Re: 681 and 529 auditing codes

From: Steven L Umbach (sumbach_at_ameritech.net)
Date: 08/07/03


Date: Wed, 06 Aug 2003 23:46:36 GMT


     It probably means your network is being enumerated from exposing
netbios/smb ports to the internet. From a network computer go to
http://scan.sygatetech.com/ and do at least a quick scan for basic
vulnerability to untrusted networks. If it shows you are vulnerable, you
need to reconfigure your firewall if you have one or get a firewall ASAP.
Check your network adapters that are directly connected to the internet [if
any] to see if they have file and print sharing enabled and if so disable or
uninstall it on those adapters. If you can not get a firewall ASAP, you may
try to configure ipsec filtering to block access from the internet and make
exception rules for required internet access as a temporary measure. ---
Steve

"kevin" <kalak76@yahoo.com> wrote in message
news:07c401c35c71$bcb0a960$a301280a@phx.gbl...
> Hi,
>
> Our accounts get locked out peridocially due to something
> attempting to login to the domain using dictionary
> attacks. This causes our accounts to lock out, even
> though we have no policy or GPOs set. We're getting a
> bunch of 681 and 529 audit events. I know it's from the
> outside because in the 681 event, it's coming from an
> unknown domain, attempting to log on as one of our valid
> user accounts.
>
> What is the cause of this, and why? And what can I do to
> prevent it immediately!??
>
> Thanks,



Relevant Pages

  • Re: Biometrics
    ... within a network for internal safety reasons and potentially to act as ... source code that is flexible enough to offer external security, ... Chris's distinction between the Internet and "a network" (presumably ... You quote a specific vulnerability below, about DNS, and you then make ...
    (microsoft.public.security)
  • drone armies C&C report - July/2005
    ... 3356 LEVEL3 Level 3 Communications ... 3491 BTN-ASN - Beyond The Network A ... 3801 MISNET - Mikrotec Internet Ser ... 15857 DIALOG-AS DIALOG-NET Autonomuo ...
    (Bugtraq)
  • Masquerading problem... can you help?
    ... server to masquerade a simple network and allow access to ... My server uses a modem to dial the internet. ... `SuSE-FW-DROP-DEFAULT' ...
    (comp.os.linux.security)
  • Re: U.S. as Traffic Cop in Web Fight
    ... Internet providers to treat all Web traffic equally, ... Digits: What Is Net Neutrality? ... AT&T cited network congestion concerns. ... Phone companies including AT&T have argued that they can live with the FCC's ...
    (talk.politics.guns)
  • Re: Biometrics
    ... You are asserting that one single vulnerability allows "military and top secrets to be leaked" and thus requires the use of some other operating system. ... within a network for internal safety reasons and potentially to act as ... Chris's distinction between the Internet and "a network" (presumably ...
    (microsoft.public.security)