Re: Enabling logging on IPC$ share ?

From: Steven Umbach (n9rou_at_n0spam-comcast.net)
Date: 02/15/04


Date: Sat, 14 Feb 2004 23:05:09 GMT

Curious?? You should hope to see no access from the internet to a domain
controller unless this is a intrusion detection project on a non production DC.
You can enable auditing of object access and then audit particular folders/files
but that will generate a lot of events in the security log. Auditing of logon
events will give you the most information in conjunction with firewall logs. A
personal firewall such as Sygate [free to try] has lot's of logging capabilities
and can be used just for that purpose by disabling the firewall function itself.
Packet sniffers such as the built in Netmon or other free one will give a lot of
detailed information at the packet level. TCPView from SysInternals will give a
lot of information on live network connections mapping ports to
processes/applications. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;301640
http://www.sysinternals.com/ntw2k/source/tcpview.shtml

"Kazil" <anonymous@discussions.microsoft.com> wrote in message
news:58AC8640-2E21-4D90-B2AB-4B0ED7E5E218@microsoft.com...
> I have hooked a Win2K Domain Controller to the Internet and I'm curious what
types of access I will see. I have enabled all kinds of logging, but would like
to enable logging on the Administrative shares and the IPC$ share. Is that
possible?



Relevant Pages

  • Re: netfilter iptables and firewall
    ... to access the Internet unless everything is done through an authenticated ... HOWEVER - you should not depend on your firewall ... Temporarily, jack up the logging, so that you are logging all NEW ... Use common scripting tools to sort out source and destination IPs, ...
    (comp.security.firewalls)
  • Re: netfilter iptables and firewall
    ... to access the Internet unless everything is done through an authenticated ... HOWEVER - you should not depend on your firewall ... Temporarily, jack up the logging, so that you are logging all NEW ... Use common scripting tools to sort out source and destination IPs, ...
    (comp.security.firewalls)
  • RE: ISA Server 2004 Issue with FWX_E_OUTBOUND_PATH_THROUGH_DROPPED
    ... error in my logging as well. ... Outside the firewall I can still browse the internet fine. ... > seems like if I use another port off our FW and grab a dhcp ip from the ...
    (microsoft.public.isaserver)
  • Re: avast
    ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
    (microsoft.public.windowsxp.general)
  • Re: XP NOT RESPONDING
    ... Did you have a firewall going before connecting to the internet? ... Microsoft has these suggestions for Protecting your computer from the ... Why you should use a computer firewall.. ... are pay - some you can only download if you are registered - but it is best ...
    (microsoft.public.windowsxp.setup_deployment)