Hacker

From: Ed Kipp (ekipp_at_ucsd.edu)
Date: 05/01/03


Date: Thu, 1 May 2003 10:04:45 -0700


It's very difficult to determine where the login attempts
are coming from, but an important thing to do is to make
sure that RestrictAnonymous is enabled at it's highest
level so a hacker cannot enumerate your account list.
Many of the recent attacks we've seen on our network have
a list of seven or eight accounts, some may exist on your
network and some may not. The best defense seems to be
ensuring that passwords are complex enough to not be
guessed, to restrict anonymous access, and if you have
the resources, purchase a firewall.

>-----Original Message-----
>I have auditing of failed logon attempts on. I noticed
>there is someone trying to logon to my server as guest,
>then admin, then administrator. This happens several
>times in a row within 2 min. I found it happpening
since
>Feb. Is there a way for me to figure out who it is that
>keeps doing this?
>.
>



Relevant Pages

  • Re: Restricting Domain login to a single user
    ... >walk up to any computer on our network and login with his ... >or her account username and password. ... Can you restrict it ...
    (microsoft.public.win2000.security)
  • Restrict login to certain user(s)
    ... I have a XP Workstation on the network where i want to ... restrict the login to only a few Domain-Users. ...
    (microsoft.public.windowsxp.security_admin)
  • Restricting Domain login to a single user
    ... At this time anyone with an account can ... walk up to any computer on our network and login with his ... Can you restrict it ...
    (microsoft.public.win2000.security)
  • Re: Time server...how to set it up on FC1?
    ... Network Time Protocol is different from the "time" ... I suggest that you set up ntpd on your server. ... would set this to "restrict default ignore" and then allow access for your ... # Permit time synchronization with our time source, ...
    (Fedora)
  • Re: Restrict access to certain sites
    ... Establish what is accepted use of the Internet. ... network or anything being removed from the network, ... Monitor only - Track what's done. ... restrict their logon since they're using their own and will eliminate the ...
    (microsoft.public.win2000.dns)