)
Date: 01/05/03


From: "Rick Hawkes" <mediawebrick@hotmail.com>
Date: Sat, 4 Jan 2003 21:05:06 -0800


Greetings!

I am running Win2K server, fully up-to-date software wise,
I think. I was looking at the Security log the other day
and noticed a lot of failed logon attempts. Then I put a
security policy in to lock out the user accounts after
three bad password attempts, and in a matter of hours, all
the user accounts were locked out.

I am not using active directory, just local users.

The server is a web server, running IIS 5, lots of front
page sites, RhinoSoft Serv-U for ftp. It's also running
SQL 7.0 SP3.

Clearly someone is trying to break in.

1) How on earth do they know what user accounts I have on
my system

2) How could they be getting in to attempt to logon?
Terminal services? If so, can I stop that service without
losing functionality?

Is there some way I can find out where the attempt to
logon is coming from?

Obviously I don't want unauthorized logins to the system.
Can anyone give me an idea what to do? It's a little
unnerving to have this happening.

...Rick...



Relevant Pages

  • Re: The very strange problem about Win XP and Win 2K server
    ... You need to have auditing of account logon and /or logon events for success ... and failure enabled before you will see anything in the security log of the ... server which you can do in Local Security Policy. ...
    (microsoft.public.win2000.security)
  • RE: security logon failures
    ... We are a small company with only one server and the ... The security log on the event ... Firstly, I want to explain that, If audit logon is enabled on SBS server, ... will be generated in security log. ...
    (microsoft.public.windows.server.sbs)
  • Re: Domain password change policy
    ... W2003 allows you to change multiple user accounts as you need to in bulk, ... Keep in mind that when you enable the change, any passwords already older ... I would also suggest enabling audting of account logon ... You can then view the security log in Event Viewer ...
    (microsoft.public.win2000.group_policy)
  • Re: The very strange problem about Win XP and Win 2K server
    ... When I logged on to the server from my remote PC there are no errors report. ... I go to the server to see the security log and there also no error recorded. ... > auditing of logon events in the Local Security Policy of the Windows 2000 ... >> There are all logged on OK, but if we run above command from a Win XP PC. ...
    (microsoft.public.win2000.security)
  • NT AUTHORITYANONYMOUS LOGON
    ... I noticed in Event Viewer's Security Log of a Windows 2000 Server PC the ... Event Type: Success Audit ... User Name: ANONYMOUS LOGON ... That server is connected to the Internet via a DSL line through a DSL router ...
    (microsoft.public.win2000.security)