Re: pls help

From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 03/13/03


From: "Karl Levinson [x y] mvp" <levinson_k@excite.com>
Date: Thu, 13 Mar 2003 16:10:58 -0500

Linksys routers can usually be configured to use syslog to capture the logs to a free syslog client on a computer, such as www.wallwatcher.com or www.kiwisyslog.com I would recommend that, as this is going to be your best way of getting IP addresses going forward. [You are probably not going to get the IP addresses for the devices that already attempted to access your network.] www.sygate.com, www.kerio.com, www.agnitum.com and www.zonealarm.com are free firewall software that may also be useful.

It would seem that you have no firewall or your firewall is not blocking Netbios traffic. You would want to fix this. www.linksys.com and www.netgear.com have firewalls starting around $80 US. www.netscreen.com 5XP is a much better firewall starting around $550 US.

You'd also want to secure the computers on your network, especially the OWA / SMTP / IIS server or servers:

http://securityadmin.info/faq.htm#harden

To look for more information on potential hacking, see here:

http://securityadmin.info/faq.htm#hacked
http://securityadmin.info/faq.htm#re-secure

If you want to start getting advanced, you could also try learning how to use a sniffer:

http://securityadmin.info/faq.htm#sniffer

Or use Snort or another free or not-free software for intrusion detection:

http://securityadmin.info/faq.htm#ids

  "Huzaif" <huzaif@ahmedgroup.co.uk> wrote in message news:uL7Ic$V6CHA.1732@TK2MSFTNGP12.phx.gbl...
  hi all Gurus,

  I have since yesterday had so many events in my security logs for users and workstatiosn which are not even in my LAN
  event are as follows .......every 3 minutes
  ***************************************
  Event id : 681
  category is account logon

  The logon to account: ibm

  by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0

  from workstation: ASYLUM

  failed. The error code was: 3221225572

  ********************************************************************

  The logon to account: cynthia

  by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0

  from workstation: AGUPTA

  failed. The error code was: 3221225572

  ********************************************************************

  and all sorts of random users and computer names are coming up so i have no idea what is happening and i cant even trace them as this event log does not tell me the ip address my server is behind a Linksys router so no luck of professisonal logs and tracks as i genrally fidn peopel doigna port scan so is there a way to catch from where in the world all this is happening from and secondly how do i get the ip addres of these people

  The server is hosting OWA and company website and SMTP relay server which is another one next to it I a not gettignthe same logs on the other server i.e. NS02

  but NS01 is getting all the security logs as above..... pls help

  Huzaif



Relevant Pages

  • Re: assign new user to workstation
    ... I understand that you create a new account ... workstation thru the Add User Wizard. ... we can logon each workstation with each domain user ... What error do you get when you try to logon OWA? ...
    (microsoft.public.windows.server.sbs)
  • Re: assign new user to workstation
    ... I do not think the underscore in the account name will cause ... must change password at next logon" is enabled. ... After the user logon workstation and change the ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • The local policy of this system does not permit you to logon interactively
    ... workstation administrator rights. ... computer joins a domain - the domain administrator becomes ... the local administrator has logon rights to the sytem. ... > administrator account nor with my alternative account ...
    (microsoft.public.win2000.security)
  • Re: auditing 1 AD account
    ... Blank workstation name usually means the login is coming from a non-windows ... > workstation name the user is trying to logon at, ... >>password, locking out the account. ...
    (microsoft.public.win2000.security)
  • Account Lockout
    ... My account has been locked out. ... Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 ... Source Workstation: NET-ADMIN ... Error Code: 0xC000006A ...
    (microsoft.public.windowsxp.security_admin)