failure audit event 565 driving me crazy - reward offered
From: Thomas McLeod (thomas03_at_mcleodsoft.net.nospam)
Date: 05/27/03
- Next message: Jeremy Winston: "Re: Ports???"
- Previous message: Narain Ramjieawan: "Ports???"
- Next in thread: David Rosenthal: "Re: failure audit event 565 driving me crazy - reward offered"
- Reply: David Rosenthal: "Re: failure audit event 565 driving me crazy - reward offered"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 26 May 2003 20:43:30 -0400
To the first person that tells me exactly what's happening here I will send
a $5 gift certification for Ben & Jerry's Ice Cream.
Ready?
After being hacked, we recently turned on auditing for Directory Service
Access. Now every few minutes I get these Event Id 565 logs on our domain
controller (MCLEOD01$) by our Exchange server (SEQUOIA$) computer account:
Object Open:
Object Server: DS
Object Type: container
Object Name: %{3238f9ac-e713-4af0-81f2-c09ebfc148df}
New Handle ID: -
Operation ID: {0,4163737}
Process ID: 244
Primary User Name: MCLEOD01$
Primary Domain: MSD
Primary Logon ID: (0x0,0x3E7)
Client User Name: SEQUOIA$
Client Domain: MSD
Client Logon ID: (0x0,0x3E5A4B)
Accesses Read Property
Privileges -
Properties:
SYNCHRONIZE
ACCESS_SYS_SEC
Write Self
%%7692
%%7695
%{00000000-0000-0000-0000-000000000000}
READ_CONTROL
WRITE_DAC
Create Child
List Contents
Write Property
Delete Tree
uSNChanged
I have looked everywhere for an ojbect named
%{3238f9ac-e713-4af0-81f2-c09ebfc148df} and can't find one. (No, it's not a
GUID of anything in Active Directory). I was able to discovery through much
trial and error that setting the Recipient Update Services in Exchange to
"Never Run" eliminates the log entries. But I can't shut these down
permanently.
Thought Questions:
1. what is object %{3238f9ac-e713-4af0-81f2-c09ebfc148df} ?
2. what does the % mean in front of the GUID ?
3. what are %%7692 and %%7695 ?
Any Information would be helpful
Thomas McLeod
Montpelier, Vermont
- Next message: Jeremy Winston: "Re: Ports???"
- Previous message: Narain Ramjieawan: "Ports???"
- Next in thread: David Rosenthal: "Re: failure audit event 565 driving me crazy - reward offered"
- Reply: David Rosenthal: "Re: failure audit event 565 driving me crazy - reward offered"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|