Re: NTLM Sniffing
From: Carl Hilton (someone_at_microsoft.com)
Date: 08/28/03
- Next message: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Previous message: Edward \(MSFT\): "Re: BEWARE security patch => hard disk corrupted"
- In reply to: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Next in thread: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Reply: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Reply: Michael Giorgio - MS MVP: "Re: NTLM Sniffing"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 28 Aug 2003 15:05:09 -0400
Wow, I have spent weeks trying to find a solution from MS, and NEVER ran
across this KB Article... Now, where can I get the checked netlogon.dll?
"Shawn Rabourn (MS)" <shawnrab@online.microsoft.com> wrote in message
news:OHKvhSZbDHA.300@TK2MSFTNGP12.phx.gbl...
> You may need to enable netlogon logging to identify the workstation in
which
> the user is trying to log on with and then filter your trace accordingly.
>
> 109626 Enabling Debug Logging for the Net Logon Service
> http://support.microsoft.com/?id=109626
>
> --Shawn
> This posting is provided "AS IS" with no warranties and confers no rights.
>
>
> "Carl Hilton" <someone@microsoft.com> wrote in message
> news:OyWV3TYbDHA.3080@TK2MSFTNGP11.phx.gbl...
> > OK, I am in a WinNT domain (although 99% of my workstations are W2K), I
> have
> > a packet capture of about 45 minutes of traffic. This is the time it
took
> > for a user to get locked out.. Now, how can I see what is causing the
> > lockout? I searched the packets for the USERID, but that did not work
Yes,
> I
> > had the packet capture for EACH/BOTH DCs. So, what traffic is bouncing
> > against the DC's so that this user's account is getting locked out?
> >
> > Carl
> >
> >
>
>
- Next message: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Previous message: Edward \(MSFT\): "Re: BEWARE security patch => hard disk corrupted"
- In reply to: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Next in thread: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Reply: Shawn Rabourn \(MS\): "Re: NTLM Sniffing"
- Reply: Michael Giorgio - MS MVP: "Re: NTLM Sniffing"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]