Re: What is NtLmSsp?

From: Steven L Umbach (n9rou@attbi.com)
Date: 04/15/03


From: "Steven L Umbach" <n9rou@attbi.com>
Date: Tue, 15 Apr 2003 01:16:33 GMT


        Someone is trying to log onto that computer as administrator from
the network. It could be the internet or a lan computer. NtLmSsp means it is
trying to use ntlm to log on, which pretty much rules out W2K/XP domain
machines if you have a domain. Try to ping computername. If it on lan you
will probably resolve it if computer is still on and connected. If you are
connected to the internet and do not have a firewall, you need one. If it is
coming from the lan you should be able to track them down and do whatever it
is you do to people trying that stuff. To catch a lan hacker you could
configure a software firewall on your computer and log activity on ports 139
and 445 and compare entries in firewall log to failed authentication
attempts. --- Steve

http://securityadmin.info/faq.htm#firewalls
http://securityadmin.info/faq.htm#harden
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/com/htm/sec
urity_9qgg.asp

"Jason Cochrane" <jason@*spam*dpskc.com> wrote in message
news:e6bcJksADHA.1888@TK2MSFTNGP12.phx.gbl...
> In my Security Log, I have several failed attempts to logon to my network.
> Here is an example of the Event Properites:
>
> ***************************
> Type: Failure
> User: NT AUTHORITY\SYSTEM
> Source: Security
> Category: Logon/Logoff
> Event ID: 529
> Reason: Unknown user name or bad password
> User Name: Administrator
> Domain: ALAN
> Logon Type: 3
> Logon Process NtLmSsp
> Authentication Package: NTLM
> Workstation Name: \\ALAN
>
> **********************************************
>
> I would like to find out what IP this person is using so I can block it,
or
> find out where it is coming from. What is the logon process NtLmSsp? I
> have not seen this phrase before. Also, how can I block people from
trying
> this?
>
> Thx,
>
> Jason
>
>



Relevant Pages

  • Re: Moving Exchange Server
    ... Placing them in the LAN gives internal users 100% access with no firewall to ... DMZ, thus 0% risk/ports open between them. ... If Microsoft Exchange and/or Active Directory cannot run ... >> Internet is better? ...
    (microsoft.public.exchange.setup)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... > My LAN is configured with static IP addresses, ... > I have full connectivity with the internet from every machine on my ... > # Allow out access to my ISP's Domain name server. ... > # Interrogate packets originating from the public internet ...
    (freebsd-questions)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)

Quantcast